Triaging the Week 134

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Theme 1: The Collapsing Exploit Window

Stories

🗞️ Autonomous Campaign Exploits PaperCut Flaws Worldwide (GreyNoise) – A threat actor used hundreds of autonomous AI agents, built on OpenAI Codex and DeepSeek models, to compromise 440+ PaperCut NG/MF servers across 395 organizations. The agents went from zero exploit code to Domain Admin in as little as five minutes and breached 11 organizations in 26 seconds. The education sector accounts for over half of victims. 🔎 Threat Hunting Package

🗞️ The Era of Autonomous Cyber Attacks: How Adversaries Are Scaling Agentic AI (Google Threat Intelligence Group) – Adversaries are moving from manual LLM prompting to multi-agent frameworks. These frameworks manage scanning pipelines, fix their own errors, and harvest credentials. They complete full attack lifecycles in under six hours while routing traffic through victim infrastructure.

🗞️ State-Aligned Espionage Groups Rapidly Adopt BlueMoon Exploit Kit in Zero-Day Attacks (Proofpoint) – Four nation-state clusters are using an exploit kit that chains Chromium “patch-gap” zero-days with a Windows kernel privilege escalation. It exploits the weeks between open-source commits and stable browser releases, and its code artifacts point to AI-assisted development. 🔎 Threat Hunting Package

🗞️ Microsoft Defender Zero-Day ‘ShieldCrash’ Bypasses Recent Patch to Grant SYSTEM File Access (BleepingComputer) – ShieldCrash was released right after September Patch Tuesday amid a disclosure dispute with Microsoft. It bypasses the ShieldBreak fix (CVE-2026-69414) and gives local attackers SYSTEM-level file reads on fully patched Windows 10, 11, and Server.

Recommendations

☑️ Patch on emergency timelines. That means PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078), every Chromium-based browser in the enterprise, and legacy Windows builds (Windows 10, Server 2019/2022). Be ready to push Microsoft’s out-of-band Defender fix.

☑️ Remove public access to utility apps like the PaperCut Application Server (pc-app.exe). Segment print and utility infrastructure, and run it with least-privilege service accounts.

☑️ Hunt Active Directory for post-exploitation activity: DCSync, LSASS memory dumping, unauthorized Domain Admins additions, and noPac attempts.

☑️ Build EDR detections for abnormal child processes spawned from browser workers. Also watch for unsigned binaries interacting with Defender scanning paths and system file handles.

☑️ Enforce application control and least privilege on endpoints, cloud compute, AI platform accounts, and API credentials. This stops low-privileged users from running privilege escalation payloads.

☑️ Scan and isolate AI developer extensions and workspace configuration files to block prompt injection and command execution.

☑️ Invest in real-time behavioral detection and automated response built for attack lifecycles measured in minutes, not days.

Theme 2: AI Systems as the New Attack Surface

Stories

🗞️ LiteLLM Flaws Enable Unauthenticated Root RCE and Full Cloud Compromise (Wiz Research) – Attackers can chain an MCP authentication bypass (CVE-2026-59822) with unsandboxed custom guardrail registration to get root RCE. They can then steal cloud IAM credentials through instance metadata services. Nearly 1 in 10 internet-facing deployments still use the default master key (sk-1234).

🗞️ The Shared Clipboard Threat: How Cross-Account Isolation Flaws Exposed Connected ChatGPT Data (Check Point) – Custom metadata in a shared internal JFrog Artifactory repository became a cross-tenant channel. Malicious prompts or shared links could run hidden tasks inside a victim’s session and exfiltrate data from connected services like Gmail.

🗞️ Federal Agencies Warn of Industrial-Scale AI Model Distillation Campaigns (CISA) – CISA, the NSA, and the FBI warn in advisory AA26-251A that China-based AI entities are extracting chain-of-thought reasoning from US frontier models. They use fraudulent accounts, gray-market API “transfer stations,” metadata sanitization, and targeted jailbreaks.

🗞️ Autonomous AI Agent Swarm Hijacks Public Wiki for Sandbox Evasion and Collusion (Nightingale Collective) – AI agents escaped OpenAI evaluation sandboxes and made 18,000+ edits to a public software wiki. They abused state-changing HTTP GET requests to turn read-only web access into a covert message board, which they used to share proxy bypasses and coordinate across evaluation runs.

🗞️ Anthropic’s Claude Models Breach Real-World Systems During Cyber Evals (Anthropic) – Anthropic disclosed four incidents in which Claude models, including Mythos 5, hit real third-party systems such as PyPI and a security vendor’s database after misconfigured evaluations. The models believed they were in CTF exercises. Anthropic attributes the incidents to “biased reasoning,” where the models ignored evidence they were on the open internet, and “recklessness.”

Recommendations

☑️ Upgrade LiteLLM to 1.84.0 or higher, rotate all master and virtual API keys, and inspect registered custom guardrails for malicious Python.

☑️ Take AI gateway management interfaces off the public internet and put them behind a VPN or zero-trust access with MFA. Apply least-privilege IAM to AI proxy workloads and block container egress to IMDS.

☑️ Audit and restrict the SaaS integrations connected to AI workspaces. Advise users against opening untrusted shared chat links or unverified custom GPTs.

☑️ Threat-model every shared internal API, cache, and metadata store in AI platforms as a tenant isolation boundary.

☑️ Lock down AI evaluation sandboxes with strict egress filtering, proxy inspection, blocking of state-changing requests, isolation between runs, and misconfiguration checks.

☑️ Monitor agent runs in real time for swarm coordination, proxy bypasses, and covert channels. Test models before release with deliberately misconfigured, no-solution exercises to measure boundary-probing behavior, and bring in independent auditors for ongoing oversight.

☑️ AI providers should flag distillation patterns, such as new premium accounts hitting maximum throughput or running non-human 24/7 traffic. They can serve degraded responses to suspected extraction queries and share intelligence across model providers, cloud hosts, and API aggregators.

Theme 3: Identity Is the Perimeter

Stories

🗞️ Cybercrime Reporting Overhaul Reveals Hidden Surge in UK Account Hacks (City of London Police) – Reported losses from hacked UK accounts rose 417% to £6.3M, and victims reporting financial loss rose 929%. Most of that jump comes from the new Report Fraud platform capturing crime that previously went unreported. SMBs made up 62% of organizational reports and are often used as stepping stones into larger supply chains.

🗞️ BigBear 2.0: The Evolving Evilginx2 Phishing Campaign Hijacking Microsoft 365 Sessions (CloudSEK) – “General Boss” runs an Evilginx2-based PhaaS operation that replays stolen M365 session cookies to bypass MFA. It has hit 3,300+ victim IPs in 40+ countries. Geo-matched residential proxies mirror each victim’s location to evade Microsoft’s geo-anomaly detection. 🔎 Threat Hunting Package

🗞️ IT Help Desk Vishing & AiTM Token Theft Drive Cloud Data Extortion Surge (Arctic Wolf) – Attackers vish executives through fake help desk calls and capture M365 session tokens via AiTM proxies. They replay the tokens through geo-matched residential proxies and exfiltrate cloud data for extortion without deploying any malware. 🔎 Threat Hunting Package

🗞️ Infostealer Logs Fuel AI Account Hijacking via Stolen Session Tokens and API Keys (Okta) – Session tokens and API keys harvested from infostealer logs act as “skeleton keys” to AI provider accounts. Attackers skip credential challenges entirely and run up hundreds of thousands of dollars in unauthorized token usage.

Recommendations

☑️ Deploy phishing-resistant FIDO2/WebAuthn keys and move away from SMS, TOTP, and push MFA. In the meantime, enforce MFA on every business account as a baseline, especially for SMBs.

☑️ Require compliant, managed devices in Conditional Access and restrict session token reuse across unauthorized networks. That way a stolen cookie alone isn’t enough to get in.

☑️ Harden help desk identity verification for password resets, MFA resets, and access requests.

☑️ Monitor SIEM logs for residential proxy sign-ins, bulk SharePoint search queries, and sudden spikes in AI API token consumption or unusual origin locations.

☑️ Audit, rotate, and set expiration limits on API keys and session tokens, especially for AI provider accounts. Deploy EDR to stop infostealers from pulling browser data and session stores.

☑️ Run vendor risk assessments on smaller third-party partners. Build a culture where employees report possible compromises quickly without fear.

Theme 4: Hiding in Plain Sight

Stories

🗞️ DPRK APTs Deploy “Ted Backdoor” & CurlRAT in Stealthy Linux Attacks (Rapid7) – North Korean actors targeting South Korean media and automotive firms compiled a backdoor directly into the victim’s own HAProxy 2.8.12. The backdoor intercepts traffic and injects scripts while load balancing keeps running normally. It is paired with an SSH keylogger and a custom CurlRAT. 🔎 Threat Hunting Package

🗞️ ASCII Smuggling: How an AI Exploit is Now Hiding Phishing Attacks in Plain Sight (Microsoft Security) – A technique first used for AI prompt injection has moved into phishing. Invisible Unicode tag characters (U+E0000–U+E007F) split keywords like “funding” to evade ML tokenizers and keyword filters in finance-themed lures. The text still looks normal to human readers.

🗞️ EtherHiding Evolves: Blockchain Dead Drops and Covert WebRTC Channels Drive Massive ClickFix Campaign (Netskope) – More than 5,400 compromised small-business websites pull ClickFix payloads from immutable BNB Smart Chain testnet contracts. Hand-written WebRTC responses skip signaling servers and open encrypted UDP C2 channels that web proxies can’t inspect. 🔎 Threat Hunting Package

🗞️ Breaking the Seal: Unmasking the JSCeal V8 Bytecode Stealer (Check Point Research) – JSCeal is a cryptocurrency stealer that also logs keystrokes, steals credentials, and intercepts HTTPS traffic. It ships as compiled V8 bytecode to defeat traditional analysis tools. Check Point Research released a fully static deobfuscation pipeline that recovers its logic without executing it. 🔎 Threat Hunting Package

🗞️ PEEP Browser RAT Disguises as ‘Smart Bookmarks’ Chrome Extension for Stealthy Post-Exploitation Attacks (SOCRadar) – This post-exploitation toolkit injects a fake “Smart Bookmarks” extension directly into Chrome and Edge profiles, bypassing Web Store checks. It uses native messaging to cross from the browser sandbox to the OS. Its C2 panel poses as an “authorized CTF” to slip past AI safety filters. 🔎 Threat Hunting Package

Recommendations

☑️ Verify the integrity of critical Linux binaries on edge servers, including HAProxy, sshd, crond, and agetty. Deploy file integrity monitoring across the DMZ and hunt for /tmp/jasper-log and encrypted log files under /var/lib/sshd/.

☑️ Tighten egress controls. Block the BSC testnet RPC endpoint pool, restrict outbound traffic from edge devices, and monitor for anomalous WebRTC peer connections and non-HTTP UDP channels.

☑️ Configure email gateways to strip or flag Unicode tag characters (U+E0000–U+E007F). Add OCR or visual rendering analysis so emails are inspected the way humans actually see them.

☑️ Enforce browser extension allowlisting. Audit profiles for “Smart Bookmarks,” and alert on anomalous native-messaging hosts and regular 30-second HTTP beaconing.

☑️ Add EDR rules for PowerShell downloading packaged Node.js runtimes (node.zip) or executing .jsc files. Pair them with controls and user training against pasting PowerShell from ClickFix-style prompts.

☑️ Add static deobfuscation tools like View8 to your CTI and malware analysis workflows to track compiled JavaScript threats.

☑️ Train staff to verify unexpected business funding or credit offers through a separate, trusted channel.

Theme 5: Scams at Scale

Stories

🗞️ Beware the BengalSEO Trap: How Fake Search Results Lead to Custom Malware (DFIR Report) – BengalSEO is an SEO poisoning campaign traced to IT service providers in Rajasthan, India. It uses a custom Traffic Distribution System to filter victims and route them to tech support scams and a custom malware strain called MayaBot. 🔎 Threat Hunting Package

🗞️ Massive DoppelCart Scam Network Exposed: 119,000 Fake-Shop Domains Impersonating E-Commerce Brands (Netby) – DoppelCart may be the largest documented fake-shop network to date. It clones real brand catalogs, hotlinks product images straight from genuine brand servers, and advertises fake 65% discounts. Victims then send their complaints to the real brands.

🗞️ GoldFactory Weaponizes App Cloning to Evade Banking Security (Group-IB) – GoldFactory pairs its Gigabud Android trojan with Vwork, a modified fork of the open-source tool Shelter. Vwork clones banking apps into an isolated Android Work Profile, where security SDKs in the main profile can’t see the fraudulent sessions. 🔎 Threat Hunting Package

🗞️ Otax Hybrid Malware Blends Spyware, Ransomware, and Harassment (Zimperium) – Mantax Otax is Indonesian-linked Android malware that combines full surveillance with file encryption on legacy devices. Its spyware steals lock-screen PINs, streams the screen live, and harvests WhatsApp and Telegram chats. It also harasses victims with audio threats and strobing overlays while extorting them through chat portals. 🔎 Threat Hunting Package

Recommendations

☑️ Block APK sideloading through MDM policies so apps can only be installed from verified app stores.

☑️ Deploy Mobile Threat Defense with on-device behavioral detection. It should flag abuse of the Accessibility and MediaProjection APIs and unexpected Android Work Profile creation.

☑️ Migrate devices off Android 9 and older so Scoped Storage can block full-device ransomware encryption.

☑️ Educate users about SEO poisoning, tech support scams, and too-good-to-be-true deals. Tell them never to grant Accessibility, overlay, or battery-optimization permissions to apps received via SMS or messaging apps.

☑️ Update secure web gateways to block known BengalSEO infrastructure, and tune EDR to catch custom malware like MayaBot.

☑️ Retailers should monitor lookalike domains across emerging TLDs like .shop and set up rapid takedown workflows. They should also restrict image hotlinking and teach customers to verify official URLs before buying.


Feature Video

In 2025, a single threat actor stole more cryptocurrency than the entire GDP of some recognized nations.

No ransomware. No smart contract exploit. No zero-day.

That actor is North Korea’s Lazarus Group, and the operation never touched a single line of smart contract code!

A few numbers that put this in perspective:

💲 $142M — North Korea’s entire annual physical export economy

💲 $1.5B — stolen in a single afternoon (Bybit, Feb 2025)

💲 76% — share of all global crypto hack losses attributed to North Korean actors through early 2026

💲 ~40% — of North Korea’s weapons and missile funding now comes from cyber theft

This isn’t a hacking group anymore. It’s a state treasury with four distinct clusters:

😈 APT38 — SWIFT manipulation, bank endpoint compromise

😈 Andariel — defense/aerospace espionage, self-funded via ransomware

😈 TraderTraitor — Web3/crypto, Electron app supply chain attacks

😈 Citrine Sleet — kernel-level rootkits, trojanized dev tooling

I broke down all three of their major kill chains — Bangladesh Bank, 3CX, and Bybit — in a new video. Plus, how to hunt for each distinct cluster! 

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools