Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Theme 1: Trusted Software Is the Delivery Vehicle
Stories
🗞️ TerminalFix Campaign Exploits Fake CAPTCHAs for Multi-Stage Intrusions (Microsoft Security) — Fake Cloudflare CAPTCHA overlays trick users into pasting PowerShell into Windows Terminal. The chain uses DLL sideloading and pulls payload components out of PNG pixels to build persistent network-level proxy access. 🔎 Threat Hunting Package
🗞️ Attackers Abuse Faronics Deploy Platform for Stealthy Network Intrusions (Huntress) — Business-themed phishing (fake tax docs, invoices, Adobe updates) gets victims to install a legitimately signed endpoint management platform, which is then used to run PowerShell and drop ScreenConnect. Visitor-based cloaking keeps analysts out.
🗞️ Evasive Cyber Campaign Uses Dynamic Installers to Bypass Security Controls (Microsoft Security) — Spoofed download sites regenerate the archive server-side on every request, so each victim gets a unique hash under an identical filename. Static blocklists are simply not in the game. 🔎 Threat Hunting Package
🗞️ Meta Ads Push StreamRAT Trojan for Full Android Device Takeover (ThreatFabric) — Paid streaming ads on Meta and TikTok walk Spanish-speaking users through bypassing Android’s own security prompts, using a dummy VPN to break reputation checks mid-install, then abuse Accessibility services for near-total remote control.
Recommendations
☑️ Move detection off static hashes and onto behaviour. Installers spawning script interpreters, mshta.exe, regsvr32.exe, and DLL sideloading anomalies.
☑️ Hunt for unexpected Faronics Deploy and ScreenConnect installs; check ScriptRunner.log and the ck deployment identifier.
☑️ Enforce application control (WDAC/AppLocker), restrict local install rights, and monitor every RMM tool for use outside authorised IT.
☑️ Add DNS-layer filtering for look-alike domains and newly registered software distribution URLs.
☑️ Use MDM to block sideloading and unapproved APKs, audit mobiles for untrusted apps, and revoke Accessibility permissions from anything unverified.
☑️ Train users on the full lure set: clipboard-to-terminal prompts, fake update pop-ups, and social media ads. Treat any host that ran one as a compromised pivot point.
Theme 2: The Supply Chain Turns Hostile
Stories
🗞️ 19 Chrome & Edge Extensions Weaponized with Wallet-Draining Malware (Socket) — Attackers are buying established extensions with real user bases, then shipping malicious auto-updates carrying credential stealers and wallet drainers over WebSocket C2 with CSP stripping. 🔎 Threat Hunting Package
🗞️ 13 Malicious Packagist Themes Deliver iOS Spyware to Steal Crypto Wallets (Socket) — Trojanised OphimCMS and KKPhim themes on Vietnamese streaming sites inject JavaScript that chains CVE-2025-31277 and CVE-2025-43529 for a WebKit-to-kernel escape, lifting keychain data from seven major wallet apps. 🔎 Threat Hunting Package
🗞️ Coder’s Cloud Registry Infrastructure Compromised to Push Malicious Terraform Modules (Coder) — Attackers injected rogue IPs straight into Coder’s Cloudflare backend pool, serving poisoned Terraform modules that shipped auth tokens and database passwords to coder-infra[.]com during an August 31 exposure window.
Recommendations
☑️ Audit installed browser extensions estate-wide and remove anything unnecessary. “Enable Right Click & Copy — Smart Unlock + OCR” is the standout with roughly 80,000 users exposed.
☑️ Whitelist approved extensions through endpoint management and watch for anomalous WebSocket C2 traffic.
☑️ If you run OphimCMS or KKPhim, strip packages from the flagged vendors (ophimcms, haiau009, chilltvcms, vsmov, vsphim), and push iOS estates to 26.1 or later.
☑️ Coder users: sweep firewall, DNS, proxy, and VPC flow logs for coder-infra[.]com, grep provisioner logs for data.external.telemetry, rotate everything exposed, then upgrade to 2.37.0, 2.36.4, 2.35.7, or 2.34.9 and purge cached modules.
☑️ Put software composition analysis, version pinning, and integrity checksums in front of both application dependencies and IaC modules. The initial vetting event is not the risk, the update is.
Theme 3: Your AI Toolchain Is Now Attack Surface
Stories
🗞️ Critical Langflow and Ruby on Rails Flaws Exploited for Mass Credential Theft and C2 Attacks (VulnCheck) — CVE-2026-0768 and CVE-2026-66066 are under active exploitation, with adversaries raiding environment variables for OpenAI and AWS keys, planting backdoors, and disabling auditd to create forensic blind spots.
🗞️ GitSpawn Vulnerability: AI Coding Agents Tricked Into Running Untrusted Code (Manifold) — Malicious repos abuse Git’s core.fsmonitor during an agent’s background context-gathering, so code runs outside the sandbox before the workspace-trust prompt ever appears.
🗞️ Infostealer Malware Hijacks Claude Sessions to Secretly Drain Paid AI Allowances (BleepingComputer) — Vidar, LummaC2, StealC and Atomic Stealer are harvesting authenticated session cookies to ride active AI accounts, sidestepping passwords and MFA entirely and burning paid token quotas without a login alert.
Recommendations
☑️ Patch Langflow and Rails now, then rotate every API key, cloud secret, and database credential configured on those hosts.
☑️ Put AI development frameworks and admin portals behind ZTNA or VPN. Nothing in this category belongs on the public internet.
☑️ Update AI coding agents to patched releases (Claude Code ≥2.1.196, Goose ≥1.44.0) and restrict use of any that remain unpatched.
☑️ Treat downloaded repos and ZIPs as untrusted; inspect .git/config for execution sinks before pointing an agent at the directory, and run agents in isolated environments with restricted egress.
☑️ Shorten session lifetimes and enforce EDR blocking on infostealers; audit AI billing for unexplained usage spikes as a compromise signal.
☑️ Add runtime process auditing for unauthorised Python execution, secret file access, and attempts to kill audit daemons.
Theme 4: Adversaries Are Operationalizing AI
Stories
🗞️ Frontier Models Achieve Autonomous End-to-End Cyber Attacks (Booz Allen) — The Cyber Weapon Index finds frontier models paired with execution frameworks can run full multi-stage kill chains unaided. The system, not the model, is now the unit of risk.
🗞️ Adversaries Leverage Commercial LLMs to Fuel Multi-Stage LATAM Attacks (Palo Alto Unit 42) — CL-CRI-1131 and CL-CRI-1163 use Claude and GPT variants through NextChat as live copilots to debug commands and automate post-exploitation. Sloppy SSL certificate hygiene let defenders map their shared proxy estate. 🔎 Threat Hunting Package
🗞️ Russia-Aligned UAC-0099 Uses Nuclear Prompt Injection to Blind AI Malware Scanners (ESET) — “GuardBreaker” plants nuclear weapon references in VBS comments so LLM triage tools refuse to analyse the file, hiding the MATCHBOIL payload behind the defender’s own safety guardrails.
Recommendations
☑️ Segregate untrusted input from control prompts in every LLM triage pipeline so file contents cannot steer the analysis.
☑️ Keep static analysis, signature detection, and sandbox detonation running independently of the AI layer. A refusal must never stop the pipeline.
☑️ Route every AI safety refusal or policy error to deterministic or human secondary review rather than closing the case.
☑️ Restrict and audit outbound traffic to unapproved LLM interfaces and commercial AI APIs, and hunt anomalous SOCKS5 relays and consolidated multi-SAN certificates.
☑️ Shift toward automated, machine-speed defence and Counter AI tactics that deceive autonomous attackers, plus behaviour-based EDR for dynamically generated payloads.
Theme 5: Already Inside the Walls
Stories
🗞️ Unmasking the DPRK Remote Worker Threat (Huntress) — North Korean operatives walk past the perimeter through the hiring process using forged passports and stolen profile photos, then run corporate laptops from overseas via PiKVM hardware and proxy chains.
🗞️ Massive Global Takedown: 20-Year-Old Sality Botnet Finally Disrupted (CrowdStrike) — CrowdStrike and law enforcement partners sinkholed a P2P botnet that survived two decades on a decentralised architecture with no single point of failure, isolating over 15,000 compromised machines. 🔎 Threat Hunting Package
🗞️ ‘FalconFlank’ PoC Targets CrowdStrike Falcon (The Register) — Researcher ‘Nightmare Eclipse’ turns Falcon’s macro remediation feature into a local privilege escalation path, and in doing so pivots a long-running vendetta from Microsoft onto the security vendors themselves.
Recommendations
☑️ Harden recruitment: live video calls, physical address verification before shipping hardware, and metadata checks on submitted identity documents.
☑️ Alert on anomalous hardware (Raspberry Pi KVMs, USB capture cards) alongside suspicious VPN use and off-hours login clusters.
☑️ Lock down network shares and removable media, the vectors polymorphic file infectors use to regenerate, and deploy endpoint protection that handles them.
☑️ Hunt for peer-to-peer communication patterns internally. C2 blocklists do nothing against decentralised infrastructure.
☑️ Monitor for local privilege escalation attempts and unusual macro execution, and enforce least privilege plus strict macro policies.
☑️ Watch for CrowdStrike’s FalconFlank mitigation guidance and deploy it the moment it lands.
Feature Video
Most write-ups of the North Korean IT worker threat stop at the front door.
They explain how these operatives get hired. That’s worth knowing, but it’s only Act 1.
Nobody briefs you on Act 2.
So I built the profile I wanted to read. Here’s what’s in it:
🧑💼 The organization. Not a hacking unit. A state-run staffing agency under the Reconnaissance General Bureau, Department 53 (same parent as Lazarus). Around 8,400 operatives embedded globally.
💵 The money. $250–600M a year by UN estimates, closer to $800M in a single fiscal year by Treasury’s count. Up to 90% clawed back to the department that buys ballistic missile components.
🗓️ The timeline. Five phases from 2011 to now, including the one global accident that made the whole model viable.
⚙️ The hiring pipeline. Identity harvesting, a sub-industry of account laundering run over Discord, and fabricated GitHub histories going back a decade, compiled last year.
💬 The interview. Three stacked layers of deception, and a fourth participant on the call you never see.
📰 The Christina Chapman case. 309 companies. 68 burned identities. $17.1M. Eight and a half years.
🌐 The infrastructure. Why your EDR is structurally blind to how these operatives connect — not misconfigured, blind.
☠️ The extortion. What Secureworks tracks as Nickel Tapestry, and why firing one of these people is the most dangerous moment of the whole engagement.
📖 The playbook. Seven concrete detection opportunities, each mapped to where it lives in the kill chain.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



