Triaging the Week 124

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

ðŸŠĪ Initial Access Brokers (IABs) & Backdoor Tradecraft

Stories

🗞ïļ DragonForce Ransomware Weaponizes Microsoft Teams Relays — DragonForce’s “Backdoor.Turn” hides C2 traffic inside legitimate Microsoft Teams TURN infrastructure, using anonymous visitor tokens and a BYOVD technique (an undocumented Huawei audio driver) to bypass endpoint defenses. 🔎 Threat Hunting Package

🗞ïļ Stealthy New Backdoor Arsenal Opens Corporate Networks to Ransomware Affiliates — IAB “Woodgnat” (KongTuke) is selling access built on the memory-resident, disk-free “Backdoor.Mistic” and “ModeloRAT,” delivered via ClickFix social engineering on compromised WordPress sites, to ransomware groups like Qilin, Akira, and Black Basta. 🔎 Threat Hunting Package

🗞ïļ Initial Access Brokers Abuse Browser Extensions for Stealthy Ransomware Footholds — “Edgecution,” from the Payouts King ransomware broker, tricks victims via fake IT-helpdesk Teams messages into installing a hidden Edge extension that abuses Chrome’s native messaging protocol to relay commands to a Python backdoor. 🔎 Threat Hunting Package

🗞ïļ State-Sponsored Hackers Pre-Positioned for Critical Infrastructure Sabotage — ASIO’s 2026 threat assessment confirms nation-state actors have compromised an Australian critical infrastructure provider, quietly mapping internal environments and living off the land to maintain dormant footholds for a future strategic strike.

Recommendations

☑ïļ Hunt for anomalous outbound relay traffic (Teams/Skype/QUIC) and headless browser or native-messaging activity tied to unauthorized extensions 

☑ïļ Update driver and extension blocklists; enforce centralized policies that block sideloaded browser extensions and known-vulnerable drivers (e.g., Huawei HWAuidoOs2Ec.sys) 

☑ïļ Mandate phishing-resistant MFA and out-of-band verification for any “IT support” requests received over chat platforms 

☑ïļ Apply strict IT/OT segmentation and Zero Trust application control to prevent lateral movement and limit the blast radius of a dormant foothold

🔐 Vulnerabilities & Exploitable Infrastructure

Stories

🗞ïļ Apple Patches High-Severity Beats Studio Buds Eavesdropping Flaw — CVE-2025-20701 lets nearby attackers exploit a missing Bluetooth authentication check in the Airoha SoC to silently eavesdrop, and when chained, take over the earbuds entirely.

🗞ïļ “Squidbleed” Memory Disclosure Vulnerability Puts Squid Proxies at Risk — CVE-2026-47729 lets attackers craft HTTP requests that leak Squid’s heap memory, exposing session cookies, OAuth tokens, and corporate credentials from forward and reverse proxy deployments.

🗞ïļ AryStinger Botnet Hijacks Legacy Routers for Global Attack Proxies — Over 4,000 decade-old D-Link/Linksys routers and NAS devices have been folded into a botnet built specifically for reconnaissance and intrusion staging, not the usual DDoS or cryptomining. 🔎 Threat Hunting Package

🗞ïļ “Adblock for YouTube” Chrome Extension Leaves 11 Million Users Vulnerable to Remote Script Injection — A popular ad blocker (11M installs) has a hidden mechanism letting its developer push remote JavaScript execution to any site via a simple backend change, no Chrome Web Store review required. 🔎 Threat Hunting Package

Recommendations

☑ïļ Patch immediately: verify Beats Studio Buds firmware (1B211+), upgrade Squid to the fixed release, and patch routers/NAS against CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 

☑ïļ Reduce exposed attack surface — disable Bluetooth in untrusted public spaces, restrict Squid proxy access to internal subnets only via ACLs, and audit/replace end-of-life hardware 

☑ïļ Hunt for exploitation signs: malformed HTTP headers against Squid, unauthorized SSH/dropbear services on unusual ports, and the specific Chrome extension ID (cmedhionkhpnakcndndgjdbohmhepckk) in your environment 

☑ïļ Enforce MDM/Chrome Enterprise allowlists to block unvetted high-permission browser extensions before they’re ever installed

ðŸ§ē Social Engineering & Trust Abuse

Stories

🗞ïļ Malicious WhatsApp Campaign Abuses Contact Trust to Deploy Remote Backdoors — Compromised WhatsApp accounts (80% of victims in Malaysia) send malicious VBScript disguised as business documents that quietly install legitimate RMM tools like AnyDesk for persistent access. 🔎 Threat Hunting Package

🗞ïļ Evolving macOS “ClickFix” Campaigns Automate DMG Mounting to Push Infostealers — ClickFix has evolved past manual Terminal commands, now automating disk image mounting through browser workflows to silently harvest keychain data and crypto wallets. 🔎 Threat Hunting Package

🗞ïļ Scammers Abuse Shopping Platforms to Deliver Fake Invoices — Threat actors are planting fake receipts inside legitimate order-tracking apps like Shop, embedding scam support numbers that exploit the platform’s built-in trust to trigger panic-driven calls.

🗞ïļ Evasive OXLOADER Malware Uses Google Ads to Deliver CASTLESTEALER Infostealer — A new Windows loader masquerades as developer tools like Node.js via malicious Google Ads, using abuse of the .reloc section and five anti-VM checks to evade sandboxes before deploying CASTLESTEALER. 🔎 Threat Hunting Package

Recommendations

☑ïļ Train staff to never run script files (.vbs/.js/.bat) from messaging apps, click “fix it yourself” browser prompts, or trust links/numbers inside push notifications — verify out-of-band instead 

☑ïļ Block or tightly restrict script hosts (wscript.exe, cscript.exe, mshta.exe) and monitor for unauthorized RMM installs (AnyDesk, ManageEngine) and automated hdiutil disk-mounting from browser child processes 

☑ïļ Reinforce that legitimate vendors never require sponsored-ad downloads — direct staff to official domains only when seeking software 

☑ïļ Use platform-native reporting tools to flag suspicious in-app receipts/stores and lock down notification automation permissions

ðŸĪ– AI Supply Chain & Agentic Risk

Stories

🗞ïļ Hijacking 26,000 AI Agents in an Hour: The Hidden Supply-Chain Danger of AI Skills — A malicious “skill” pushed via an Instagram ad hijacked over 26,000 enterprise AI agents by exploiting scanners that only check static files and ignore dynamically-fetched external links that can be altered post-install.

🗞ïļ Malicious OpenClaw Skills Bypass Scanners to Trigger AI Supply Chain Risks — Unit 42 found five malicious OpenClaw skills that exploit the framework’s lack of permission isolation, inheriting full agent system access to deploy macOS infostealers and run fraudulent schemes via natural-language manipulation. 🔎 Threat Hunting Package

🗞ïļ New macOS Gaslight Backdoor Deceives AI-Assisted Triage Tooling — This Rust backdoor doesn’t bother evading sandboxes technically; it embeds a 38-message prompt-injection cascade that fakes system errors to trick LLM-based triage tools into abandoning analysis. 🔎 Threat Hunting Package

Recommendations

☑ïļ Implement continuous runtime scanning for AI skills/extensions to catch post-installation modifications — static, one-time checks aren’t enough 

☑ïļ Establish a single vetted internal repository for all AI add-ons and gate marketplace extensions behind sandboxed pre-approval 

☑ïļ Redesign agent environments around runtime isolation (containerization) and strict network egress controls rather than implicit trust 

☑ïļ Harden AI triage pipelines with strict data-instruction separation so sample metadata is never treated as executable instruction

ðŸĨŠ Law Enforcement Wins & Supply Chain / Phishing Evolution

Stories

🗞ïļ Global Law Enforcement Disrupts Notorious SocGholish Malware Network — Operation Endgame saw 11 agencies seize 100+ servers and clean nearly 15,000 WordPress sites, dismantling a major Initial Access Broker that fed LockBit and infostealer payloads via fake browser-update pop-ups.

🗞ïļ Global Cyber Strike Shatters Cybercrime “Assembly Line”: SocGholish, Amadey, and StealC Infrastructure Dismantled — The follow-on Europol/Microsoft action seized ₮41M in crypto, disabled 326 servers, and recovered 27 million stolen credentials — a strategic shift toward dismantling cybercrime-as-a-service supply chains rather than single operators.

🗞ïļ WordPress Supply Chain Attack: Backdoors Injected into Premium Pro Plugins — Attackers breached ShapedPlugin’s build pipeline and backdoored only the premium “Pro” releases, harvesting database configs, session cookies, and 2FA TOTP seeds via official update channels.

🗞ïļ Automated Crypto Clipper Spreads Like a Worm via Tor Infrastructure — Unlike typical isolated clippers, this strain self-propagates via network shares and removable media while routing all C2 through embedded Tor, rendering domain blocklists ineffective. 🔎 Threat Hunting Package

🗞ïļ Inside the Note-Free “Prinz Eugen” Go-Based Ransomware — This Go-based ransomware skips the ransom note entirely, prioritizing high-value recently-modified files and running anti-forensic routines to wipe memory and move extortion communications out-of-band. 🔎 Threat Hunting Package

🗞ïļ Bluekit Phishing-as-a-Service Weaponizes “Browser-in-the-Middle” Live Streaming — Bluekit streams a real login page’s DOM over WebSockets to victims in real time, bypassing legacy reverse-proxy phishing detection with randomized layouts and WebRTC-based IP checks.

Recommendations

☑ïļ Audit all CMS/WordPress admin accounts, rotate credentials, enforce MFA, and remove unauthorized user profiles — especially after any recent plugin updates 

☑ïļ Disable unauthenticated SMB shares, block auto-run on removable media, and flag unexpected embedded Tor proxy activity at the endpoint 

☑ïļ Update incident response playbooks for note-free ransomware: alert on disk-write spikes and file inaccessibility rather than waiting for a ransom note 

☑ïļ Migrate authentication to hardware-backed FIDO2/WebAuthn or passkeys to neutralize session-streaming phishing kits like Bluekit, and cross-reference credentials against breach registries from these takedowns


Feature Livestream

Most teams treat MISP as a database they fill in by hand. This week I’m going live to change that!

MISP Workflows is the most underused feature in the platform. It turns MISP from a passive store into something that tags, enriches, and governs itself — no analyst babysitting required.

In one hour, I’ll build four automations live, from scratch:

→ Auto-tag and enrich every IP the moment it’s added

→ Fire a Slack alert the second an event is published

→ A blocking quality gate that stops any event publishing without a TLP marking

→ Push flagged events straight to your automation hub via webhook

No slides-only theory. Real builds on a real instance, including gotchas I’ve hit so you don’t have to. Every blueprint I create will be yours to download and import.

If you run CTI tooling, or you’re tired of relying on analyst discipline to keep your intel clean, this one’s for you. 

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools