<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Mon, 01 Jun 2026 17:09:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request</title>
		<link>https://cybersecuritynews.com/ibm-websphere-server-remote-code-execution/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 17:09:10 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151462</guid>

					<description><![CDATA[<p>IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The flaw, tracked as CVE-2026-8633, affects environments that use the optional Web Server Plug-ins component, significantly elevating the risk for enterprise deployments that rely on WebSphere infrastructure. The vulnerability [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/ibm-websphere-server-remote-code-execution/">IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">IBM has disclosed a critical <a href="https://cybersecuritynews.com/ibm-security-verify-flaw/" target="_blank" rel="noreferrer noopener">security vulnerability</a> in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests.</p>



<p class="wp-block-paragraph">The flaw, tracked as CVE-2026-8633, affects environments that use the optional Web Server Plug-ins component, significantly elevating the risk for enterprise deployments that rely on WebSphere infrastructure.</p>



<p class="wp-block-paragraph">The vulnerability has been assigned a CVSS score of 9.8, highlighting its critical severity. It requires no authentication and can be exploited remotely, allowing attackers to <a href="https://cybersecuritynews.com/ibm-qradar-siem-vulnerability-2/" target="_blank" rel="noreferrer noopener">gain full control of affected systems</a>.</p>



<p class="wp-block-paragraph">Successful exploitation could result in complete compromise, affecting confidentiality, integrity, and availability.</p>



<p class="wp-block-paragraph">Given the widespread adoption of WebSphere in enterprise and government networks, the exposure is considered highly significant.</p>



<h2 id="h-ibm-websphere-rce-vulnerability" class="wp-block-heading"><strong>IBM WebSphere RCE Vulnerability</strong></h2>



<p class="wp-block-paragraph">The root cause of the issue lies in improper control of code generation, categorized under CWE-94. This weakness allows attackers to <a href="https://cybersecuritynews.com/ibm-identity-and-verify-access-vulnerabilities/" target="_blank" rel="noreferrer noopener">inject malicious payloads</a> into the system via crafted HTTP requests.</p>



<p class="wp-block-paragraph">Once processed by the vulnerable Web Server Plug-ins, these requests can trigger remote code execution.</p>



<p class="wp-block-paragraph">Additionally, the flaw introduces the risk of HTTP request smuggling, enabling attackers to <a href="https://cybersecuritynews.com/ibm-security-verify-access-flaw/" target="_blank" rel="noreferrer noopener">bypass security mechanisms</a> and manipulate backend communications.</p>



<p class="wp-block-paragraph">CVE-2026-8633 specifically affects IBM Web Server Plug-ins used alongside both traditional WebSphere Application Server and WebSphere Liberty deployments</p>



<p class="wp-block-paragraph">Impacted versions include WebSphere Application Server 8.5 and 9.0, as well as WebSphere Liberty 8.5 and 9.0, along with their corresponding plug-in versions.</p>



<p class="wp-block-paragraph">Because these plug-ins are commonly used to route requests between web servers and application servers, exploitation could provide attackers with a direct pathway into backend systems.</p>



<p class="wp-block-paragraph"><a href="https://www.ibm.com/support/pages/node/7274072" target="_blank" rel="noreferrer noopener nofollow">IBM has issued remediation guidance</a> and strongly recommends immediate action. Organizations are advised to apply interim fixes that address APAR PH71342 after upgrading to the required minimum fix pack levels.</p>



<p class="wp-block-paragraph">For WebSphere 9.0 environments, users should upgrade to Fix Pack 9.0.5.28 or later once available. Similarly, WebSphere 8.5 users are advised to update to Fix Pack 8.5.5.30 or a later version when released.</p>



<p class="wp-block-paragraph">In addition to patching, organizations should take proactive defensive measures. Monitoring HTTP traffic for anomalies, especially malformed or unexpected request patterns, can help detect exploitation attempts.</p>



<p class="wp-block-paragraph">Restricting external access to WebSphere plug-in endpoints and deploying <a href="https://cybersecuritynews.com/best-web-application-firewall-waf/" target="_blank" rel="noreferrer noopener">Web Application Firewall protections</a> can further reduce exposure. Security teams should also initiate threat hunting activities to identify any signs of compromise within affected environments.</p>



<p class="wp-block-paragraph">As threat actors increasingly target middleware and application infrastructure, vulnerabilities like CVE-2026-8633 underscore the importance of timely patching and layered security controls.</p>



<p class="wp-block-paragraph">Organizations using IBM WebSphere are urged to treat this issue as a priority and act swiftly to mitigate potential risks.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/ibm-websphere-server-remote-code-execution/">IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/IBM-WebSphere-Server-Vulnerable-to-remote-code-execution-Attack-Via-specially-crafted-request.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151462</post-id>	</item>
		<item>
		<title>Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks</title>
		<link>https://cybersecuritynews.com/magento-cache-plugin-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 17:03:51 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151505</guid>

					<description><![CDATA[<p>A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, or admin access required. Security researchers at Sansec uncovered an unauthenticated PHP object injection flaw in&#160;Mirasvit Cache Warmer, a full-page cache extension used by thousands of Magento and [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/magento-cache-plugin-vulnerability/">Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A critical security vulnerability has been discovered in a widely used <a href="https://cybersecuritynews.com/magento-input-validation-vulnerability/" target="_blank" rel="noreferrer noopener">Magento caching plugin</a> that allows attackers to remotely execute malicious code with no login, configuration changes, or admin access required.</p>



<p class="wp-block-paragraph">Security researchers at Sansec uncovered an unauthenticated PHP object injection flaw in&nbsp;Mirasvit Cache Warmer, a full-page cache extension used by thousands of Magento and Adobe Commerce storefronts.</p>



<p class="wp-block-paragraph">The vulnerability, tracked as&nbsp;CVE-2026-45247, carries a maximum-severity CVSS score of&nbsp;9.8 (Critical).</p>



<h2 id="h-magento-cache-plugin-vulnerability" class="wp-block-heading"><strong>Magento Cache Plugin</strong> <strong>Vulnerability</strong></h2>



<p class="wp-block-paragraph">Mirasvit Cache Warmer is designed to preload cached versions of store pages for different visitor types, varying by currency, customer group, and other session states.</p>



<p class="wp-block-paragraph">To do this, it packs session details into a cookie and sends them with each crawl request. On the server side, a plugin reads that cookie and adjusts the session accordingly before rendering the page.</p>



<p class="wp-block-paragraph">The critical problem: the plugin passes part of that cookie value directly to PHP&#8217;s native&nbsp;unserialize()&nbsp;function, with no class restrictions and no authentication checks.</p>



<p class="wp-block-paragraph">Because the cookie value is entirely client-side, an attacker can craft it to inject arbitrary PHP objects. This is known as <a href="https://cybersecuritynews.com/multiple-php-vulnerabilities/" target="_blank" rel="noreferrer noopener">PHP Object Injection</a> (CWE-502).</p>



<p class="wp-block-paragraph">When combined with a&nbsp;gadget chain, malicious logic built from classes already bundled within Magento and its dependencies, this object injection escalates directly into&nbsp;Remote Code Execution (RCE).</p>



<p class="wp-block-paragraph">The attack fires on every storefront request, not just internal cache-warming traffic, making any public-facing <a href="https://cybersecuritynews.com/adobe-magento-rce-vulnerability-exploited/" target="_blank" rel="noreferrer noopener">Magento store a potential target.</a></p>



<p class="wp-block-paragraph">All versions of Mirasvit Cache Warmer&nbsp;before 1.11.12&nbsp;are vulnerable. The extension ships bundled inside several other Mirasvit packages, meaning many merchants may be running it without realizing it.</p>



<p class="wp-block-paragraph"><a href="https://sansec.io/research/mirasvit-cache-warmer-object-injection" target="_blank" rel="noreferrer noopener nofollow">Sansec&#8217;s scanning found</a> approximately&nbsp;6,000 stores&nbsp;running Mirasvit extensions, with the actual number likely far higher, as CDNs like Cloudflare mask many installations from external fingerprinting.</p>



<p class="wp-block-paragraph">The exploit leaves a recognizable trail in web logs. Security teams should watch for storefront requests carrying a&nbsp;CacheWarmer&nbsp;cookie whose value begins with&nbsp;CacheWarmer:&nbsp;followed by a base64 string.</p>



<p class="wp-block-paragraph">Serialized PHP objects typically base64-encode to strings starting with&nbsp;Tz,&nbsp;Qz, or&nbsp;YT&nbsp;— making the pattern&nbsp;CacheWarmer:(Tz|Qz|YT)&nbsp;a strong indicator of an active exploitation attempt.</p>



<h2 id="h-mitigations" class="wp-block-heading"><strong>Mitigations</strong></h2>



<p class="wp-block-paragraph">Mirasvit released the patched version&nbsp;1.11.12 on May 25, 2026, within days of being notified. Store owners should act immediately:</p>



<p class="wp-block-paragraph"><strong>Update now:</strong> &nbsp;Upgrade Mirasvit Cache Warmer to version 1.11.12 or later.</p>



<p class="wp-block-paragraph"><strong>Block attacks:</strong> Deploy a<a href="https://cybersecuritynews.com/best-web-application-firewall-waf/" target="_blank" rel="noreferrer noopener"> web application firewall </a>capable of blocking serialization-based exploit attempts.</p>



<p class="wp-block-paragraph"><strong>Scan for compromise:</strong> Check for webshells, backdoors, or unexpected PHP files in&nbsp;pub/&nbsp;and other web-accessible directories.</p>



<p class="wp-block-paragraph"><strong>Audit installed packages:</strong> Confirm whether Cache Warmer is bundled inside other Mirasvit modules on your store.</p>



<p class="wp-block-paragraph">Sansec&#8217;s Shield customers were already protected from April 24, 2026, the same day the flaw was discovered. The CVE was formally assigned on May 26, 2026.</p>



<p class="wp-block-paragraph">Given that exploitation requires zero authentication and can be fully automated, unpatched stores remain at serious risk of full server compromise.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/magento-cache-plugin-vulnerability/">Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Critical-vulnerability-Magento-Cache-Plugin-Enables-remote-code-execution-Attacks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151505</post-id>	</item>
		<item>
		<title>Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors</title>
		<link>https://cybersecuritynews.com/mcp-toolbox-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 17:00:32 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151483</guid>

					<description><![CDATA[<p>A newly disclosed vulnerability, tracked as CVE-2026-9739, is raising security concerns across enterprise environments using MCP Toolbox, particularly those that rely on Server-Sent Events (SSE) for database connectivity. The flaw, currently awaiting NVD enrichment, allows attackers to exploit a DNS rebinding weakness that could lead to unauthorized access to backend systems. Security researchers identified that [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/mcp-toolbox-vulnerability/">Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly disclosed vulnerability, tracked as CVE-2026-9739, is raising security concerns across enterprise environments using MCP Toolbox, particularly those that rely on Server-Sent Events (SSE) for database connectivity.</p>



<p class="wp-block-paragraph">The flaw, currently awaiting NVD enrichment, allows attackers to <a href="https://cybersecuritynews.com/multiple-azure-devops-vulnerabilities/" target="_blank" rel="noreferrer noopener">exploit a DNS rebinding</a> weakness that could lead to unauthorized access to backend systems.</p>



<p class="wp-block-paragraph">Security researchers identified that the issue stems from a misconfigured cross-origin policy within the MCP Toolbox SSE implementation.</p>



<p class="wp-block-paragraph">Despite earlier efforts to enforce stricter origin controls during the beta phase, a critical security header remained overly permissive, exposing systems to cross-domain attacks.</p>



<h2 id="h-mcp-toolbox-vulnerability" class="wp-block-heading"><strong>MCP Toolbox Vulnerability</strong></h2>



<p class="wp-block-paragraph">The vulnerability is classified under CWE-942 (Permissive Cross-domain Policy with Untrusted Domains). It occurs because a hard-coded HTTP response header sets <a href="https://cybersecuritynews.com/nestjs-framework-vulnerability/" target="_blank" rel="noreferrer noopener">Access-Control-Allow-Origin</a> to a wildcard value.</p>



<p class="wp-block-paragraph">This configuration allows any external domain to interact with the SSE endpoint, effectively bypassing intended origin restrictions.</p>



<p class="wp-block-paragraph">Although developers introduced security flags such as allowed-origins and allowed-hosts, these controls were nullified by the wildcard policy.</p>



<p class="wp-block-paragraph">The issue specifically affects environments running MCP Toolbox with SSE enabled under the v2024-11-05 specification, particularly when enterprise database connectors are exposed via SSE endpoints.</p>



<p class="wp-block-paragraph">Attackers can leverage DNS rebinding techniques to trick a victim’s browser into sending authenticated requests to internal services, potentially exposing sensitive data or enabling <a href="https://cybersecuritynews.com/gemini-mcp-tool-0-day-vulnerability/" target="_blank" rel="noreferrer noopener">unauthorized database queries</a>.</p>



<p class="wp-block-paragraph">In a typical attack scenario, a victim visits a malicious website controlled by an attacker. The attacker then uses DNS rebinding to redirect browser requests to internal MCP Toolbox services.</p>



<p class="wp-block-paragraph">Because of the permissive cross-origin resource sharing configuration, the browser allows interaction with these internal endpoints. This ultimately enables the attacker to gain indirect access to enterprise database connectors.</p>



<p class="wp-block-paragraph">This form of attack is especially dangerous in cloud and hybrid environments where internal services are accessible through web interfaces, significantly increasing the attack surface.</p>



<p class="wp-block-paragraph"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9739" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-9739</a> is categorized as a DNS rebinding vulnerability caused by CORS misconfiguration and mapped to CWE-942.</p>



<p class="wp-block-paragraph">The affected component is the MCP Toolbox SSE handler, and the primary impact is unauthorized access to internal services. A CVSS score has not yet been assigned, as the NVD assessment is still pending.</p>



<h2 id="h-mitigation-and-fixes" class="wp-block-heading"><strong>Mitigation and Fixes</strong></h2>



<p class="wp-block-paragraph">Developers have addressed the vulnerability in recent updates by removing the wildcard origin header and enforcing strict origin validation.</p>



<p class="wp-block-paragraph">Organizations are strongly advised to upgrade MCP Toolbox to the latest patched version and avoid using permissive CORS policies in production environments.</p>



<p class="wp-block-paragraph">Restricting allowed origins to trusted domains, turning off unnecessary SSE endpoints, and monitoring network traffic for unusual internal requests are essential defensive measures.</p>



<p class="wp-block-paragraph">Security teams should also audit their deployments to identify <a href="https://cybersecuritynews.com/lenovo-driver-terminate-edr-processes/" target="_blank" rel="noreferrer noopener">exposed SSE endpoints</a> and ensure proper access control mechanisms are in place.</p>



<p class="wp-block-paragraph">The vulnerability was publicly disclosed through GitHub issue #3053 and resolved in pull request #3054 within the official MCP Toolbox repository.</p>



<p class="wp-block-paragraph">This incident highlights how misconfigured cross-origin policies in modern streaming technologies, such as SSE, can introduce critical security risks if not properly secured.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/mcp-toolbox-vulnerability/">Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Critical-MCP-Toolbox-Vulnerability-Impacts-enterprise-database-connectors.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151483</post-id>	</item>
		<item>
		<title>Android Banking Trojan OverlayPhantom Abuses Accessibility Service to Control Devices</title>
		<link>https://cybersecuritynews.com/android-banking-trojan-overlayphantom/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:09:13 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151507</guid>

					<description><![CDATA[<p>A dangerous new Android banking trojan called OverlayPhantom has been quietly targeting users across ten countries, placing banking credentials, financial data, and cryptocurrency accounts at serious risk. The malware has been active since May 2025 and spreads through malicious links disguised as downloads from trusted, well-known applications. What makes OverlayPhantom particularly alarming is how it [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/android-banking-trojan-overlayphantom/">Android Banking Trojan OverlayPhantom Abuses Accessibility Service to Control Devices</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A dangerous new Android banking trojan called OverlayPhantom has been quietly targeting users across ten countries, placing banking credentials, financial data, and cryptocurrency accounts at serious risk. </p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/hackers-hijacked-discord-invite-to-inject-malicious-links/" id="111105" target="_blank" rel="noreferrer noopener">malware has been active since May 2025 and spreads through malicious links</a> disguised as downloads from trusted, well-known applications.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What makes OverlayPhantom particularly alarming is how it gets onto a device. It uses a two-stage infection process, starting with a dropper app that pretends to be either ID Austria, the official Austrian government identity application, or the popular platform TikTok. </p>



<p class="wp-block-paragraph">Victims are tricked into installing what appears to be a routine system update, and from that point, the malware takes hold.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Analysts at Cyble Research and Intelligence Labs (CRIL) uncovered OverlayPhantom while investigating government-themed URL impersonation campaigns. </p>



<p class="wp-block-paragraph"><a href="https://cyble.com/blog/overlayphantom-android-banking-trojan/" id="https://cyble.com/blog/overlayphantom-android-banking-trojan/" target="_blank" rel="noreferrer noopener nofollow">Cyble said in a report</a> shared with Cyber Security News (CSN) that the malware targets more than 180 banking, financial services, and cryptocurrency applications across the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once installed, OverlayPhantom disguises itself as &#8220;Google Play Services,&#8221; making it nearly impossible for an average user to spot or remove. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCk7Taf89Oziy2xPZz8V8AGNCSEytSrHxhgI-oNIS0rGZat5DVjfXaSItDwfhyBagXQ-eNtqQXuZFd5OOWH8PEzMTsUKH05cOo_azi9r_I9wzZ2rgNRar_xLisP1t5txXHzXT22r1ENnOKVb9VgsSDJCV8YT5DQbPNKgakYn7_qcLnRU8yNDWRHRr4sG4/s16000/OverlayPhantom%E2%80%99s%20targets%20(Source%20-%20Cyble).webp" alt="OverlayPhantom’s targets (Source - Cyble)" /><figcaption class="wp-element-caption">OverlayPhantom’s targets (Source &#8211; Cyble)</figcaption></figure>
</div>


<p class="wp-block-paragraph">From that position, it abuses Android&#8217;s Accessibility Service, a built-in feature designed to help users with disabilities, to take persistent control of the infected device. </p>



<p class="wp-block-paragraph">The threat actor can then issue over 30 remote commands to manipulate the device without the victim ever noticing.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The breadth of its reach, paired with the technical sophistication behind its design, points to a financially motivated group running a large-scale fraud operation. </p>



<p class="wp-block-paragraph">With over 180 targeted apps and victims spread across Western markets, OverlayPhantom is far from a small campaign.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-android-banking-trojan-overlayphantom" class="wp-block-heading"><strong>Android Banking Trojan OverlayPhantom</strong></h2>



<p class="wp-block-paragraph">The Accessibility Service abuse is what gives OverlayPhantom its real power over infected devices. Once the victim grants this permission, guided through a tutorial embedded in the dropper app, the malware connects to its Command and Control (C&amp;C) server at IP address 199.217[.]99[.]122.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074"></a></p>



<p class="wp-block-paragraph">The C&amp;C traffic is divided across three dedicated ports: port 9091 for issuing commands, port 9092 for device status updates, and port 9090 for live screen streaming. </p>



<p class="wp-block-paragraph">This multi-port setup keeps communication running reliably and harder to block. The malware uses Android&#8217;s MediaProjection API to stream the victim&#8217;s screen in near real time using JPEG compression, giving the attacker a live view of everything on the device.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The remote command set covers a wide range of actions. The attacker can simulate taps, swipes, and long presses, lock the screen, manipulate clipboard contents, display fake notifications, and launch overlay windows to capture PIN codes or passwords. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieKC9AprI8fcdtCCHAvem2pR4ArENJcctm6_qvgM86Whd0aCBE5yhACAKQp_IGnvfQKNQtyLXcyP7GQl7Ep7u3VWtzt6NgkHMCJ337eDgdvd59OVxHW-eEYXfFQCrD0oPnTHvU71Vdl3tbt7y1fFxuvymgRKdP2cLcAL7Lvs6J21Ia8ipQZnyhy1YYSAo/s16000/Google%20Play%20Update%20lure%20to%20install%20OverlayPhantom%20(Source%20-%20Cyble).webp" alt="Google Play Update lure to install OverlayPhantom (Source - Cyble)" /><figcaption class="wp-element-caption">Google Play Update lure to install OverlayPhantom (Source &#8211; Cyble)</figcaption></figure>
</div>


<p class="wp-block-paragraph">These controls let the threat actor perform unauthorized transactions without the victim ever knowing.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-overlay-attacks-targeting-banking-and-cryptocurrency-apps" class="wp-block-heading"><strong>Overlay Attacks Targeting Banking and Cryptocurrency Apps</strong></h2>



<p class="wp-block-paragraph">OverlayPhantom keeps a hardcoded list of target applications embedded in its code. When the victim opens a banking or financial app, the malware silently checks whether that app is on its list. </p>



<p class="wp-block-paragraph">If there is a match, it pulls up a counterfeit HTML phishing page, renders it in a WebView layer, and places it over the legitimate application. The fake screen looks identical to the real one.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/new-phishing-attack-mimics-facebook-login-page/" id="117605" target="_blank" rel="noreferrer noopener">victim enters credentials believing they are logging into their actual bank</a> or crypto wallet. That data is instantly harvested and sent to the C&amp;C server without leaving any visible sign of compromise. </p>



<p class="wp-block-paragraph">This overlay technique is exactly what makes OverlayPhantom so effective and difficult for victims to detect.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiMqvmw8aVefbSnW8IeXIOCf1-Zim4H1ZzQrxseZf6K3IcfvMNNPkx_qw0xA-SQBa124gEgna2Dx0Qwu2lD6qtmkxqQH-kJz3Heo9bCY8MTrD1czDuagLVel9KBlrUG8mdhO0VQBM_zrv6P0vGWzFQ_y-NXjy3k2KQIZPJwgKalGP6q1ZlxzxgOscqbjE/s16000/Counterfeit%20HTML%20phishing%20pages%20in%20the%20APK%20file%20(Source%20-%20Cyble).webp" alt="Counterfeit HTML phishing pages in the APK file (Source - Cyble)" /><figcaption class="wp-element-caption">Counterfeit HTML phishing pages in the APK file (Source &#8211; Cyble)</figcaption></figure>
</div>


<p class="wp-block-paragraph">To stay protected, users should only download apps from official platforms like the Google Play Store and avoid clicking links received through SMS, email, or social media. </p>



<p class="wp-block-paragraph">Granting Accessibility Service permissions to any unfamiliar app should be avoided at all costs. Enabling multi-factor authentication on banking and financial apps adds a critical extra layer of defense, even when credentials are stolen. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/any-run-launches-android-os-support/" id="96504" target="_blank" rel="noreferrer noopener">Keeping Android OS and installed apps regularly updated</a> is equally important, as security patches often close the exact vulnerabilities that malware like OverlayPhantom exploits.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d5956d37-b36f-44f6-aa63-4ee5ac52d796/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.pdf?AWSAccessKeyId=ASIA2F3EMEYETNCONWHZ&amp;Signature=XrIq0e4m6ZqY8v7suVnZJxvLnyQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJHMEUCIGAD7w82OPZ%2BmYe9sHr1SBPpMlM0F5oXNnL1gHSzyjn8AiEAgnMZwl1lYJp%2FJwt%2FvVhMOrKhHHdh204qLZDn%2By4CMwwq8wQIDhABGgw2OTk3NTMzMDk3MDUiDOhhLuW5%2Fs0dU1B%2BsCrQBNVmdnV8XA0v7PIYwZDpdhfCQ12f4C4wbRFpoHHj%2FgxnbfiqG4y85lZazF%2FDaTOKG02%2BzLs4MiSbWwpk7%2Fw4T7VqMh5cK1oI%2BpuccfjVdqOljQLNnUDd2zbLyZ6la7%2F9x2ZDoYcOwLzqfZm4ZrWIqh9w4s0Tg%2BvOBM0fPM6UO3u1ZWUkNOTX%2FdHMbtbYxAFuYe8CAdTREOveslpnEXoizIyoDx%2FUddZur5iG6F%2B2L0SY%2FtagBGU%2B1s0omt13CMxolHFHpjje8BejuxAQRZ%2BUXFX1I%2BahXcFMYX8foriQgw%2B6UUHoKOML1O3GApWSoPJf8XJMIUtfkRMR65YUBidZjfb3UHd4VvT2l2nhxIPOnoi7lJmBxJdfCBkSbdsQMJmRJxD9%2BCpxuY6MLA0RqrKtAG%2FUr1NqrZU3a4qR7wu781QUNwWR6hRoZo8Z2kYS0FkZQf6YSbTqQEmPG2%2BST51z1ZxPG1X0JKf1GI8jyCDRKfCFsrrOTq%2Bbo2mLkTbWMfo0OHOdUm2mULh72TJ15EsGigzObwJKnKYTT3qUV%2FkI%2Frdg91KAWIzwzapkP%2B2XEhjsKlUmqdRl8Lwt2d5CoPqrbu4I%2Ft%2Fu5jLGPY%2FfSSaHI7TqLOXhomvwGvDfi116VeT9yVNseR8Jdog4rsP%2FtD3artv5hedBThQgJYurOP2R9T142nB%2BWBCJtXCI6QoPr9JR%2FbMbVEuRVPY6RDjPYsue8rfyyQn2TnR6bEVy%2Fz45UcUV8Pq2AiVeZBQd59bvswgFjOvcPzMP63QFMVmTB587jS8wjYb20AY6mAHSGfG9IsqCYoxqHOqX1BaA5eD8Mm2N0%2BEK4vjAjB5oB06QDxLti%2BYMoqo3l8oepIJm94zmbsit%2BAuvKur69H5frZcgq1MapUjJI5cMQydftgC5QXZ0DUIfIURmmGU2hZO9Tkny8ArzBQ3hfPfzmWHpghBZHS63gWQa4mqt1rruMHSSX7yK4OC9J8XF0fwG3rpdLSb9w%2B4QTw%3D%3D&amp;Expires=1780321074" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>URL</td><td>hxxps://bitlrewards-app[.]com/api/download/IDAustria</td><td>Distribution URL used to spread OverlayPhantom</td></tr><tr><td>IP</td><td>199.217[.]99[.]122</td><td>C&amp;C server IP address</td></tr><tr><td>File Hash (SHA-256)</td><td>9ef37376bfaa18e193cc72218924ad8ebf56d2667d348f0eae5ae6ec45ab8775f</td><td>OverlayPhantom malware sample hash</td></tr><tr><td>File Hash (SHA-256)</td><td>8b614a2918378063d6e6655b676ceb52ae65b1510e2cc08087fcac31acb7aeb8d</td><td>OverlayPhantom malware sample hash</td></tr><tr><td>File Hash (SHA-256)</td><td>dc1f2a75f3d5b5bd054a5367bd5015ebc90f3453d63c7cce438c12dc2ae86a</td><td>OverlayPhantom malware sample hash</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/android-banking-trojan-overlayphantom/">Android Banking Trojan OverlayPhantom Abuses Accessibility Service to Control Devices</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Android-Banking-Trojan-OverlayPhantom-Abuses-Accessibility-Service-to-Control-Devices.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151507</post-id>	</item>
		<item>
		<title>Microsoft Office for the Web and Teams Hit by File Access Outage</title>
		<link>https://cybersecuritynews.com/microsoft-office-teams-file-access/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:07:30 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151546</guid>

					<description><![CDATA[<p>Microsoft experienced a service disruption affecting users&#8217; ability to open files through Office for the Web and Microsoft Teams, with the company confirming resolution after investigating elevated error rates across its online productivity platform. The incident, tracked internally under MO1329446 in the Microsoft 365 Admin Center, began with widespread user reports of file-access failures across [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-office-teams-file-access/">Microsoft Office for the Web and Teams Hit by File Access Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft experienced a service disruption affecting users&#8217; ability to open files through Office for the Web and Microsoft Teams, with the company confirming resolution after investigating elevated error rates across its online productivity platform.</p>



<p class="wp-block-paragraph">The incident, tracked internally under MO1329446 in the Microsoft 365 Admin Center, began with widespread user reports of file-access failures across web-based Office experiences.</p>



<p class="wp-block-paragraph">Users attempting to open documents, spreadsheets, or presentations via the browser-based Office suite or Teams encountered errors, disrupting collaboration workflows for potentially millions of enterprise users globally.</p>



<p class="wp-block-paragraph">Microsoft&#8217;s engineering team initially acknowledged the issue, stating they were &#8220;investigating reports that some users are unable to open files in Office for the Web or <a href="https://cybersecuritynews.com/microsoft-teams-vulnerability-spoofing/" target="_blank" rel="noreferrer noopener">Microsoft Teams</a>.&#8221; Shortly after, the team confirmed detection of elevated error rates spanning multiple Office for the Web services.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<div class="embed-x"><blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr">We’re investigating reports that some users are unable to open files in Office for the web or Microsoft Teams. For more information, please see MO1329446 in the admin center.</p>&mdash; Microsoft 365 Status (@MSFT365Status) <a href="https://x.com/MSFT365Status/status/2061445951143686267?ref_src=twsrc%5Etfw">June 1, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></div>
</div></figure>



<p class="wp-block-paragraph">Engineers conducted service telemetry analysis to identify the failure scope, correlating error patterns across service dependencies to determine the root cause and remediation path.</p>



<p class="wp-block-paragraph">The cross-dependency investigation suggests the disruption may have stemmed from a shared backend component or infrastructure layer serving multiple Microsoft 365 services simultaneously, a pattern consistent with prior Azure-backed service incidents.</p>



<p class="wp-block-paragraph">Microsoft has not yet publicly disclosed whether the incident originated from a code deployment, configuration change, or underlying infrastructure fault.</p>



<p class="wp-block-paragraph">Microsoft confirmed that the impact is no longer occurring and has published final<a href="https://admin.cloud.microsoft/?#/servicehealth/:/alerts/MO1329446" target="_blank" rel="noreferrer noopener nofollow"> incident details under MO1329446</a> in the Microsoft 365 Admin Center. Affected organizations with active Microsoft 365 subscriptions can review the post-incident report through their admin portals for detailed timelines and remediation steps.</p>



<p class="wp-block-paragraph">Enterprises relying on Microsoft 365 for critical workflows are advised to monitor the <a href="https://status.cloud.microsoft/" target="_blank" rel="noreferrer noopener nofollow">Microsoft 365 Service Health Dashboard</a> for real-time status updates and configure admin center alerts to receive proactive notifications during future service disruptions.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-office-teams-file-access/">Microsoft Office for the Web and Teams Hit by File Access Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Microsoft-Office-Teams-File-Access.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151546</post-id>	</item>
		<item>
		<title>Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</title>
		<link>https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:06:10 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151532</guid>

					<description><![CDATA[<p>Attackers are actively exploiting misconfigurations in Docker and Kubernetes environments to break out of containers and take full control of the underlying host systems. What was once a niche concern has grown into a serious and escalating threat, with attackers running multi-stage operations that extend well beyond a single compromised container. Modern container platforms are [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/">Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Attackers are actively exploiting misconfigurations in Docker and Kubernetes environments to break out of containers and take full control of the underlying host systems. </p>



<p class="wp-block-paragraph">What was once a niche concern has grown into a serious and escalating threat, with attackers running <a href="https://cybersecuritynews.com/storm-1977-hackers-compromised-200-crypto-mining-containers/" id="102714" target="_blank" rel="noreferrer noopener">multi-stage operations that extend well beyond a single compromised container</a>.</p>



<p class="wp-block-paragraph">Modern container platforms are designed to isolate applications from one another and from the host. But that isolation is only as strong as the configuration behind it. </p>



<p class="wp-block-paragraph">When settings are applied carelessly or left at insecure defaults, the wall between a container and its host becomes dangerously thin, giving attackers a direct path to escalate privileges.</p>



<p class="wp-block-paragraph"><a href="https://securelist.com/container-attack-vectors/120010/" id="https://securelist.com/container-attack-vectors/120010/" target="_blank" rel="noreferrer noopener nofollow">Researchers at Securelist said in a report</a> shared with Cyber Security News (CSN) that these attacks have evolved into multi-stage scenarios involving supply chain compromises, Kubernetes secrets theft, orchestration API abuse, and container escape attempts. </p>



<p class="wp-block-paragraph">In one notable case, the APT group TeamPCP compromised Checkmarx KICS across multiple attack chains, poisoning a Docker Hub repository to steal Kubernetes secrets.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The threat is not limited to exotic zero-day exploits. Misconfigurations are far more common as the root cause of successful breaches than complex kernel vulnerabilities. Attackers look for the low-hanging fruit first, and insecure container configurations remain plentiful across enterprise environments.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153"></a></p>



<p class="wp-block-paragraph">Once inside a compromised container, an attacker rarely needs to do much to find something valuable. Containers routinely hold API keys, SSH keys, access tokens, service credentials, and Kubernetes ServiceAccount tokens. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgavsLD2zTD9w0od5U2yT07rCTkDzPMtoY0rC9j-llBboKbmY0XT2unuSMWppT2PnqgiqqL2tsO6C9CiFHflwGe4KsMNNIrDVGS9_wrSSdW7i-W8zk3e4iM7lf2xBoHB33dzaPqqxS8a2hEcoNj9XVpwbJFcLySmDLSm9szRCbrElFDBAt8IVisTtZHQJ4/s16000/Container%20escape%20attack%20(Source%20-%20Securelist).webp" alt="Container escape attack (Source - Securelist)" /><figcaption class="wp-element-caption">Container escape attack (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">These assets alone can be enough to pivot into cloud infrastructure or establish long-term persistence without ever escaping the container.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-attackers-abuse-docker-and-kubernetes-misconfigurations" class="wp-block-heading"><strong>Attackers Abuse Docker and Kubernetes Misconfigurations</strong></h2>



<p class="wp-block-paragraph">The most dangerous configuration a container operator can enable is the privileged flag. When a container runs with this setting, it receives all Linux capabilities and direct access to host devices, <a href="https://cybersecuritynews.com/apple-carplay-vulnerability-exploited/" id="125638" target="_blank" rel="noreferrer noopener">making it functionally equivalent to root access</a> on the host machine. </p>



<p class="wp-block-paragraph">Using a utility like <code>nsenter</code>, an attacker can spawn a shell outside the container and move freely on the underlying system.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Specific Linux capabilities also open the door to escapes when improperly assigned. The <code>CAP_SYS_ADMIN</code> capability allows a container to mount file systems and interact with kernel parameters. </p>



<p class="wp-block-paragraph">Combined with access to host directories through the <code>hostPath</code> parameter, an attacker can mount the host disk inside the container and overwrite critical system files. <code>CAP_SYS_MODULE</code> lets an attacker load a malicious kernel module that triggers a reverse shell from kernel space.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdbaY0pyQAeI6h5NunXS6q8SJM309I4QxDTlJawQ7-5nEIUPLAwJeu-DhEUkkyLXnKtd6ix4e32_ugWjltpU8u0EHXqP3o8I9BqAAc4sgGLzU_MKOe1q4s8Isosn2SQ3V_-x7ajnMdrnLE_wR90XrXQmE9x8-4GHqLTtELfYmE4f33QYy4WGCnjqM3a3Q/s16000/Container%20and%20C2%20Host%20(Source%20-%20Securelist).webp" alt="Container and C2 Host (Source - Securelist)" /><figcaption class="wp-element-caption">Container and C2 Host (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph"><code>CAP_SYS_PTRACE</code> becomes dangerous when the host PID namespace is shared via <code>hostPID: true</code>. </p>



<p class="wp-block-paragraph">An attacker can then attach to host processes, inject code, and extract sensitive data from memory. <code>CAP_NET_ADMIN</code> enables network stack manipulation and, when combined with <code>hostNetwork: true</code>, opens the door to traffic interception across the environment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Orchestration APIs present an equally serious risk. An exposed Docker API accessible over TCP without authentication gives an attacker remote administrative access to the host. </p>



<p class="wp-block-paragraph">A compromised Kubernetes token with weak RBAC policies can allow deployment of privileged pods and a full cluster takeover with just a few API calls.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-supply-chain-attacks-targeting-container-infrastructure" class="wp-block-heading"><strong>Supply Chain Attacks Targeting Container Infrastructure</strong></h2>



<p class="wp-block-paragraph">Beyond runtime misconfigurations, attackers are going after containers before they are even deployed. Supply chain attacks target the image build and delivery process, injecting malicious code at stages where organizations are least likely to look. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/docker-hub-pushing-malware/" id="63576" target="_blank" rel="noreferrer noopener">Developers who pull public images from Docker Hub without checking their origin</a> are especially vulnerable, since threat actors regularly publish tainted images that mimic legitimate tools.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgv1CP9QwXvWEp9iZXbEsZC7YiT335oYnPTt_A7vsoIJ3VcHoQdOolDXMO5Pl1q_5BL2GLjyA_QaodIpVVeM4nR-ERgaNFNZYVY7-Xh0Mj77zJO3I4RD1lQw_DaWoNvhjtLCkonVzjGEp0JpKT369l5ATMsJIHi93pVvswMiJnPxtyN8Dg_xyPOx7WrPKI/s16000/API%20request%20(Source%20-%20Securelist).webp" alt="API request (Source - Securelist)" /><figcaption class="wp-element-caption">API request (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">CI/CD pipelines are another high-value target. These systems hold elevated privileges and broad infrastructure access. </p>



<p class="wp-block-paragraph">By compromising a single pipeline stage, an attacker can modify Docker image builds, quietly adding hidden scripts or remote management tools, while the container appears legitimate on the outside.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">To defend against these threats, teams should audit container configurations regularly and avoid running containers with the privileged flag. </p>



<p class="wp-block-paragraph">All images should be verified before use, RBAC policies should be tightened, and CI/CD pipelines treated as critical infrastructure with strict access controls. Runtime monitoring and supply chain validation are essential parts of any secure container deployment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/">Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151532</post-id>	</item>
		<item>
		<title>SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</title>
		<link>https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 14:42:22 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151509</guid>

					<description><![CDATA[<p>A well-known social engineering campaign called SmartApeSG is back in the spotlight, this time using ClickFix scripts to quietly plant remote access malware on Windows computers. The campaign lures victims through fake verification pages that trick them into running a malicious script without realizing the full damage it causes. What makes this wave especially concerning [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/">SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A well-known social engineering campaign called SmartApeSG is back in the spotlight, this time using ClickFix scripts to quietly plant remote access malware on Windows computers. </p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/new-clickfix-campaign-hijacks-facebook-sessions/" id="140399" target="_blank" rel="noreferrer noopener">campaign lures victims through fake verification pages</a> that trick them into running a malicious script without realizing the full damage it causes. </p>



<p class="wp-block-paragraph">What makes this wave especially concerning is that the attack does not stop at one piece of malware. It delivers a second, more powerful tool once it gains a foothold inside the system.</p>



<p class="wp-block-paragraph">The infection chain starts when a user visits a compromised or malicious website displaying a fake &#8220;verification&#8221; page. This page instructs the visitor to copy and run a PowerShell or similar script, which is the ClickFix technique. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVgRkQdnMT-xhExUADKQCBolc3NrEH_ie6saolBi0n9aASW67-Rz1IQW-7-Kfti7u696AU-9EMQwHAmX5xElHA8vUwoo3G4SksokJjq43Cau8VWbv1hxKMWhh7PzJyiaVcDHiIG-x0z0kyqAyS-YE-KDKkQS4GgCAkaOua8valHvPwtl5Dx0beXPiXiHM/s16000/Fake%20verification%20page%20with%20ClickFix%20instructions%20from%20the%20SmartApeSG%20campaign%20(Source%20-%20Internet%20Storm%20Center).webp" alt="Fake verification page with ClickFix instructions from the SmartApeSG campaign (Source - Internet Storm Center)" /><figcaption class="wp-element-caption">Fake verification page with ClickFix instructions from the SmartApeSG campaign (Source &#8211; Internet Storm Center)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once the script runs, it silently reaches out to attacker-controlled servers and pulls down the first stage of the infection. The victim sees nothing unusual on their screen, while the attacker gains quiet and persistent access to the machine.</p>



<p class="wp-block-paragraph"><a href="https://isc.sans.edu/diary/Unidentified+RAT+pushes+NetSupport+RAT/33034" id="https://isc.sans.edu/diary/Unidentified+RAT+pushes+NetSupport+RAT/33034" target="_blank" rel="noreferrer noopener nofollow">Internet Storm Center said in a report</a> shared with Cyber Security News (CSN) that they identified the campaign after observing a suspicious infection on May 27, 2026. </p>



<p class="wp-block-paragraph">Researcher Brad Duncan noted that an unidentified RAT had been generating encoded traffic to a command and control server since at least April 2026. </p>



<p class="wp-block-paragraph">The discovery confirmed that this campaign had been quietly running for several weeks before it was formally documented and published.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What sets this attack apart is its deliberate two-stage design. The first stage drops an unidentified RAT that sends encoded traffic to its C2 server over TCP port 443, making it blend in with regular web traffic. </p>



<p class="wp-block-paragraph">Once the initial RAT is in place, it pulls in a second payload: a malicious package of NetSupport Manager RAT, a legitimate remote access tool that attackers have repurposed to take unauthorized control of infected machines.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The entire process is built to stay quiet and survive reboots. After the NetSupport RAT is installed and made persistent on the host, the scripts used to set it up are deleted automatically, removing traces of the initial compromise. </p>



<p class="wp-block-paragraph">This cleanup step makes forensic investigation harder and reveals the careful level of planning behind the campaign.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-smartapesg-campaign-uses-clickfix-scripts" class="wp-block-heading"><strong>SmartApeSG Campaign Uses ClickFix Scripts</strong></h2>



<p class="wp-block-paragraph">The SmartApeSG campaign uses a fake browser verification page as its entry point, a tactic that has grown increasingly popular among threat actors. </p>



<p class="wp-block-paragraph">Visitors are told to run a script to &#8220;verify&#8221; their identity, which instead executes the ClickFix payload. The script then contacts attacker infrastructure to fetch a ZIP archive containing the initial RAT package from a remote server.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8HoF7khTCP2aQ0SWeh0GqbYtj9U8BMBpyYh2YHq9UKnIU5EEEQ2okNILhGUNVDsZEiSHUqTWbMzT9_fLJpHhrgoVwFCm-2cDBBFzND0hq9ROR_CHqmekIQ_x6fLlZ1ktUE6rF6JZR7Uk1JYi3JzRDKW548HxVfaGYcCjsOg4JwYxLxpf0ZOW4yqoqHw4/s16000/Initial%20RAT%20malware%20on%20an%20infected%20Windows%20host%20(Source%20-%20Internet%20Storm%20Center).webp" alt="Initial RAT malware on an infected Windows host (Source - Internet Storm Center)" /><figcaption class="wp-element-caption">Initial RAT malware on an infected Windows host (Source &#8211; Internet Storm Center)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once extracted and executed, the initial RAT begins sending encoded traffic to its C2 server at a fixed IP address over port 443. </p>



<p class="wp-block-paragraph">The use of encoded, non-SSL traffic on that port is unusual and helps the <a href="https://cybersecuritynews.com/macos-malware-leverages-google-ads/" id="149578" target="_blank" rel="noreferrer noopener">malware avoid detection tools that expect standard HTTPS</a> on that port. The RAT then pulls down follow-up files through the same C2 channel to prepare the system for the next stage of the attack.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-netsupport-rat-deployed-as-persistent-follow-up-payload" class="wp-block-heading"><strong>NetSupport RAT Deployed as Persistent Follow-Up Payload</strong></h2>



<p class="wp-block-paragraph">The second stage delivers a malicious NetSupport Manager RAT package via a CAB file that is fetched and extracted to the system. </p>



<p class="wp-block-paragraph">A batch script called <code>token.bat</code> handles the extraction and installation, while a VBScript file called <code>processor.vbs</code> triggers the batch script. Together, these components install the NetSupport RAT and configure it to run automatically whenever the system restarts.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Defenders are advised to monitor for unusual PowerShell execution tied to browser events, as this is a clear sign of the ClickFix technique being abused. Blocking access to suspicious or newly registered domains can also reduce the overall risk. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/security-teams-shrink-as-automation-rises/" id="100650" target="_blank" rel="noreferrer noopener">Security teams should watch for encoded traffic</a> over port 443 that does not follow normal SSL/TLS patterns, as this is a known behavior of the initial RAT in this chain. Since the domains and file hashes used in this campaign rotate daily, checking the @monitorsg feed on Mastodon is recommended for the latest indicators.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/secure-util.js</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/private-template?c66kjD5i</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/legacy-worker.js?18b3825af007e53d</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>IP Address</td><td>178.156.165[.]82</td><td>ClickFix script C2 traffic</td></tr><tr><td>IP Address</td><td>178.156.173[.]194</td><td>ClickFix script C2 traffic</td></tr><tr><td>URL</td><td>hxxps[:]//silverharvestnetwork[.]com/check</td><td>ClickFix script C2 traffic; also hosts initial RAT ZIP archive</td></tr><tr><td>IP Address</td><td>89.110.110[.]119:443</td><td>Initial RAT C2 server (TCP port 443, encoded traffic)</td></tr><tr><td>IP Address</td><td>185.163.47[.]217:443</td><td>NetSupport RAT C2 server</td></tr><tr><td>SHA256</td><td>1514b1268e9dc6d2f37137aa38c756cb4bf8186ac9235d6863b78e7f8bbbe976</td><td>ZIP archive containing initial RAT software package</td></tr><tr><td>SHA256</td><td>469bac8e10f50263e8ff0806e6ba126bb4cc660799129a8653eab3f8ec7201e5</td><td>processor.vbs — initial VBScript that runs token.bat</td></tr><tr><td>SHA256</td><td>9c7eda2c4d3aaa8746495741bef57a07de180f0409409faf0f91658e88ba33f5</td><td>token.bat — batch script that installs and persists NetSupport RAT</td></tr><tr><td>SHA256</td><td>7ba5481c873bb3081442561f749f590badd72ef249fddfe993e30b28dc0c2112</td><td>setup.cab — CAB file containing malicious NetSupport RAT package</td></tr><tr><td>File Path</td><td>C:\ProgramData\processor.vbs</td><td>Initial VBScript dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\token.bat</td><td>Batch script dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\setup.cab</td><td>CAB archive dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\UpdateInstaller\</td><td>Extraction directory for NetSupport RAT contents</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/">SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151509</post-id>	</item>
		<item>
		<title>Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</title>
		<link>https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 14:34:58 +0000</pubDate>
				<category><![CDATA[Cyber Attack News]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151518</guid>

					<description><![CDATA[<p>A significant supply chain attack on June 1, 2026, targeting over 30 official packages under the @redhat-cloud-services npm scope. The campaign, dubbed &#8220;Miasma: The Spreading Blight,&#8221; is a new variant of the Mini Shai-Hulud malware family a sophisticated credential-stealing worm previously linked to threat actor group TeamPCP. This is not a typosquatting campaign. The attackers [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/">Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A significant supply chain attack on June 1, 2026, targeting over 30 official packages under the @redhat-cloud-services npm scope.</p>



<p class="wp-block-paragraph">The campaign, dubbed &#8220;Miasma: The Spreading Blight,&#8221; is a new variant of the <a href="https://cybersecuritynews.com/hackers-compromise-antv-packages/" target="_blank" rel="noreferrer noopener">Mini Shai-Hulud malware family</a>  a sophisticated credential-stealing worm previously linked to threat actor group TeamPCP.</p>



<p class="wp-block-paragraph">This is not a typosquatting campaign. The attackers hijacked a legitimate, trusted npm namespace and published backdoored versions of widely-used frontend components, API clients, and developer tooling.</p>



<p class="wp-block-paragraph">According to <a href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" target="_blank" rel="noreferrer noopener nofollow">Aikido</a> and <a href="https://research.jfrog.com/post/shai-hulud-miasma-redhat-cloud-services/" target="_blank" rel="noreferrer noopener nofollow">JFrog</a> detections, the malicious packages were published via GitHub Actions OIDC tokens, indicating the CI/CD pipeline itself was compromised, not individual developer accounts.</p>



<p class="wp-block-paragraph">Each poisoned package embeds a preinstall lifecycle hook in its <code>package.json</code>:</p>



<pre class="wp-block-preformatted">json<code>"scripts": { "preinstall": "node index.js" }</code></pre>



<p class="wp-block-paragraph">This executes a 4.2 MB obfuscated payload automatically during every <code>npm install</code>, before any application code runs. The loader uses a multi-stage decryption chain — numeric character arrays, a ROT-style transform, and AES-128-GCM blobs — to evade static detection, before dropping a transient Bun-based payload to <code>/tmp/p*.js</code> for execution.</p>



<p class="wp-block-paragraph">Once active, the malware performs a sweeping credential collection targeting:</p>



<ul class="wp-block-list">
<li><strong>GitHub tokens</strong> — classic, fine-grained, and GitHub Actions OIDC tokens</li>



<li><strong>Cloud credentials</strong> — AWS access keys, GCP service account files, Azure service principal and managed identity tokens</li>



<li><strong>Infrastructure secrets</strong> — Kubernetes service account tokens and kubeconfig files, HashiCorp Vault tokens</li>



<li><strong>Developer tooling</strong> — npm and PyPI publish tokens, SSH private keys, Docker registry credentials, GPG keys, <code>.env</code> files across the filesystem</li>
</ul>



<p class="wp-block-paragraph">In cloud environments, the malware goes beyond static files. It actively queries <a href="https://cybersecuritynews.com/typosquatted-npm-packages-steal-cloud-and-ci-cd-secrets/" target="_blank" rel="noreferrer noopener">AWS Secrets Manager</a>, SSM Parameter Store, Azure Key Vault, and GCP Secret Manager when permissions allow. GitHub Actions runners are a prime target: the payload reads secrets directly from runtime process memory, bypassing workflow log masking entirely.</p>



<p class="wp-block-paragraph">A notable evasion technique in this wave involves disguising exfiltration traffic to <code>api.anthropic.com/v1/api</code> — a legitimate-looking domain that blends into network logs at organizations using Anthropic services.</p>



<p class="wp-block-paragraph">The <code>/v1/api</code> path is not a valid Anthropic route, suggesting attackers chose it purely for camouflage. Defenders should hunt for node or Bun processes contacting this host from CI runners or developer machines.</p>



<p class="wp-block-paragraph">The malware also uses a GitHub dead-drop model, creating public repositories under victim accounts with the description <code>Miasma: The Spreading Blight</code> and committing stolen credentials as JSON result files.</p>



<p class="wp-block-paragraph">The malware installs persistent monitoring services — <code>kitty-monitor.service</code> on Linux and <code>com.user.kitty-monitor.plist</code> on macOS — that poll for remote instructions. It also injects hooks into AI developer tools including Claude, Codex, Gemini, Copilot, Kiro, and opencode, and adds VS Code folder-open tasks that re-execute the payload.</p>



<p class="wp-block-paragraph">Most critically, a destructive token monitor (<code>gh-token-monitor</code>) watches stolen GitHub tokens. If a token is revoked before persistence is removed, it can execute destructive commands such as wiping the user&#8217;s home directory.</p>



<p class="wp-block-paragraph">Incident responders must isolate machines and remove persistence before revoking any tokens.</p>



<h2 id="h-indicators-of-compromise" class="wp-block-heading"><strong>Indicators of Compromise</strong></h2>



<p class="wp-block-paragraph">Any project that installed the following package versions on or after June 1, 2026 should be treated as compromised: Here is the complete IOC table for all 31 compromised <code>@redhat-cloud-services</code> npm packages:</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>#</th><th>Package Name</th><th>Malicious Version</th></tr></thead><tbody><tr><td>1</td><td>@redhat-cloud-services/chrome</td><td>2.3.1</td></tr><tr><td>2</td><td>@redhat-cloud-services/compliance-client</td><td>4.0.3</td></tr><tr><td>3</td><td>@redhat-cloud-services/config-manager-client</td><td>5.0.4</td></tr><tr><td>4</td><td>@redhat-cloud-services/entitlements-client</td><td>4.0.11</td></tr><tr><td>5</td><td>@redhat-cloud-services/eslint-config-redhat-cloud-services</td><td>3.2.1</td></tr><tr><td>6</td><td>@redhat-cloud-services/frontend-components</td><td>7.7.2</td></tr><tr><td>7</td><td>@redhat-cloud-services/frontend-components-advisor-components</td><td>3.8.2</td></tr><tr><td>8</td><td>@redhat-cloud-services/frontend-components-config</td><td>6.11.3</td></tr><tr><td>9</td><td>@redhat-cloud-services/frontend-components-config-utilities</td><td>4.11.2</td></tr><tr><td>10</td><td>@redhat-cloud-services/frontend-components-notifications</td><td>6.9.2</td></tr><tr><td>11</td><td>@redhat-cloud-services/frontend-components-remediations</td><td>4.9.2</td></tr><tr><td>12</td><td>@redhat-cloud-services/frontend-components-testing</td><td>1.2.1</td></tr><tr><td>13</td><td>@redhat-cloud-services/frontend-components-translations</td><td>4.4.1</td></tr><tr><td>14</td><td>@redhat-cloud-services/frontend-components-utilities</td><td>7.4.1</td></tr><tr><td>15</td><td>@redhat-cloud-services/hcc-feo-mcp</td><td>0.3.1</td></tr><tr><td>16</td><td>@redhat-cloud-services/hcc-kessel-mcp</td><td>0.3.1</td></tr><tr><td>17</td><td>@redhat-cloud-services/hcc-pf-mcp</td><td>0.6.1</td></tr><tr><td>18</td><td>@redhat-cloud-services/host-inventory-client</td><td>5.0.3</td></tr><tr><td>19</td><td>@redhat-cloud-services/insights-client</td><td>4.0.4</td></tr><tr><td>20</td><td>@redhat-cloud-services/integrations-client</td><td>6.0.4</td></tr><tr><td>21</td><td>@redhat-cloud-services/javascript-clients-shared</td><td>2.0.8</td></tr><tr><td>22</td><td>@redhat-cloud-services/notifications-client</td><td>6.1.4</td></tr><tr><td>23</td><td>@redhat-cloud-services/patch-client</td><td>4.0.4</td></tr><tr><td>24</td><td>@redhat-cloud-services/quickstarts-client</td><td>4.0.11</td></tr><tr><td>25</td><td>@redhat-cloud-services/rbac-client</td><td>9.0.3</td></tr><tr><td>26</td><td>@redhat-cloud-services/remediations-client</td><td>4.0.4</td></tr><tr><td>27</td><td>@redhat-cloud-services/rule-components</td><td>4.7.2</td></tr><tr><td>28</td><td>@redhat-cloud-services/sources-client</td><td>3.0.10</td></tr><tr><td>29</td><td>@redhat-cloud-services/tsc-transform-imports</td><td>1.2.2</td></tr><tr><td>30</td><td>@redhat-cloud-services/types</td><td>3.6.1</td></tr><tr><td>31</td><td>@redhat-cloud-services/vulnerabilities-client</td><td>2.1.8</td></tr></tbody></table><figcaption class="wp-element-caption">If any of these package versions were installed in your environment on or after June 1, 2026, immediately treat all GitHub tokens, npm tokens, cloud credentials (AWS, GCP, Azure), Kubernetes service account tokens, SSH keys, and CI/CD secrets as compromised. Isolate affected machines before revoking any tokens to avoid triggering the Miasma dead-man switch.</figcaption></figure>



<h2 id="h-mitigation-steps" class="wp-block-heading"><strong>Mitigation Steps</strong></h2>



<ul class="wp-block-list">
<li>Run <code>npm uninstall</code> on all affected packages and regenerate lockfiles from trusted metadata</li>



<li>Use <code>npm ci --ignore-scripts</code> in CI pipelines as a temporary safeguard</li>



<li>Remove <code>kitty-monitor</code> and <code>gh-token-monitor</code> persistence files from all affected machines before revoking tokens</li>



<li>Inspect <code>.claude/settings.json</code>, <code>.vscode/tasks.json</code>, and <code>~/.config/index.js</code> for injected hooks</li>



<li>Audit npm and GitHub accounts for unexpected patch-version publishes or newly created repositories matching the <code>Miasma: The Spreading Blight</code> description</li>



<li>Rotate <strong>all</strong> exposed credentials — GitHub tokens, npm tokens, cloud keys, SSH keys, Vault tokens, and Kubernetes service account tokens — only after persistence is confirmed removed</li>



<li>Rebuild affected CI runners and developer workstations from clean images</li>
</ul>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/">Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Red-Hat-Cloud-Services-npm-Packages.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151518</post-id>	</item>
		<item>
		<title>Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</title>
		<link>https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 12:40:00 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151486</guid>

					<description><![CDATA[<p>Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/">Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. </p>



<p class="wp-block-paragraph">The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat group operating under several known aliases. </p>



<p class="wp-block-paragraph">Security researchers have been tracking a rapid surge in activity that shows no signs of stopping. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a>The threat group, known as Screening Serpens and also identified as UNC1549, Smoke Sandstorm, and Iranian Dream Job, has been active since at least 2022. </p>



<p class="wp-block-paragraph">Historically focused on Middle Eastern targets, the group expanded into Western Europe in late 2025. Their preferred targets sit inside high-value sectors including aerospace, defense manufacturing, and telecommunications. </p>



<p class="wp-block-paragraph">They reach victims through personalized social engineering, using fake job listings and spoofed meeting invitations to lure professionals into downloading malicious files.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Unit 42 researchers identified six new remote access Trojan (RAT) variants deployed between February and April 2026, grouped into two distinct malware families named MiniUpdate and MiniJunk V2. </p>



<p class="wp-block-paragraph"><a href="https://unit42.paloaltonetworks.com/screening-serpens-iran-nexus-apt-new-rat-variants/" id="https://unit42.paloaltonetworks.com/screening-serpens-iran-nexus-apt-new-rat-variants/" target="_blank" rel="noreferrer noopener nofollow">Unit 42 said in a report</a> shared with Cyber Security News (CSN) that the campaigns align closely with the conflict timeline, with coordinated attacks hitting entities in the U.S. and Israel in late March, followed by targets in the UAE and another Middle Eastern country in mid-April 2026.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Both <a href="https://cybersecuritynews.com/21-new-malware-families-mac-attack/" id="58089" target="_blank" rel="noreferrer noopener">malware families begin their infection chains through spear phishing</a>. Victims receive what appears to be a recruitment portal or a video conferencing app installer. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3MmeJv87D0iDibUFyZ51q7fXQppDakIPL8W0I6ySc4ne-Thg9FrW1Tp17qtqaOwR9lkVqb6Da_XmUHu6hBBMJAevwn2M1-ciyLZ5Am9EmynqNBS73GXDghJIh4R-yWulOIKnxzYLPYLm_9Rxam43HdVibWU8ueEk2y534eI4rq3Ygrup3UOaxpidzaYg/s16000/Contents%20of%20the%20archive%20(Source%20-%20Unit42).webp" alt="Contents of the archive (Source - Unit42)" /><figcaption class="wp-element-caption">Contents of the archive (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once they interact with the file, a silent multi-stage infection chain kicks off in the background, and the attacker quietly gains full control over the compromised machine.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-appdomainmanager-hijacking" class="wp-block-heading"><strong>AppDomainManager Hijacking</strong></h2>



<p class="wp-block-paragraph">The most significant technical leap in this campaign is the use of a technique called AppDomainManager hijacking. </p>



<p class="wp-block-paragraph">This method targets the initialization phase of .NET applications by modifying a legitimate configuration file, allowing malicious code to run before the host application even finishes loading. Since this happens so early, most security tools do not get a chance to detect it.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">By adding a few targeted XML lines to the application&#8217;s config file, attackers instruct the .NET runtime to disable its own security features. </p>



<p class="wp-block-paragraph">They turn off Event Tracing for Windows (ETW), the primary data source that modern endpoint detection and response (EDR) platforms rely on to monitor .NET activity. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtm0Rlqde_5botNHVggG36gy5kfLup-qFTCzxcvVm8fXjS69J3q4nM-N1lsEQdDvtaelxJydqYYVTZD3Tfr0k14tJDIXeT1tNLe91kRLXkk3IRLpU0iH-0Raid3Ue4qQhIUA4cbPRQHQGDKhyphenhyphenFrvxcTou3bxAzNkmh9zSXNwJ4UI0NrJgilUXqu5NLO8Y/s16000/A%20fake%20job%20description%20document,%20designed%20by%20the%20attacker%20to%20impersonate%20a%20global%20air%20carrier%20company%20(Source%20-%20Unit42).webp" alt="A fake job description document, designed by the attacker to impersonate a global air carrier company (Source - Unit42)" /><figcaption class="wp-element-caption">A fake job description document, designed by the attacker to impersonate a global air carrier company (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">They also bypass strong-name signature validation, ensuring that unsigned DLL files load without triggering security exceptions.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">This approach is described as a mature living-off-the-land technique because it requires no complex shellcode or memory patching. </p>



<p class="wp-block-paragraph">The attacker simply asks the system to turn off its own defenses using a file that looks entirely legitimate. The result is a payload running in a completely unmonitored, highly privileged environment with no alerts raised.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-infection-chain-and-social-engineering-tactics" class="wp-block-heading"><strong>Infection Chain and Social Engineering Tactics</strong></h2>



<p class="wp-block-paragraph">The MiniUpdate family was delivered through archives impersonating a global airline and a popular video conferencing platform. </p>



<p class="wp-block-paragraph">One archive contained six fake job description PDFs with believable job IDs and titles such as Senior Software Engineer, targeting IT and engineering professionals. </p>



<p class="wp-block-paragraph">A nested payload inside a file named Hiring <a href="https://cybersecuritynews.com/beware-of-fake-error-pages-that-linux-and-windows-systems/" id="117688" target="_blank" rel="noreferrer noopener">Portal.zip launched a fake error window</a> while the malware quietly installed itself.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU06lzihhv0GoeQ7NdAbLsJYsQ-RHnGDNnvG1_eLgI0k9JreE3RvJPu-IkWx3Z9Gm0JhUm4VByVNr4NuvI2hdT4LRYCsx4-t_6pWSdyleD3WUfcskKCbOQpB_b-5sp5oh-Au4VFkkrkgr-p52KtzUejCilEuH3pTEekNu7C3pXjvO14M0bjQj-6o7LVKE/s16000/Task%20Scheduler%20window%20showing%20the%20associated%20scheduled%20task%20(Source%20-%20Unit42).webp" alt="Task Scheduler window showing the associated scheduled task (Source - Unit42)" /><figcaption class="wp-element-caption">Task Scheduler window showing the associated scheduled task (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">For persistence, the malware used Windows Task Scheduler, creating a daily trigger at 09:30 local time. The MiniJunk V2 family used an older configuration method but added heavy code obfuscation and file size inflation to bypass automated scanning limits. </p>



<p class="wp-block-paragraph">Command-and-control traffic was routed through Azure-hosted domains that mimicked legitimate Windows service names, making network-level detection significantly harder.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Researchers recommend that defenders tune EDR platforms specifically to flag DLL sideloading and AppDomainManager hijacking behaviors, rather than relying solely on signature-based detection. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZP-Bih6fKjCGYjIwFlrPrJpOh3AvlKABPEzCqucnXARuf_LdGrOLUnn_cFDixejgCtkn2jEcms96QrFNzhUajHRbeGHQeF2IDJy98NVdi9RxTV3sP3lUsvS0IIOINANj-tbQyaTWHFFH9tvSLAsQ2VcK7oeA5wJPSiK-tQ297F52m1WW_tzGOyTCIThQ/s16000/MiniUpdate%20malware%20flow%20(Source%20-%20Unit42).webp" alt="MiniUpdate malware flow (Source - Unit42)" /><figcaption class="wp-element-caption">MiniUpdate malware flow (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Treating trusted, signed binaries that load unsigned modules as high-risk will help security teams catch these attacks much earlier. Organizations in aerospace, defense, and<a href="https://cybersecuritynews.com/north-korean-it-workers-mimic-as-us-organizations-for-job-offers/" id="84332" target="_blank" rel="noreferrer noopener"> technology should stay alert to fake job offers or meeting invitations</a> arriving through unofficial channels.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Domain</td><td><code>licencemanagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>LicenceSupporting.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>PeerDistSvcManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>ThemesManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>ThemesProviderManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>NanoMatrix.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>QuantumWeave.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>ElementShift.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>buisness-centeral.azurewebsites[.]net</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>buisness-centeral-transportation.azurewebsites[.]net</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>Buisness-centeral-transportation[.]com</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>PremierHealthAdvisory[.]com</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>PremierHealthAdvisory.azurewebsites[.]net</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>Premier-HealthAdvisory.azurewebsites[.]net</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltonsfinance[.]com</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltonsfinance.azurewebsites[.]net</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltons-finance.azurewebsites[.]net</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>business-startup[.]org</code></td><td>Associated C2 infrastructure</td></tr><tr><td>Domain</td><td><code>business-startup.azurewebsites[.]net</code></td><td>Associated C2 infrastructure</td></tr><tr><td>Domain</td><td><code>docspace-y4cumb.onlyoffice[.]com</code></td><td>ONLYOFFICE payload delivery</td></tr><tr><td>Domain</td><td><code>docspace-twpf0e.onlyoffice[.]com</code></td><td>ONLYOFFICE payload delivery</td></tr><tr><td>URL</td><td><code>hxxps[:]//docspace-y4cumb.onlyoffice[.]com/storage/files/root/folder_3602000/file_3601577/v1/content.zip</code></td><td>MiniJunk V2 payload URL</td></tr><tr><td>URL</td><td><code>hxxps[:]//docspace-twpf0e.onlyoffice[.]com/storage/files/root/.../content.zip</code></td><td>MiniJunk V2 U.S. Campaign payload URL</td></tr><tr><td>URL</td><td><code>hxxps[:]//2117.filemail[.]com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm</code></td><td>MiniUpdate Israel payload URL</td></tr><tr><td>SHA256</td><td><code>44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250</code></td><td>MiniUpdate U.S. Campaign — Initial archive</td></tr><tr><td>SHA256</td><td><code>332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17</code></td><td>MiniUpdate U.S. Campaign — Hiring Portal.zip</td></tr><tr><td>SHA256</td><td><code>0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864</code></td><td>MiniUpdate U.S. Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d</code></td><td>MiniUpdate Israel Campaign — Initial archive</td></tr><tr><td>SHA256</td><td><code>d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2</code></td><td>MiniUpdate Israel Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad</code></td><td>MiniUpdate UAE/Middle East Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27</code></td><td>MiniUpdate Middle East Campaign</td></tr><tr><td>SHA256</td><td><code>9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84</code></td><td>MiniJunk V2 Middle East — uevmonitor.dll</td></tr><tr><td>SHA256</td><td><code>B19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4</code></td><td>MiniJunk V2 Middle East — unbcl.dll</td></tr><tr><td>SHA256</td><td><code>8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b</code></td><td>MiniJunk V2 U.S. — Portable Platform.zip</td></tr><tr><td>SHA256</td><td><code>43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa</code></td><td>MiniJunk V2 U.S. — Connection.dll</td></tr><tr><td>SHA256</td><td><code>9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1</code></td><td>MiniJunk V2 U.S. — unbcl.dll</td></tr><tr><td>File Name</td><td><code>UpdateChecker.dll</code></td><td>MiniUpdate core RAT payload</td></tr><tr><td>File Name</td><td><code>uevmonitor.dll</code></td><td>MiniJunk V2 primary loader</td></tr><tr><td>File Name</td><td><code>Connection.dll</code></td><td>MiniJunk V2 U.S. Campaign RAT payload</td></tr><tr><td>File Name</td><td><code>unbcl.dll</code></td><td>Social engineering decoy DLL</td></tr><tr><td>File Name</td><td><code>Hiring Portal.zip</code></td><td>Malicious archive delivery file</td></tr><tr><td>File Name</td><td><code>Portable platform.zip</code></td><td>MiniJunk V2 U.S. Campaign delivery archive</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/">Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151486</post-id>	</item>
		<item>
		<title>SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</title>
		<link>https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 12:27:32 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151485</guid>

					<description><![CDATA[<p>A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan&#8217;s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 Afghan Mustoufiats — regional revenue and finance directorates that form the fiscal backbone of the country. The attack [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/">SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan&#8217;s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. </p>



<p class="wp-block-paragraph">The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 Afghan Mustoufiats — regional revenue and finance directorates that form the fiscal backbone of the country.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attack began with a spear phishing email carrying a ZIP archive. Inside was a malicious shortcut file disguised with a PDF icon and a filename written in Pashto — the dominant language used by Afghan government workers. </p>



<p class="wp-block-paragraph">The lure posed as a list of employees invited to a seminar on psychological and intellectual warfare, showing that the attackers had precise knowledge of their targets&#8217; working environment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Analysts from Seqrite, in a <a href="https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/" target="_blank" rel="noreferrer noopener">report shared with Cyber Security News</a>, identified this campaign and attributed it to the SideCopy APT cluster with medium-to-high confidence. </p>



<p class="wp-block-paragraph">SideCopy operates under the broader Transparent Tribe, also known as APT36, umbrella — a group with a documented history of targeting South Asian government institutions. </p>



<p class="wp-block-paragraph">Seqrite Labs has been tracking this threat cluster for years as part of its global spear phishing monitoring program.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once the victim opened the shortcut file, the malware silently used mshta.exe — a legitimate Windows utility — to reach out to a compromised Afghan education domain and pull a remote payload. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/iranian-hackers-attack-telecom-companies-using-custom-tools-and-living-off-the-land-techniques/" id="53130" target="_blank" rel="noreferrer noopener">This technique is called Living-off-the-Land</a>, where attackers abuse built-in system tools to avoid triggering security alerts. The malware then decoded obfuscated JavaScript in memory and embedded itself in the Windows Registry, disguising its persistence entry as a Microsoft Edge process.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUhfUw__bbbIfKdpxBEJCESriaI2JgWyrXrfrF7jz9ZY0h8sqEyATN5KajThxFhmipQRJTF4EtHIzsozRYKEIw52EvadgdFnonUfFKi34rDK6jS0gNDYByRUP0k9RgEpAWjt-ckhP7Eq2lhuqenrkXGHgGEHhEmYNlhC9Wn11VplEP4aVVYXvTHyBad_c/s16000/Infection%20Chain%20(Source%20-%20Seqrite).webp" alt="Infection Chain (Source - Seqrite)" /><figcaption class="wp-element-caption">Infection Chain (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The final stage deployed XenoRAT 1.8.7, an open-source Remote Access Trojan available on GitHub, which established an encrypted connection to a bulletproof server in Frankfurt, Germany. </p>



<p class="wp-block-paragraph">This command-and-control infrastructure was entirely separate from the delivery domain — a deliberate design to ensure long-term access even if the delivery layer was discovered and shut down.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-sidecopy-hackers-deploy-persistent-xenorat-malware" class="wp-block-heading"><strong>SideCopy Hackers Deploy Persistent XenoRAT Malware</strong></h2>



<p class="wp-block-paragraph">The malware chain ran across five stages, each built to pass control to the next without triggering detection. After the shortcut file launched mshta.exe, it pulled an HTML Application payload from abimj.edu.af, a compromised Afghan education website. </p>



<p class="wp-block-paragraph">That payload contained obfuscated JavaScript which decoded itself in memory and dropped a .NET-based loader DLL to continue the infection.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9YXmAESYqqUjPIl9R88B51E9eP0TJB-Pbee2g3y9ks08_pE_EeZmncxpg-RBY89UBUN0EXjMnVxBS7LHUh3OZTMZaD7x1Ys8Rxag-kzJOKAs7hdZX9ExSd7Sg17DMMVhZLVmO_WYSAjXa5ZoLlSlLMABB2HM04UFF7LgQWStnRbn1329hhkJfXWbOoI4/s16000/A%20legitimate%20Microsoft%20binary%20(Source%20-%20Seqrite).webp" alt="A legitimate Microsoft binary (Source - Seqrite)" /><figcaption class="wp-element-caption">A legitimate Microsoft binary (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">That loader DLL downloaded an encoded, GZIP-compressed blob from attacker-controlled URLs and unpacked it entirely in memory. </p>



<p class="wp-block-paragraph">The shellcode that followed used reflective loading — allocating executable memory and injecting itself without writing the main payload to disk. This fileless approach makes the malware far harder to <a href="https://cybersecuritynews.com/the-role-of-antivirus-software-in-keeping-your-computer-safe/" id="91581" target="_blank" rel="noreferrer noopener">catch with conventional antivirus scanning</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">XenoRAT is a capable surveillance tool once active. It connects to a hard-coded IP address using encrypted TCP traffic and registers itself through both a Windows Scheduled Task named &#8220;XenoUpdateManager&#8221; and a Registry Run key. </p>



<p class="wp-block-paragraph">The malware runs a mutex called &#8220;clouda&#8221; to prevent duplicate instances, and it queries installed antivirus products before reporting back to its operators.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-persistence-mechanisms-and-infrastructure-exposure" class="wp-block-heading"><strong>Persistence Mechanisms and Infrastructure Exposure</strong></h2>



<p class="wp-block-paragraph">The decoy document dropped during execution was a real Afghan Ministry of Finance internal staff directory, listing Finance Directors, Revenue Chiefs, and Secretaries from all 34 provinces — complete with mobile numbers. </p>



<p class="wp-block-paragraph">This level of detail indicates the attackers conducted prior intelligence gathering, likely through earlier compromises of Afghan government networks.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The delivery domain abimj.edu.af resolved to IPs 103.132.98.224 and 103.132.98.226, both on a subnet belonging to Afghanistan&#8217;s own Ministry of Communication. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkWQUuutKQJ8-baB_BPTp65xYi1xm1iZ6wlPRJfFgMZlxBZMpZ5jjwlAuOEyIbMkH-g3JYAlKNoq_dSqF7M4r-_cQ1-SduKATM_jmSYyaTKAEwh96RV51SrdCOmK8WTBvCxA_x4E3eqCC0MYj7LiqAhp0ZHdR2o8TiGrNz5QwTl1mbqlT2O1jEmTxsYic/s16000/Shellcode%20Execution%20(Source%20-%20Seqrite).webp" alt="Shellcode Execution (Source - Seqrite)" /><figcaption class="wp-element-caption">Shellcode Execution (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Staging malicious payloads on local Afghan infrastructure allowed traffic to blend with legitimate government communications, <a href="https://cybersecuritynews.com/network-monitoring-tools/" id="20062" target="_blank" rel="noreferrer noopener">bypassing network monitoring tools</a>. </p>



<p class="wp-block-paragraph">The RAT&#8217;s C2 server at 185.235.137.106 was hosted on AS59711, a Bulgaria-registered provider with Frankfurt data center presence previously linked to SideCopy activity.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Security teams should monitor for unusual mshta.exe executions, unexpected Registry Run keys mimicking Windows processes, and outbound traffic to unrecognized European hosting providers. </p>



<p class="wp-block-paragraph">Enforcing application allow-listing, auditing scheduled tasks regularly, and restricting HTA execution from public directories are effective mitigations. Seqrite released detections under signatures including Link.Downloader.50744.GC and Script.Netloader.50745.GC to help identify compromised systems.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>SHA256</td><td>194B912C242604D6F9A79369F22338C58A13CE0CC2ED280CE505075808BC2F14</td><td>ZIP archive (initial delivery)</td></tr><tr><td>SHA256</td><td>3B4194BDFE40D94031A94B30397FFD8A4B09D0A4057668E897B8BDCD1703DD01</td><td>Malicious LNK file</td></tr><tr><td>SHA256</td><td>DF9173A28C0B0B878C10A53D35CD7CE6F6ED66D207B6B7C4FF723721F1C027AB</td><td>Decoy PDF document</td></tr><tr><td>SHA256</td><td>A63E90EE57A1F213A8FE76EF1A6CFF5AE9ED7EBCEDA258431533825E648C0C67</td><td>ugayt.hta payload</td></tr><tr><td>SHA256</td><td>5833917BD137804F5A021D2CB37ADFE5C4B7B67DBB06D59C3B9C5CF393835E45</td><td>noway.bat (persistence batch file)</td></tr><tr><td>SHA256</td><td>99127C8C67D90E2776BEEB85281F9C68399BF4567B07A6B638D68B760212E88D</td><td>zuidrt.hta (Stage-2 HTA payload)</td></tr><tr><td>SHA256</td><td>8F2D979EF33B2900351C94C7335275A9342C75189E1A901998E90A539E944A1A</td><td>WayBroad.dll (Stage-1 Loader DLL)</td></tr><tr><td>SHA256</td><td>0019212F25EB04BBB33BB194879C095265DB7855D6003BDD777CF0CBB90EB772</td><td>Aotestpass.dll (Stage-2 Loader DLL)</td></tr><tr><td>SHA256</td><td>9AE3D785486022AF82EA92E51B26E3F55C1BBA88A7BE2AD9790F4240E8499D14</td><td>XenoRAT final payload</td></tr><tr><td>IP Address</td><td>185.235.137.106</td><td>XenoRAT C2 server (HZ Hosting, Frankfurt)</td></tr><tr><td>IP Address</td><td>103.132.98.224</td><td>Delivery domain resolved IP (Afghan MoCIT)</td></tr><tr><td>IP Address</td><td>103.132.98.226</td><td>Delivery domain resolved IP (Afghan MoCIT)</td></tr><tr><td>Domain</td><td>abimj.edu.af</td><td>Compromised Afghan education domain used for payload delivery</td></tr><tr><td>URL</td><td>hxxp://abimj.edu.af/index.php</td><td>Stage-1 remote HTA/PHP payload endpoint</td></tr><tr><td>URL</td><td>hxxp://abimj.edu.af/institute/cloudiyaf/document.pdf</td><td>Decoy PDF download URL</td></tr><tr><td>URL</td><td>hxxps://abimj.edu.af/institute/10/</td><td>Stage-2 payload download URL</td></tr><tr><td>URL</td><td>hxxps://abimj.edu.af/institute/7/</td><td>Alternate Stage-2 URL (Windows 7 targets)</td></tr><tr><td>File Name</td><td>zuidrt.hta</td><td>Persistent HTA payload stored in Public folder</td></tr><tr><td>File Name</td><td>noway.bat</td><td>Hidden batch file for registry persistence execution</td></tr><tr><td>File Name</td><td>ayui.vmxx</td><td>Disguised encoded Stage-2 payload blob</td></tr><tr><td>File Name</td><td>ayhui.vmxx</td><td>Reconstructed intermediate shellcode container</td></tr><tr><td>Registry Key</td><td>HKCU\Software\Microsoft\Windows\CurrentVersion\Run &#8220;Edgre&#8221;</td><td>Persistence Run key masquerading as Microsoft Edge</td></tr><tr><td>Mutex</td><td>clouda</td><td>XenoRAT single-instance mutex</td></tr><tr><td>Scheduled Task</td><td>XenoUpdateManager</td><td>Persistence scheduled task created by XenoRAT</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/">SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151485</post-id>	</item>
	</channel>
</rss>
