
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence.
The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now.
What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned up.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
- Malicious VS Code themes exposed
GlassWorm-Linked VS Code Extensions Discovered
Socket said it discovered two suspicious VS Code themes still available on the Visual Studio Marketplace (Coca-Cola Christmas and Aurora Borealis Studio Theme) that claim to be color themes but share ties to Aurora Nocturne Night Theme, a previously removed malicious extension that concealed an obfuscated Windows downloader. Further analysis has uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes. An analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes has revealed that it contains a loader that decrypts and executes embedded JavaScript, avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos as a dead drop resolver to identify follow-on payload infrastructure. "That build contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity," Socket researcher Kirill Boychenko said.
- BraZetsu C2 infrastructure traced
Mapping BraZetsu Infrastructure via TLS Certificates
Last month, Group-IB published a detailed analysis of BraZetsu, a Python-based Windows malware framework that's designed to gain access to Windows hosts via phishing attacks. It's also linked to Infected Marketplace, an underground market that inventories compromised Windows hosts and sells the access after a deposit of about $5.80, settled through NowPayments. Hunt.io, in a new analysis of the network indicators, said "the command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure. The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host."
- WhatsApp lure deploys Windows RAT
New VulcanRAT207.A Detailed
A financial-document lure ("Statement.exe"), reportedly delivered via WhatsApp, has been found to deliver a previously tracked WebSocket remote access trojan (RAT) tracked as VulcanRAT207. As part of a multi-stage Windows intrusion. "After unpacking, the loader screened the host, attempted elevation, and injected a downloader into the LocalSystem Task Scheduler process," Morphisec said. "The chain retrieved a deployment bundle, used a signed GoFly driver ["GoFly64.sys"] to terminate selected Baidu security processes [using the BYOVD technique], established a Vulkan DLL side-loading task, and launched a WebSocket remote access trojan (RAT). The loader screens the host, attempts elevation, and uses PoolParty Variant 7 to place a downloader in the Windows Task Scheduler process without relying on CreateRemoteThread." The malware can collect system metadata, enable interactive shell access, terminate security processes, implement process injection techniques, replace clipboard text, enumerate local accounts, and terminate itself.
- Qilin suspect extradited
Alleged Qilin Ransomware Group Member Extradited to Germany
An alleged member of the Qilin ransomware group has been arrested in Japan and extradited to Germany. The suspect, a 28-year-old Russian national, was detained in Osaka in May and reportedly handed over to the German authorities on October 2, 2026. The suspect is believed to be a core member of the ransomware gang, and wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting more than $160,000 in cryptocurrency.
- Medical devices face PQC gaps
PQC Readiness in Healthcare
A new analysis from Forescout has revealed that most medical devices cannot be upgraded to post-quantum cryptography (PQC), leaving sensitive healthcare data vulnerable to future quantum-enabled attacks. The analysis, which covered over 2.5 million devices across more than 50 healthcare delivery organizations (HDOs), found that only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell (SSH) implementations capable of supporting a transition to PQC, compared to 50% of IT devices. "Across exposed healthcare systems, only 31% support TLS 1.3, the only TLS version capable of supporting standardized post-quantum cryptography," Forescout said. "Healthcare data – including medical histories, diagnostic images, lab results, and prescription records – remains valuable for a lifetime, making the sector especially vulnerable to harvest-now, decrypt-later (HNDL) attacks."
- Ransomware affiliate turns rogue
Gentlemen Ransomware Affiliate Double Crosses Gang
A Russian-speaking Gentlemen ransomware affiliate called Azazel robbed two dozen victims across six countries, then double-crossed his own gang by publishing the stolen data on a private leak site and pocketing the profits. Azazel "built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims," CloudSEK said.
- Power BI phishing delivers RMM
Phishing Campaign Abuses Microsoft Power BI to Drop RMM Tools
Huntress has detailed a phishing campaign where threat actors abused legitimate Power BI domains to make the attacks more persuasive, evade security controls, and trick victims into downloading ScreenConnect installers. "These emails led victims to a fake reference document on the Power BI domains, which prompted targets to 'Download Reference,'" Huntress said. "When they attempted to do so, a new tab opened to an attacker-controlled website, which would fingerprint victims before triggering a rogue ScreenConnect installer download. Notably, these webpages delayed the payload's automatic download. After a few seconds, a script programmatically activated a hidden download link that led to the installer." The campaign was first observed on September 10, 2026.
- File upload flaw enables web shells
Flaw in Recreation Management Software Abused to Upload Web Shells
A file upload vulnerability in a popular web-based recreation management software platform designed for local municipalities and parks has been weaponized to compromise three servers by adding a new account, using it to upload web shells, and ultimately stealing payment data. "User-agent strings suggest that the threat actor is based in China," Huntress said. "We also suspect the use of AI-generated scripts throughout the kill chain, from the large number of failed initial access probes to the final upload of PowerShell scripts with extensive comments in the provided instructions. The initial attempts during the first act were noisy and clumsy, and may have even been initiated via an AI-generated automation script due to the high volume of attempts. The attacker ultimately achieved initial access with a more manual approach: creating their own account on the platform and finding a flaw in the upload function."
- AI agent profiles non-users
Meta's Muse Agent Collects Extensive Data
Muse, the buzzy personal AI agent from Meta, has been observed building dossiers about its users and their social circles. An analysis of Muse's internal instructions by TIME has revealed it updates its dossiers on its users and the people they mention in chats, messages, and emails every hour. This also includes people who don't use Muse. In response to the findings, Meta said, "Muse remembers what matters most to you, including information about others that you choose to share, so it can be a helpful personal assistant."
- Malicious packages target developers
@subql/common npm Package Compromised
The npm package "@subql/common" version 5.8.3 has been compromised to include a "hidden payload that collects credentials and supports remote shell access," StepSecurity said. "It starts during installation and when the package is imported. The code targets developer workstations and CI environments, including GitHub Actions runners and accessible cloud services." In another supply chain attack, a RubyGems account named "reqthrottle_3474" has been observed publishing 42 malicious gems, most of which target cryptocurrency developers. "The gems do nothing in CI or in a sandbox," SafeDep said. "On a developer’s machine, they wait 20 to 40 minutes in the background, then do one of two things: (1) Eleven gems open a reverse shell to 45.138.12[.]177 on port 8089 or 8090, and (2) Thirty-one gems download wgkit.tar.gz from 45.138.12[.]177:8092 and run wg_install.sh from it." Also detected is a cluster of nine npm packages that embed a self-spreading Linux worm. All the packages were published by the npm account "dirtyblanket" within a span of 33 minutes on September 29, 2026. "The worm installs a backdoor, systemd-fontd, as a fake systemd font service," SafeDep said. "It is the open-source CHAOS remote access tool. Over Tor, it gives the operator a shell, file access, and screenshots. It uses every SSH private key on the machine to log in to the hosts in known_hosts and runs itself there. It adds itself to the Arch User Repository (AUR) packages that those keys can push to." The worm also uses the npm tokens on the machine to push new versions of the developers' npm packages to propagate it.
- Phishing targets people and AI
Phishing Campaign Targets Both Humans and AI Agents
Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection hidden in the same message. "Humans are targeted with social engineering such as password-protected attachments, and AI assistants are targeted with prompt injections designed to influence or override user behavior," Barracuda said, adding the research "shows how attackers are combining tactics to manipulate both human users and their email AI assistants in the same phishing email." It did not disclose the scale of the campaign.
- Insider sabotage draws prison term
Ex-Engineer Sentenced to 32 Months in Prison for Failed Extortion Attempt
Daniel Rhyne, 59, a former core infrastructure engineer at an industrial company headquartered in Somerset County, New Jersey, has been sentenced to 32 months in prison for locking thousands of systems and servers on his employer's network in a failed data extortion campaign. Rhyne was charged in September 2024 with one count of extortion in relation to a threat to cause damage to a protected computer, one count of intentional damage to a protected computer, and one count of wire fraud. He pleaded guilty earlier this April.
- Exposed server reveals attack tools
Open Directory Exposes Threat Actor Tradecraft
An attacker-controlled staging service at "151.243.232[.]123" has unearthed activity involving an environment linked to Mexican airline Viva Aerobus in late September 2026. The exposed infrastructure contained 17 named post-exploitation tools, including credential-dumping scripts, Mimikatz output, SQL credential-testing utilities, and file-transfer tooling. Although the exact initial intrusion method is unclear, the threat actor is said to have gained access to a Microsoft SQL server and then used its xp_cmdshell functionality to run commands and serve additional payloads. "Instead of establishing a separate outbound channel, recovered tooling could read a file, divide it into chunks, Base64-encode the content, and return those chunks through MSSQL query output," ThreatMon said. "Unrelated internet hosts accessed the exposed infrastructure shortly after the first confirmed victim-side activity, creating a secondary exposure risk for both the attacker’s tools and previously collected material."
- Predictable cookies enable impersonation
Bypassing Session Cookie Authentication
Resecurity has detailed an authentication bypass in an unspecified yard management system (YMS) that it said is caused by two independent weaknesses in the application's session-cookie design. "First, the session cookie was signed using a hard-coded secret that was identical to the cookie name: session_secret_example," Resecurity said. "Second, the value protected by this signature was the user's public database identifier (CUID), rather than a random, unpredictable session identifier. These weaknesses could be combined to generate valid session cookies for arbitrary users whose IDs could be obtained through the application's API." This method, Resecurity added, could be abused to forge sessions for multiple distinct employee accounts, including those with elevated application privileges.
- Global scam-center crackdown
FBI Expands Hunt for Scam Centers
FBI Director Kash Patel has revealed that Operation Blackout has seized $17 billion, arrested hundreds, and freed thousands of trafficked workers, as law enforcement continues its effort to combat scam compounds that prey on the elderly by tricking them into investing their funds in non-existent cryptocurrency investment schemes. Operation Blackout is the agency's campaign to identify, disrupt, and dismantle foreign scam compounds targeting Americans. "And when these networks move – from Southeast Asia to the Middle East to Africa – we move with them," Patel said. "There is no safe haven for criminals targeting Americans." Patel has described the sites as purpose-built towns and cities where criminal syndicates confine workers and force them to contact targets through social media, phone calls, text messages, and Telegram.
One strange thing about this week's stories is how often the attackers look just as careless as the systems they're breaking into. Some leave their tools exposed. Others steal from their own partners. It would be easier to laugh at that if basic security mistakes weren't still giving them results. Being sloppy clearly doesn't stop anyone from causing damage.
There's also plenty here that won't be fixed with a quick patch. Old design choices, trusted software turning hostile, and systems that aren't ready for what's coming next. The details are worth a closer look, especially the boring ones. Those tend to be where the trouble starts. That's it for this week.
















Deja una respuesta