Hello there ð
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the weekâs top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about whatâs happening at the company. Enjoy!
Top News Stories

ðŠĪ Initial Access Brokers (IABs) & Backdoor Tradecraft
Stories
ðïļ DragonForce Ransomware Weaponizes Microsoft Teams Relays â DragonForce’s “Backdoor.Turn” hides C2 traffic inside legitimate Microsoft Teams TURN infrastructure, using anonymous visitor tokens and a BYOVD technique (an undocumented Huawei audio driver) to bypass endpoint defenses. ð Threat Hunting Package
ðïļ Stealthy New Backdoor Arsenal Opens Corporate Networks to Ransomware Affiliates â IAB “Woodgnat” (KongTuke) is selling access built on the memory-resident, disk-free “Backdoor.Mistic” and “ModeloRAT,” delivered via ClickFix social engineering on compromised WordPress sites, to ransomware groups like Qilin, Akira, and Black Basta. ð Threat Hunting Package
ðïļ Initial Access Brokers Abuse Browser Extensions for Stealthy Ransomware Footholds â “Edgecution,” from the Payouts King ransomware broker, tricks victims via fake IT-helpdesk Teams messages into installing a hidden Edge extension that abuses Chrome’s native messaging protocol to relay commands to a Python backdoor. ð Threat Hunting Package
ðïļ State-Sponsored Hackers Pre-Positioned for Critical Infrastructure Sabotage â ASIO’s 2026 threat assessment confirms nation-state actors have compromised an Australian critical infrastructure provider, quietly mapping internal environments and living off the land to maintain dormant footholds for a future strategic strike.
Recommendations
âïļ Hunt for anomalous outbound relay traffic (Teams/Skype/QUIC) and headless browser or native-messaging activity tied to unauthorized extensions
âïļ Update driver and extension blocklists; enforce centralized policies that block sideloaded browser extensions and known-vulnerable drivers (e.g., Huawei HWAuidoOs2Ec.sys)
âïļ Mandate phishing-resistant MFA and out-of-band verification for any “IT support” requests received over chat platforms
âïļ Apply strict IT/OT segmentation and Zero Trust application control to prevent lateral movement and limit the blast radius of a dormant foothold
ð Vulnerabilities & Exploitable Infrastructure
Stories
ðïļ Apple Patches High-Severity Beats Studio Buds Eavesdropping Flaw â CVE-2025-20701 lets nearby attackers exploit a missing Bluetooth authentication check in the Airoha SoC to silently eavesdrop, and when chained, take over the earbuds entirely.
ðïļ “Squidbleed” Memory Disclosure Vulnerability Puts Squid Proxies at Risk â CVE-2026-47729 lets attackers craft HTTP requests that leak Squid’s heap memory, exposing session cookies, OAuth tokens, and corporate credentials from forward and reverse proxy deployments.
ðïļ AryStinger Botnet Hijacks Legacy Routers for Global Attack Proxies â Over 4,000 decade-old D-Link/Linksys routers and NAS devices have been folded into a botnet built specifically for reconnaissance and intrusion staging, not the usual DDoS or cryptomining. ð Threat Hunting Package
ðïļ “Adblock for YouTube” Chrome Extension Leaves 11 Million Users Vulnerable to Remote Script Injection â A popular ad blocker (11M installs) has a hidden mechanism letting its developer push remote JavaScript execution to any site via a simple backend change, no Chrome Web Store review required. ð Threat Hunting Package
Recommendations
âïļ Patch immediately: verify Beats Studio Buds firmware (1B211+), upgrade Squid to the fixed release, and patch routers/NAS against CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837
âïļ Reduce exposed attack surface â disable Bluetooth in untrusted public spaces, restrict Squid proxy access to internal subnets only via ACLs, and audit/replace end-of-life hardware
âïļ Hunt for exploitation signs: malformed HTTP headers against Squid, unauthorized SSH/dropbear services on unusual ports, and the specific Chrome extension ID (cmedhionkhpnakcndndgjdbohmhepckk) in your environment
âïļ Enforce MDM/Chrome Enterprise allowlists to block unvetted high-permission browser extensions before they’re ever installed
ð§ē Social Engineering & Trust Abuse
Stories
ðïļ Malicious WhatsApp Campaign Abuses Contact Trust to Deploy Remote Backdoors â Compromised WhatsApp accounts (80% of victims in Malaysia) send malicious VBScript disguised as business documents that quietly install legitimate RMM tools like AnyDesk for persistent access. ð Threat Hunting Package
ðïļ Evolving macOS “ClickFix” Campaigns Automate DMG Mounting to Push Infostealers â ClickFix has evolved past manual Terminal commands, now automating disk image mounting through browser workflows to silently harvest keychain data and crypto wallets. ð Threat Hunting Package
ðïļ Scammers Abuse Shopping Platforms to Deliver Fake Invoices â Threat actors are planting fake receipts inside legitimate order-tracking apps like Shop, embedding scam support numbers that exploit the platform’s built-in trust to trigger panic-driven calls.
ðïļ Evasive OXLOADER Malware Uses Google Ads to Deliver CASTLESTEALER Infostealer â A new Windows loader masquerades as developer tools like Node.js via malicious Google Ads, using abuse of the .reloc section and five anti-VM checks to evade sandboxes before deploying CASTLESTEALER. ð Threat Hunting Package
Recommendations
âïļ Train staff to never run script files (.vbs/.js/.bat) from messaging apps, click “fix it yourself” browser prompts, or trust links/numbers inside push notifications â verify out-of-band instead
âïļ Block or tightly restrict script hosts (wscript.exe, cscript.exe, mshta.exe) and monitor for unauthorized RMM installs (AnyDesk, ManageEngine) and automated hdiutil disk-mounting from browser child processes
âïļ Reinforce that legitimate vendors never require sponsored-ad downloads â direct staff to official domains only when seeking software
âïļ Use platform-native reporting tools to flag suspicious in-app receipts/stores and lock down notification automation permissions
ðĪ AI Supply Chain & Agentic Risk
Stories
ðïļ Hijacking 26,000 AI Agents in an Hour: The Hidden Supply-Chain Danger of AI Skills â A malicious “skill” pushed via an Instagram ad hijacked over 26,000 enterprise AI agents by exploiting scanners that only check static files and ignore dynamically-fetched external links that can be altered post-install.
ðïļ Malicious OpenClaw Skills Bypass Scanners to Trigger AI Supply Chain Risks â Unit 42 found five malicious OpenClaw skills that exploit the framework’s lack of permission isolation, inheriting full agent system access to deploy macOS infostealers and run fraudulent schemes via natural-language manipulation. ð Threat Hunting Package
ðïļ New macOS Gaslight Backdoor Deceives AI-Assisted Triage Tooling â This Rust backdoor doesn’t bother evading sandboxes technically; it embeds a 38-message prompt-injection cascade that fakes system errors to trick LLM-based triage tools into abandoning analysis. ð Threat Hunting Package
Recommendations
âïļ Implement continuous runtime scanning for AI skills/extensions to catch post-installation modifications â static, one-time checks aren’t enough
âïļ Establish a single vetted internal repository for all AI add-ons and gate marketplace extensions behind sandboxed pre-approval
âïļ Redesign agent environments around runtime isolation (containerization) and strict network egress controls rather than implicit trust
âïļ Harden AI triage pipelines with strict data-instruction separation so sample metadata is never treated as executable instruction
ðĨ Law Enforcement Wins & Supply Chain / Phishing Evolution
Stories
ðïļ Global Law Enforcement Disrupts Notorious SocGholish Malware Network â Operation Endgame saw 11 agencies seize 100+ servers and clean nearly 15,000 WordPress sites, dismantling a major Initial Access Broker that fed LockBit and infostealer payloads via fake browser-update pop-ups.
ðïļ Global Cyber Strike Shatters Cybercrime “Assembly Line”: SocGholish, Amadey, and StealC Infrastructure Dismantled â The follow-on Europol/Microsoft action seized âŽ41M in crypto, disabled 326 servers, and recovered 27 million stolen credentials â a strategic shift toward dismantling cybercrime-as-a-service supply chains rather than single operators.
ðïļ WordPress Supply Chain Attack: Backdoors Injected into Premium Pro Plugins â Attackers breached ShapedPlugin’s build pipeline and backdoored only the premium “Pro” releases, harvesting database configs, session cookies, and 2FA TOTP seeds via official update channels.
ðïļ Automated Crypto Clipper Spreads Like a Worm via Tor Infrastructure â Unlike typical isolated clippers, this strain self-propagates via network shares and removable media while routing all C2 through embedded Tor, rendering domain blocklists ineffective. ð Threat Hunting Package
ðïļ Inside the Note-Free “Prinz Eugen” Go-Based Ransomware â This Go-based ransomware skips the ransom note entirely, prioritizing high-value recently-modified files and running anti-forensic routines to wipe memory and move extortion communications out-of-band. ð Threat Hunting Package
ðïļ Bluekit Phishing-as-a-Service Weaponizes “Browser-in-the-Middle” Live Streaming â Bluekit streams a real login page’s DOM over WebSockets to victims in real time, bypassing legacy reverse-proxy phishing detection with randomized layouts and WebRTC-based IP checks.
Recommendations
âïļ Audit all CMS/WordPress admin accounts, rotate credentials, enforce MFA, and remove unauthorized user profiles â especially after any recent plugin updates
âïļ Disable unauthenticated SMB shares, block auto-run on removable media, and flag unexpected embedded Tor proxy activity at the endpoint
âïļ Update incident response playbooks for note-free ransomware: alert on disk-write spikes and file inaccessibility rather than waiting for a ransom note
âïļ Migrate authentication to hardware-backed FIDO2/WebAuthn or passkeys to neutralize session-streaming phishing kits like Bluekit, and cross-reference credentials against breach registries from these takedowns
Feature Livestream
Most teams treat MISP as a database they fill in by hand. This week I’m going live to change that!
MISP Workflows is the most underused feature in the platform. It turns MISP from a passive store into something that tags, enriches, and governs itself â no analyst babysitting required.
In one hour, I’ll build four automations live, from scratch:
â Auto-tag and enrich every IP the moment it’s added
â Fire a Slack alert the second an event is published
â A blocking quality gate that stops any event publishing without a TLP marking
â Push flagged events straight to your automation hub via webhook
No slides-only theory. Real builds on a real instance, including gotchas I’ve hit so you don’t have to. Every blueprint I create will be yours to download and import.
If you run CTI tooling, or you’re tired of relying on analyst discipline to keep your intel clean, this one’s for you.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



