<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Wed, 03 Jun 2026 18:03:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS</title>
		<link>https://cybersecuritynews.com/google-gemini-vulnerability-exploited/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 17:49:26 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151814</guid>

					<description><![CDATA[<p>A new class of indirect prompt injection (IPI) attacks targets Google Gemini&#8217;s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. The research, led by Or Yair, Security Research Team Lead at SafeBreach, builds on the firm&#8217;s earlier &#8220;Invitation [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/google-gemini-vulnerability-exploited/">New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new class of indirect prompt injection (IPI) attacks targets <a href="https://cybersecuritynews.com/google-gemini-for-workspace-vulnerability/" target="_blank" rel="noreferrer noopener">Google Gemini&#8217;s voice assistant</a>, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger.</p>



<p class="wp-block-paragraph">The research, led by Or Yair, Security Research Team Lead at SafeBreach, builds on the firm&#8217;s earlier &#8220;Invitation Is All You Need&#8221; disclosure, which weaponized Google Calendar invitations against Gemini.</p>



<p class="wp-block-paragraph">This time, the attack surface is far larger; any application capable of triggering a device notification becomes a viable delivery vector.</p>



<h2 id="h-google-gemini-vulnerability-exploited" class="wp-block-heading"><strong>Google Gemini Vulnerability Exploited</strong></h2>



<p class="wp-block-paragraph">The core exploit leverages Gemini&#8217;s Android Utilities agent, specifically the tool that reads incoming notifications. Because this tool processes untrusted data from third-party apps, an attacker can embed malicious instructions directly inside a crafted message.</p>



<p class="wp-block-paragraph">Once Gemini reads the poisoned notification, it silently incorporates the attacker&#8217;s commands into the conversational context without the user&#8217;s knowledge.</p>



<p class="wp-block-paragraph">Even without invoking external tools, this notification-based IPI enables context poisoning that allows attackers to control Gemini&#8217;s output entirely. A manipulated assistant could, for example, relay a fake system message: <em>&#8220;There was an error — click here to refresh&#8221;</em> — a classic phishing lure delivered through a trusted AI interface.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-9-16 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<div class="youtube-embed" data-video_id=""><iframe title="Demo 4 - Click or Trick" width="563" height="1000" src="https://www.youtube.com/embed/g1Sec2FxAPc?feature=oembed&#038;enablejsapi=1" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>



<h2 id="h-fake-context-alignment-bypassing-google-s-defenses" class="wp-block-heading"><strong>Fake Context Alignment: Bypassing Google&#8217;s Defenses</strong></h2>



<p class="wp-block-paragraph">After Google patched earlier vulnerabilities by blocking chained tool invocations and Delayed Tool Invocation, <a href="https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit/" target="_blank" rel="noreferrer noopener nofollow">SafeBreach researchers developed</a> a novel bypass technique dubbed Fake Context Alignment.</p>



<p class="wp-block-paragraph">The technique creates a dual illusion, presenting a legitimate authorization scenario to Gemini&#8217;s backend security mechanisms while showing the victim an entirely benign interaction.</p>



<p class="wp-block-paragraph">Two techniques were demonstrated:</p>



<ul class="wp-block-list">
<li><strong>Obfuscated Fake Context Alignment:</strong> Gemini appends a malicious authorization question in a foreign language (e.g., Chinese: <em>&#8220;你想打开窗户吗?&#8221;</em> — &#8220;Do you want to open the window?&#8221;) immediately followed by a harmless English question. The user replies &#8220;Yes&#8221; to the English prompt while the backend aligns the affirmative with the hidden Chinese instruction, triggering tool execution.</li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-9-16 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<div class="youtube-embed" data-video_id=""><iframe title="Demo 3 - C or T" width="563" height="1000" src="https://www.youtube.com/embed/YB2nseisdz8?feature=oembed&#038;enablejsapi=1" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>



<ul class="wp-block-list">
<li><strong>Muted Fake Context Alignment:</strong> The malicious question is embedded as clickable link text that Gemini&#8217;s text-to-speech engine silently skips. The user hears only a benign voice prompt and unknowingly authorizes a tool call by replying &#8220;Yes.&#8221;</li>
</ul>



<p class="wp-block-paragraph">Combining both techniques into an &#8220;Ultimate Combo&#8221; payload allowed researchers to bypass all of Google&#8217;s latest mitigations with high reliability and near-zero user awareness.</p>



<p class="wp-block-paragraph">With Delayed Tool Invocation re-enabled, researchers demonstrated a range of high-severity exploits. The emergence of smart home technology has facilitated various forms of exploitation, such as remotely controlling connected devices like windows, boilers, and lighting via Google Home.</p>



<p class="wp-block-paragraph">Additionally, there are alarming tactics like covert video streaming, where an attacker can force Zoom to launch and stream the victim&#8217;s camera live <a href="https://cybersecuritynews.com/badiis-malware-turns-hijacks-iis-servers/" target="_blank" rel="noreferrer noopener">through a 301 HTTP redirect</a> from a Safe Browsing-approved domain.</p>



<p class="wp-block-paragraph">Large-scale social engineering schemes are on the rise, fabricating messages from trusted contacts without prior knowledge of the contacts&#8217; names by extracting real sender names from the notification queue.</p>



<p class="wp-block-paragraph">Moreover, persistent memory poisoning has become a critical concern, as it involves injecting false information into Gemini&#8217;s long-term memory across the victim&#8217;s entire Google Workspace account, affecting tablets, computers, and smart speakers.</p>



<p class="wp-block-paragraph">Lastly, scheduled surveillance tactics allow the establishment of recurring tasks that automatically read the user&#8217;s recent messages daily, further compromising their privacy and security.</p>



<p class="wp-block-paragraph">SafeBreach disclosed the findings to <a href="https://cybersecuritynews.com/googles-bug-bounty-program-high-reward/" target="_blank" rel="noreferrer noopener">Google&#8217;s Vulnerability Reward Program</a> on August 17, 2025. Google confirmed on November 14, 2025, that updated content classifier improvements successfully mitigated the indirect prompt injection and Delayed Tool Invocation scenarios described in the research.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/google-gemini-vulnerability-exploited/">New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Google-Gemini-Vulnerability-Exploited.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151814</post-id>	</item>
		<item>
		<title>HazyBeacon Camapign Weaponizes Amazon Web Services for Stealthy Communications</title>
		<link>https://cybersecuritynews.com/hazybeacon-camapign-weaponizes-amazon-web-services/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 17:43:34 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151796</guid>

					<description><![CDATA[<p>A new malware campaign is turning trusted cloud infrastructure against the organizations that rely on it. Known as HazyBeacon and tracked under cluster identifier CL-STA-1020, the campaign targets government networks across Southeast Asia. Rather than using easily blocked servers, the threat actors hide inside one of the world&#8217;s most trusted platforms, Amazon Web Services (AWS). [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/hazybeacon-camapign-weaponizes-amazon-web-services/">HazyBeacon Camapign Weaponizes Amazon Web Services for Stealthy Communications</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new malware campaign is turning trusted cloud infrastructure against the organizations that rely on it. Known as HazyBeacon and tracked under cluster identifier CL-STA-1020, the campaign targets government networks across Southeast Asia. </p>



<p class="wp-block-paragraph">Rather than using easily blocked servers, the threat actors hide inside one of the world&#8217;s most trusted platforms, Amazon Web Services (AWS).<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What sets this campaign apart is how it communicates with infected machines. Attackers compromise AWS accounts belonging to unrelated organizations and plant lightweight serverless functions inside them as hidden relay points. </p>



<p class="wp-block-paragraph">To any security team watching traffic, the communications look like routine, encrypted HTTPS connections to Amazon&#8217;s own infrastructure.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse" id="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse" target="_blank" rel="noreferrer noopener nofollow">Researchers at Qualys said in a report</a> shared with Cyber Security News (CSN) that the campaign was originally documented by Palo Alto Networks Unit 42 in July 2025. </p>



<p class="wp-block-paragraph">The Qualys analysis breaks down the technical mechanics and outlines how defenders can detect and stop this cloud-native threat.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once HazyBeacon installs on a victim&#8217;s Windows machine, it works as a lightweight backdoor. It collects system details like hostname, IP address, and user privileges. </p>



<p class="wp-block-paragraph">It receives <a href="https://cybersecuritynews.com/new-yurei-ransomware-with-powershell-commands/" id="126128" target="_blank" rel="noreferrer noopener">encrypted commands to run shell instructions or pull down further payloads</a>. It silently uploads stolen documents and captured keystrokes to the attackers.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The campaign does not exploit flaws in AWS itself. Attackers steal static IAM access keys from exposed GitHub repositories or phishing campaigns, then use those keys to build a relay inside a compromised cloud account.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380"></a></p>



<h2 id="h-hazybeacon-camapign-weaponizes-amazon-web-services" class="wp-block-heading"><strong>HazyBeacon Camapign Weaponizes Amazon Web Services</strong></h2>



<p class="wp-block-paragraph">The core of this attack is the abuse of AWS Lambda Function URLs, introduced in April 2022. </p>



<p class="wp-block-paragraph">These URLs expose a serverless function directly to the internet without requiring services like API Gateway. That simplicity is useful for developers but easy to weaponize.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Lambda Function URLs offer two authentication modes. One requires callers to sign with valid IAM credentials, while the other, called AuthType: NONE, lets anyone send requests without authentication. </p>



<p class="wp-block-paragraph">Attackers choose this option to spin up a public HTTPS relay inside AWS infrastructure within seconds. Since the endpoint domain ends in on.aws, the traffic blends in with trusted Amazon services.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVWgSsImvWNyvwT-F0UDiv4437MTFcgzMXpgNoKssaxusrsqoomvhXt4CyfU8x6U6ktQRfgw1n0HkmyJEa70QxiYVS9M7YLPriemmEK2M8d8TZt1MGV8kKmSvaFj7KquujQendK37eiVZ5WZLLiWxhiiavCtuPlv7-xEzz3clt5BsoltHUyDFFWRjUNnw/s16000/Configure%20function%20URL%20(Surce%20-%20Qualys).webp" alt="Configure function URL (Surce - Qualys)" /><figcaption class="wp-element-caption">Configure function URL (Surce &#8211; Qualys)</figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a>The relay works as a silent middleman. <a href="https://cybersecuritynews.com/new-malware-toolkit-sends-users/" id="140662" target="_blank" rel="noreferrer noopener">Malware sends an encrypted HTTP POST to a Lambda URL</a> inside a different compromised AWS account. </p>



<p class="wp-block-paragraph">That function strips the headers and forwards the payload to the attacker&#8217;s real backend server, which responds through the same path. </p>



<p class="wp-block-paragraph">Neither the malware victim nor the AWS account owner typically knows something is wrong until an abuse notice or unexpected bill arrives.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attack follows a predictable kill chain rooted in poor identity hygiene. Attackers validate stolen keys with quiet API calls, upload a zipped Python or Node.js payload as a Lambda function with a benign name like &#8220;UpdateWorker,&#8221; and deploy it in a low-scrutiny AWS region to avoid detection.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380"></a></p>



<h2 id="h-key-defenses-against-lambda-based-command-relays" class="wp-block-heading"><strong>Key Defenses Against Lambda-Based Command Relays</strong></h2>



<p class="wp-block-paragraph">The most important first step is strong IAM hygiene. Teams should disable unused access keys, enforce regular rotation, and require <a href="https://cybersecuritynews.com/microsoft-multi-factor-authentication-issue/" id="88334" target="_blank" rel="noreferrer noopener">multi-factor authentication across cloud accounts</a>. These controls cut off the primary entry point this campaign relies on.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Enabling AWS CloudTrail logging across all regions is equally critical. <a href="https://cybersecuritynews.com/critical-aws-amplify-studio-vulnerability/" id="104603" target="_blank" rel="noreferrer noopener">CloudTrail records every API call used to create Lambda functions</a> and Function URLs, exposing unauthorized deployments even in rarely watched regions. </p>



<p class="wp-block-paragraph">Spotting anomalous activity during reconnaissance can reveal compromised credentials before a relay goes live.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Organizations can also apply Service Control Policies at the AWS Organization level to block Lambda Function URLs configured with AuthType: NONE unless explicitly approved through tagging. </p>



<p class="wp-block-paragraph">This prevents a public relay from being deployed even with valid stolen credentials. Routing Lambda workloads through a Virtual Private Cloud adds another detection layer, since relay traffic produces a one-to-one inbound to outbound pattern visible in flow logs.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8ee158b9-aab0-46ef-8502-1621094fd7dd/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.pdf?AWSAccessKeyId=ASIA2F3EMEYEXJV6PS55&amp;Signature=Mk8ycxxamo9Hz%2Fak6SNVIuxSmj8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJGMEQCIEj9INsURwQ%2FLN9bmjnEGkBeTqS5OfHre3QTTSUSvoKqAiBdL20LBpKXbuJGd7nvVMmUkPlxiYL0Wo0ZmEyAntJXLCrzBAhAEAEaDDY5OTc1MzMwOTcwNSIMhMYlLCizpmME8YpeKtAEOX8%2FA60H51hzdlzUv73GFhId%2Fda4oLDxHJuO%2FGLWa8NMKJZXKt%2FdwZrlOwk5fIpDjiT3pJa51RClupDsjZNGj%2FATbZkdnoi%2FTSUDKPN3m9EwCWiuJPc%2FjqHERbQQT5qwCWgygtc87aLPh%2BsCFhG02Hn%2FJpM%2FIXQiG%2BUq4NMQfhcVHUkNV5b0ykH16HbNyDpmweO7npOTiZrMaQ5QPksnGR%2BAFrw90jPDyLBR23W4gbShjojD1Ca9xqthuDZ5SwN9S8sdQd2VF1JsO3aOt84vXBOtX8iZrt70MlGLkVlUX%2B9VRtoqJvxyW5yiaP4eYbrhoxLeUAelkXZraKVr0kB%2F5ftcwgLwLPfKlsBKg2Eb6VB02jP4L0X3XSnX%2F9kraJFtgtmVxhwvWkQ9r7ZpyPnfQBZIgr5z1edaNJpSDTbytNBNrjmPTbK8kk34BnAAJ6aHP1VJoCO4QBejfQCKwQ6VXAXKxeGjWqQTmtRe4Q3GpP9zh8zc%2BE0YZeB4A3uDn2sxQLm8Js8u9R2Nal3rhcYnhJr1Tnv7Hcf%2FxJBsdt7nBJl0TxDYDk2QaE478rzvg9H7S2EEUs2f62H8GhX0n%2BOVb%2BzJrG4ybtkdHBvRciqfiEusv5qOSvHks6MSZXqbDr3585deMrQXaD3LZ79bOVAIIKvn8jc%2FcX%2Bs7MxtaowIRwANPlWkvpHvs68f3ZKX%2F9lB%2F%2BEAqGm9aywwHLuSl9hCZCHvo5fRap4OLXeViLIQMt2coJ7Fr%2BZEH%2FfjqGKH2HJ559PiTMNNrgMN87Sti15e7jCBi4HRBjqZAVN6Vk9q79YebiJlOg5jy1yujdFLDgOB%2BfIQVlOi%2FVcMtSgbF%2Fecnn4qrVF%2F9gsnGjw%2BE8JWFBhchL897An%2BLEuhOwOnCxwPtRrRxlK41FMA00TFZnz%2BGTwJslPoMVwKc0ePQyPh5bRhFPYdGmSgtT0KaQg21LC84TMIaiUPTNFMEvkgqLkAKRoyf5aWwFj1ObXLSCx8tAdl3A%3D%3D&amp;Expires=1780503380" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Monitoring Lambda cost anomalies rounds out the defense. A relay serving many infected machines generates massive invocation volumes that appear as billing spikes, especially in nonproduction regions. Granular AWS budget alerts can surface this abuse before it scales.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/hazybeacon-camapign-weaponizes-amazon-web-services/">HazyBeacon Camapign Weaponizes Amazon Web Services for Stealthy Communications</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/HazyBeacon-Camapign-Weaponizes-Amazon-Web-Services-for-Stealthy-Communications.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151796</post-id>	</item>
		<item>
		<title>The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks</title>
		<link>https://cybersecuritynews.com/the-gentlemen-ransomware-group-uses-fortinet-exploits/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 17:42:42 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151801</guid>

					<description><![CDATA[<p>A Russian-speaking ransomware crew known as The Gentlemen has quickly risen to become one of the most active threats in 2026, ranking second only to Qilin in ransomware activity. Their toolkit combines Fortinet vulnerability exploitation, AI-assisted operations, and a fully custom command-and-control framework that most security tools simply do not see coming. The group operates [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/the-gentlemen-ransomware-group-uses-fortinet-exploits/">The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A Russian-speaking ransomware crew known as The Gentlemen has quickly risen to become one of the most active threats in 2026, ranking second only to Qilin in ransomware activity. </p>



<p class="wp-block-paragraph">Their toolkit combines Fortinet vulnerability exploitation, AI-assisted operations, and a fully custom command-and-control framework that most security tools simply do not see coming.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The group operates without a central office or traditional payroll structure. Nine operator handles have been identified communicating across time zones through a self-hosted Rocket.Chat instance on an onion site, with plans to migrate to a Rust-based platform. </p>



<p class="wp-block-paragraph">Their lean, distributed model marks a <a href="https://cybersecuritynews.com/conti-ransomware-member-extradited/" id="132034" target="_blank" rel="noreferrer noopener">clear shift from the rigid corporate setup that groups like Conti</a> once maintained.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">In May 2026, the Ransom-ISAC research team extracted 3,366 messages from The Gentlemen&#8217;s Rocket.Chat server, exposing internal plans, tooling discussions, and victim targeting details. </p>



<p class="wp-block-paragraph"><a href="https://www.vectra.ai/blog/from-conti-to-the-gentlemen-tooling-evolved-gaps-didnt" id="https://www.vectra.ai/blog/from-conti-to-the-gentlemen-tooling-evolved-gaps-didnt" target="_blank" rel="noreferrer noopener nofollow">Analysts at Vectra AI noted the findings in a report</a> shared with Cyber Security News (CSN), observing that while the group&#8217;s tools have changed considerably, the core weaknesses they exploit in victim networks have stayed nearly the same since 2022.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The leaked messages also uncovered a connection between The Gentlemen and earlier ransomware brands. A negotiator known by the handle &#8220;Tinker&#8221; appeared in both Black Basta chats and The Gentlemen&#8217;s logs, performing the same operational role across both groups. </p>



<p class="wp-block-paragraph">A shared Matrix homeserver, bestflowers247.online, was present in archives from both groups, anchoring that infrastructure link with hard evidence.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">This pattern points to a larger truth: ransomware operators do not retire, they rebrand. The same people carry their knowledge and access from one criminal enterprise to the next, making group takedowns far less effective than many defenders might hope.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737"></a></p>



<h2 id="h-gentlemen-ransomware-uses-fortinet-exploits-ai-and-custom-c2-frameworks" class="wp-block-heading"><strong>Gentlemen Ransomware Uses Fortinet Exploits, AI, and Custom C2 Frameworks</strong></h2>



<p class="wp-block-paragraph">Fortinet remains the front door of choice for The Gentlemen. The Rocket.Chat logs mention FortiGate 81 times, with CVE-2024-55591, a FortiOS authentication bypass flaw, called out explicitly as their primary way into victim networks. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/ai-brute-force-vs-probabilistic-model/" id="62989" target="_blank" rel="noreferrer noopener">Halcyon&#8217;s separate analysis found the group brute-forcing</a> roughly 1,000 Fortinet VPNs, in some cases using reused passwords like gentlemen25 and gentle26 across multiple victims.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once inside, the group deploys a custom C2 framework called G-BOT. This previously undocumented control panel supports per-beacon SOCKS5 tunneling and uploads builders to temporary file-sharing sites, replacing commercial tools like Cobalt Strike. </p>



<p class="wp-block-paragraph">That switch makes detection harder for security teams relying on known signatures.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The group also targets hypervisors directly. Their Linux locker attacks Hyper-V Volume Manager, encrypting at the hypervisor level so that endpoint agents inside virtual machines cannot see the attack. </p>



<p class="wp-block-paragraph">The locker drops the extension .i8p14s and leaves a ransom note named README-GENTLEMEN.txt, signaling that no layer of infrastructure is off limits.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-ai-and-credential-theft-complete-the-kill-chain" class="wp-block-heading"><strong>AI and Credential Theft Complete the Kill Chain</strong></h2>



<p class="wp-block-paragraph">The Gentlemen have moved AI from a novelty into a working part of their operation. Operators reference using GPT and Claude models to assist with ransom negotiations, with one operator describing them as automatic response writers for victim communications. </p>



<p class="wp-block-paragraph">The group also discusses renting GPUs on vast.ai and running uncensored AI models from Hugging Face to triage large volumes of stolen data.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/credential-theft-risks/" id="106554" target="_blank" rel="noreferrer noopener">For credential theft, the group relies on Phemedrone Stealer</a> V2.3.2, LummaC2, XenAllPasswordPro, Chrome App-Bound Encryption Decryption, and DumpBrowserSecrets. </p>



<p class="wp-block-paragraph">These tools pull saved passwords directly out of browsers without triggering login failures, meaning standard authentication logs show nothing unusual. Stolen data then moves out through rclone to MEGA, following the same exfiltration pattern ransomware groups have used for years.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Defenders have clear steps based on what the leaked chats reveal. Security teams should audit edge devices including Palo Alto, Fortinet, Citrix, F5, and Cisco gear against the CVE list discussed in operator chats. </p>



<p class="wp-block-paragraph">Treating NTDS.dit and VSS backup access as an immediate severity-one alert, rather than a forensic discovery made weeks later, can stop domain-wide compromises before they fully develop. </p>



<p class="wp-block-paragraph">Hunting for tools like rclone, MEGAcmd, WinSCP, and Velociraptor on hosts that have no reason to run them adds an early warning layer that logs alone cannot provide.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762a8fb5-f3b9-480d-bb8c-94e02cae0757/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.pdf?AWSAccessKeyId=ASIA2F3EMEYESAZD3NQ7&amp;Signature=vSSW7u0o4Zlx%2FzLD5VpPzh5xNAU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHgaCXVzLWVhc3QtMSJIMEYCIQDOU6sRDisYnYLbTbXSKU9SxXHC%2Ff9ZL4mFNiIqtFUcCwIhANSt%2FoVJcyNnZz1lacIMjbcA6xsD%2BTwcg2yubmTpOqZrKvMECEEQARoMNjk5NzUzMzA5NzA1IgwDZ97hbS5fsBqBEIAq0ATFsSu0G2DXujoTOq5gBwM909CKefuClel62i5O1VaJnLIP1Jy2Q%2BXZpgqANoLsCMuX3hgsMkZ9IuGvVYWYiYFYE9WqcDdxlYm1YR5WCIMb1nLUNrV%2Boe1tavijKhT0LTLvhsTIZQnHG%2FXu5FDGORPWnKC%2BFlsXfOVlXzp7mIlV7c7lNc9%2F3y0S7N0DjgQcPIlVH31DqziQXoXbZBqQbfSQZzYXKCDtP5k7WU3K8Er%2BLRlGgByxfQbrdWDQ0P9SF5t6%2BlvIrz3tURfn0dkPQKGTp75M6EwtJ4iH0YAauuT0P%2BUA0IOlaSmBczSHI7dWG1ik78shblLWurxPNtR3zlspVLno0VEBizLyD1Sjq6k7A3iEP3ahigkgwlNGWRph5gJAjSXu2GmsZzwvRD6SZCaVzV5j7inBk7ijTZVYAWIXDhw8ELavUYSHHSV6Q1fOJf8O7vJo6y2YZhMV%2B%2Fw72%2FJn2ppkaH0iRvFUL1AcUReRN6lJHKyFFpLiavQc%2FlYT%2F5%2FssTJgTCD8zMh8kBIXeBygsuEibQJ9ga4I4v3hi2v7bB0e0Yb2FsBzqfKgjwEMqBhCLgSH%2FLYSzKy8q%2BWfQwv7scHT4Fxk4rcKtdFuK2qqE03Oj7g8XpmGEMj79Ito0xCmuI2%2BeB05jLT9Xw%2F9rxrat3e6EXdgRL9rhv7JCG4IBWEMG5Y5RUvRibXcaatOuIdlBjLfdRBCQuWmCOWynaZp636FGLrol5bb3NrHt9h4GKgt4O2aYn9JFtJrnu7lXE%2BSPkS71Y8DRczNtpSpeFhKMLadgdEGOpcBVauDqkLCKaWcGCsndiviYKuBV%2FRcVnNXVJuEC32hLTzxeHoSX2JV7NheoZ468c0CWYE%2FumZ%2BAJAMQSnS1u7F8x%2FWM48VCb1w6HblopoacuLG1PLQ8s9q30vrUs6F17MxeTHZQrdKlQzXyPL7K9%2FPaX7a2W3E7BIbAvzk0jQXjFaKiQhV4G8E7hYA1ZbXlebQRqLJwmbjTg%3D%3D&amp;Expires=1780505737" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>CVE</td><td>CVE-2024-55591</td><td>FortiOS authentication bypass; primary initial access vector used by The Gentlemen</td></tr><tr><td>CVE</td><td>CVE-2024-3400</td><td>Palo Alto Networks PAN-OS zero-day; most-discussed CVE in Black Basta operator chats</td></tr><tr><td>CVE</td><td>CVE-2025-32433</td><td>Erlang/OTP SSH RCE; present in The Gentlemen toolkit</td></tr><tr><td>CVE</td><td>CVE-2025-33073</td><td>NTLM relay vulnerability; present in The Gentlemen toolkit</td></tr><tr><td>CVE</td><td>CVE-2023-4966</td><td>Citrix NetScaler; referenced in operator CVE discussions</td></tr><tr><td>CVE</td><td>CVE-2020-5135</td><td>SonicWall stack buffer overflow (CVSS 9.4); used by Conti operators</td></tr><tr><td>Domain</td><td>bestflowers247.online</td><td>Shared Matrix homeserver linking Black Basta and The Gentlemen operators</td></tr><tr><td>IP / SSH</td><td>193.228.128.2:2222</td><td>NAS staging server used in The Gentlemen rclone exfiltration pipeline</td></tr><tr><td>Credential</td><td>userd0wnloAd1</td><td>Username for NAS staging server used during data exfiltration</td></tr><tr><td>Password</td><td>gentlemen25 / Gentlemen25 / gentle26</td><td>Reused VPN passwords found across multiple Fortinet-targeted victims</td></tr><tr><td>File Extension</td><td>.i8p14s</td><td>File extension appended by The Gentlemen Linux/NAS locker</td></tr><tr><td>File Name</td><td>README-GENTLEMEN.txt</td><td>Ransom note dropped by The Gentlemen Linux locker</td></tr><tr><td>Tool</td><td>Phemedrone Stealer V2.3.2</td><td>Credential stealer used by The Gentlemen for browser password harvesting</td></tr><tr><td>Tool</td><td>LummaC2</td><td>Credential stealer / payload dropper used by both Black Basta and The Gentlemen</td></tr><tr><td>Tool</td><td>XenAllPasswordPro</td><td>Password recovery tool used for credential theft</td></tr><tr><td>Tool</td><td>DumpBrowserSecrets</td><td>Browser credential dumping tool used by The Gentlemen</td></tr><tr><td>Tool</td><td>Chrome App-Bound Encryption Decryption</td><td>Tool for bypassing Chrome credential protection</td></tr><tr><td>Tool</td><td>G-BOT</td><td>Custom C2 framework with SOCKS5 tunneling used by The Gentlemen</td></tr><tr><td>Tool</td><td>rclone</td><td>Data exfiltration tool used to stage stolen data to MEGA</td></tr><tr><td>Tool</td><td>Velociraptor</td><td>Legitimate DFIR tool repurposed by The Gentlemen as C2</td></tr><tr><td>File</td><td>qwertyuio.txt</td><td>File used by LummaC2 to store exfiltrated credentials (observed in Black Basta)</td></tr><tr><td>File</td><td>README-GENTLEMEN.txt</td><td>Ransom note filename dropped by group&#8217;s Linux locker</td></tr><tr><td>Path</td><td>/opt/updateamd</td><td>Linux locker binary invocation path used by The Gentlemen</td></tr><tr><td>Archive</td><td>JA456</td><td>Follow-on leak package exposing Gentlemen operator-side artifacts including NAS and MEGA session data</td></tr><tr><td>Platform</td><td>temp.sh / 0x0.st</td><td>Temporary file-sharing sites used to upload G-BOT builder payloads</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/the-gentlemen-ransomware-group-uses-fortinet-exploits/">The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/The-Gentlemen-Ransomware-Group-Uses-Fortinet-Exploits-AI-and-Custom-C2-Frameworks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151801</post-id>	</item>
		<item>
		<title>Hackers Use Fake Purchase Orders to Deploy JS.MonoGlyphRAT Targeting US Enterprises</title>
		<link>https://cybersecuritynews.com/hackers-use-fake-purchase-orders-to-deploy-js-monoglyphrat/</link>
		
		<dc:creator><![CDATA[Balaji N]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 15:56:27 +0000</pubDate>
				<category><![CDATA[ANY.RUN]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151758</guid>

					<description><![CDATA[<p>A stealthy new threat is quietly making its way through US businesses, and most traditional security tools are completely missing it. Researchers have uncovered a previously unknown piece of malware that disguises itself as an everyday business document — a purchase order, a quote, or a request for proposal. Once an unsuspecting employee opens the [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-use-fake-purchase-orders-to-deploy-js-monoglyphrat/">Hackers Use Fake Purchase Orders to Deploy JS.MonoGlyphRAT Targeting US Enterprises</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A stealthy new threat is quietly making its way through US businesses, and most traditional security tools are completely missing it. </p>



<p class="wp-block-paragraph">Researchers have uncovered a previously unknown piece of malware that disguises itself as an everyday business document — a purchase order, a quote, or a request for proposal. </p>



<p class="wp-block-paragraph">Once an unsuspecting employee opens the attached file, attackers silently gain persistent access to the entire company network.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The malware, named JS.MonoGlyphRAT, is delivered as an ordinary-looking JavaScript <a href="https://cybersecuritynews.com/phishing-emails-target-35000-users/" target="_blank" rel="noreferrer noopener">file attached to phishing emails</a>. It is actively targeting organizations across the United States, with confirmed victims in the technology sector, managed security service providers (MSSPs), telecommunications, and education.</p>



<p class="wp-block-paragraph">Cases have also been spotted in Germany, Sweden, Australia, and several other countries, making this a growing concern well beyond US borders.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><strong><a href="https://any.run/cybersecurity-blog/monoglyphrat-attacks-us-enterprise/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=monoglyphrat&amp;utm_content=blog&amp;utm_term=030626" target="_blank" rel="noreferrer noopener nofollow">Analysts at ANY.RUN identified this malware cluster and published a detailed&nbsp;report</a></strong> shared with Cyber Security News (CSN).</p>



<p class="wp-block-paragraph">The team named it after its signature obfuscation method, where variable and function names are constructed from repeated characters in mixed case — for example, IiIiIiIiiIII or KkkKKKkKkK — making the code extremely difficult to read and analyze with standard security tools.</p>



<p class="wp-block-paragraph">The following <strong><a href="https://app.any.run/tasks/e39d92e9-a8c3-4c71-8009-2087847fb669/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=monoglyphrat&amp;utm_content=task&amp;utm_term=030626" target="_blank" rel="noreferrer noopener nofollow">analysis is based on sandbox session</a></strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAeji-W25FkTjJC4qaFgR_LujmhRxfLtLqsfdNoPECcUCdvuvA4YkTDI8Dn6Kzu7GkDrA-W0TFbXYEh-jz7vnHNmSNV78REqReEqtWw7Vc24aygvl0uZaV1I1p-7W8FUoPNu-TidUi4JCyEmGvOlFsC9ITraorvL0x2cUr5hW_03bxYesceE8gqB9utCM/s16000/The%20characteristic%20code%20obfuscation%20(Source%20-%20Any.Run).webp" alt="The characteristic code obfuscation (Source - Any.Run)"/><figcaption class="wp-element-caption">The characteristic code obfuscation (Source &#8211; Any.Run)</figcaption></figure>
</div>


<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 84%,rgb(169,184,195) 100%)">Stop threats before they become costly incidents. <a href="https://any.run/enterprise/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=monoglyphrat&amp;utm_content=enterprise&amp;utm_term=030626#contact-sales" target="_blank" rel="noreferrer noopener nofollow"><strong>Integrate ANY.RUN to detect, investigate, and block attacks like JS.MonoGlyphRAT early. Get for your team</strong></a>.</p>



<p class="wp-block-paragraph">What makes JS.MonoGlyphRAT especially dangerous is that it currently shows up as &#8220;Unknown malware&#8221; on major threat intelligence platforms like VirusTotal and ThreatFox. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwhWG4NBCDB9eGbCxzGwqWJqMGmGxtYCt8hgrpmN-uE70YwkTeOqtQF4FPDo2GoFwLNVrldH5BbFwHpQKBGLr_yl_WR3BEGlhQXZb7-kZmF4z9h0A-_pWgrncRfJOVikhlP9gbMMNnZmfL99qdNWRuFYa8gnJHey_f7r6gDpFIDKj3mSo8oXM_8_H5Wv8/s16000/Obfuscated%20JS%20file%20(Source%20-%20Any.Run).webp" alt="Obfuscated JS file (Source - Any.Run)"/><figcaption class="wp-element-caption">Obfuscated JS file (Source &#8211; Any.Run)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Standard antivirus programs that rely on known signatures simply cannot detect it. The only reliable way to catch it is by watching for suspicious behavior on a system in real time rather than matching files against a known signature database.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The financial consequences of a successful infection can reach well into the millions. Organizations face risks including ransomware deployment, data theft, regulatory penalties, business email compromise, and extended operational downtime. </p>



<p class="wp-block-paragraph">Since MonoGlyphRAT can download and <a href="https://cybersecuritynews.com/hackers-hide-malware-payloads-inside/" id="150679" target="_blank" rel="noreferrer noopener">deploy additional malicious payloads, even a single compromised machine</a> can become the starting point of a far larger and costlier breach for the entire organization.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-hackers-use-fake-purchase-orders" class="wp-block-heading"><strong>Hackers Use Fake Purchase Orders</strong></h2>



<p class="wp-block-paragraph">The attack begins with a single email. Employees in procurement, sales, or finance receive a message containing a JavaScript file named something like PURCHASE ORDER_12258.js or QUOTE_B2026.js. </p>



<p class="wp-block-paragraph">These filenames are designed to look like routine business documents that someone in a buying or selling role would open without a second thought.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8JJ8NMMO8QJyfWSojueJZbUu7GQBlvXg3g-jAJXbQ8LzYk9hzdHXS2veH3xph3bIMeskeF-HfvSMGYy2-pO2in4mel2DBVPlFcdTkPamcCcg1IxGpU3OP5UZcBrqnvb9ZI32yVxZWQ0UO8VhFwinc0sjcbl3-_icgGGy_u1Wug9s3dvipe_BhFji2IG0/s16000/C2%20interaction%20in%20beacon%20loop%20mode%20(Source%20-%20Any.Run).webp" alt="C2 interaction in beacon loop mode (Source - Any.Run)"/><figcaption class="wp-element-caption">C2 interaction in beacon loop mode (Source &#8211; Any.Run)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once the file runs through Windows Script Host (WSH), it silently copies itself into a subfolder within the user&#8217;s profile directory and registers itself in the Windows registry. </p>



<p class="wp-block-paragraph">This gives attackers a permanent foothold, as the malware starts automatically every time the computer reboots without showing any visible sign to the user.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The malware then reaches out to its command-and-control (C2) server over HTTP on non-standard ports to stay off the radar. </p>



<p class="wp-block-paragraph">It collects key system details including the username, domain, operating system version, and hardware profile, then sends that data back to the attacker and enters a silent waiting state ready for further instructions.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-how-js-monoglyphrat-operates-under-the-radar" class="wp-block-heading"><strong>How JS.MonoGlyphRAT Operates Under the Radar</strong></h2>



<p class="wp-block-paragraph">Once the connection is established, attackers can download additional payloads, run <a href="https://cybersecuritynews.com/hackers-leveraging-emoji-code/" id="143104" target="_blank" rel="noreferrer noopener">encrypted PowerShell commands, load malicious code entirely in memory</a> without leaving files on disk, and remotely update or remove the implant. </p>



<p class="wp-block-paragraph">The malware can also patch Windows&#8217; built-in security scanning to suppress detection attempts going forward.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">All C2 communication runs through custom HTTP response headers — X-S carries the active session ID, and X-A delivers the command code. </p>



<p class="wp-block-paragraph">Data exchanged between the infected machine and the attacker is encrypted using AES-128 and XOR encoding, with part of the key hardcoded directly into the malware. This layered approach makes forensic investigation significantly more difficult.</p>



<p class="wp-block-paragraph"><strong><a href="https://any.run/features/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=monoglyphrat&amp;utm_content=features&amp;utm_term=030626" target="_blank" rel="noreferrer noopener nofollow">Using&nbsp;Interactive Sandbox</a></strong>, analysts can safely execute suspicious JavaScript attachments and immediately observe malicious behaviors associated with MonoGlyphRAT, including the execution of wscript.exe, PowerShell spawning, registry-based persistence, C2 communications, and payload delivery attempts.</p>



<p class="wp-block-paragraph">MonoGlyphRAT C2 protocol operation scheme (Source &#8211; Any.Run)<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Security teams are strongly advised to monitor for behavioral signals rather than relying solely on antivirus signatures. </p>



<p class="wp-block-paragraph">Key warning signs include wscript.exe executing JavaScript files from user directories, <a href="https://cybersecuritynews.com/hackers-actively-exploiting-powershell/" id="106441" target="_blank" rel="noreferrer noopener">PowerShell processes launched with encoded command flags</a>, new registry run keys pointing to .js files, and HTTP POST traffic to unusual ports with patterns like a=iz&amp;b=. </p>



<p class="wp-block-paragraph">Detecting this threat early requires behavioral monitoring and sandbox-based analysis, not traditional signature matching. <a href="https://any.run/enterprise/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=monoglyphrat&amp;utm_content=enterprise&amp;utm_term=030626#contact-sales" target="_blank" rel="noreferrer noopener nofollow"><strong>Try ANY.RUN to strengthen your proactive defense</strong></a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a6a4d22c-90b4-481a-9e9b-86b73ee2aef9/Hackers-Use-Fake-Purchase-orders-to-Deploy-JS.MonoGlyphRAT-Targeting-US-Enterprises.pdf?AWSAccessKeyId=ASIA2F3EMEYE7RIZQFTV&amp;Signature=9BpI2BuvQK7XqRKrBh9kfFHy5HM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEHMaCXVzLWVhc3QtMSJHMEUCIQCSD4sO0p9Jn2YODG8jd%2F7MuiyrD3YcWogHUrBJ9LosowIgdoC4yeHM4OX2QGnIYAanf5cg7oZVii3TgzaCjg8sZlkq8wQIOxABGgw2OTk3NTMzMDk3MDUiDEJHMNooCOGTl607TirQBKMxsLmcguVuh7Z9GylazfYXv1pgiy0rL88siU9xOki7PSb2FdC2QSHAq5eVXplysxqhqvThaclpCO2QFX5YQkQCyDVQopiIr0CkoG9no1Xf%2BQO4Kn1bIN8R3qPZbQu1%2BCTnjckFjvdkyzk%2FtfNIOKSWHd2YhscN8ehDtzaG9%2Fc%2FjgVtuzaWFyyePl4vDgaXc%2FTG42GjLZuEqjjov4MW8uBz%2BKGxruGqptQ2CbclfcJ3tlX2yOJCZ6fVDUT0NgacOTrEwQZ9va6rUF7FCe%2Fx%2BL%2BXm8XwjsY0VDiqzof8enm1eHWIwT89RWAfNPVxv%2BX1p5OIBkEz%2BqRnetDRlver4YiE5uRD7DrHgeJ1XzD%2B2ZZNZf8fvufERKgK%2F%2BTKJuQvQPtDa6z0VnZHRJDPlXkGKuW0tAKxIQAf6DZhOpt4Q7W3oGkl0nq%2BiQ7cJ2fFXTMLLsh%2FHUxKTIuUTFFiZlAF3ozViRCtGrdr8aRcn4QGoi2YFae0S60p8Y9J%2FkQLdOF8zAVZf0XNHe1SeIj%2BsQAgh7wn6ik77i6uRVvfcI5hLFH2oZPp2x5CaCZ9lE2Rw8FjB1YKP37rUdCUrRDr7gk5cBd6M6ZtFLHCq2lz4Mb0Qd9hF5LwvJhWVQsbZRA9M3urofcirMPAXqfbzxBauMinl1CbLXoPkProCNqe1GkpFcqLvktbwjMtmcGGMm6U3g4eWb9lVRidNi7iETUkvPTyR%2FKed7h%2FkDhdzd%2Fdg%2Fv5wdmzFWOU%2B5sDux3eY%2FiW%2B2%2Fa6yhjBIh16J8p10qeMxkpjdMwg%2Fv%2F0AY6mAFX9B5zhuQTSIYi%2FB7HnqdFCK51pkqREjzLysYcWJwC3dNUtkgTfLol0TdbpGEjrjBiH7Z25QrplLAm2xCHTskU47YBEnbd4Q9E89JlV2zmMlawpyqZEtuIqdS%2Bglp1owt2LDByn41jQkHaJjn0s026XrC6SbstqvDQE%2Foe621cNBd0tT52qjwNTA22lhkXrV3GBpGxE4EDtg%3D%3D&amp;Expires=1780484950" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IP Address</td><td>158.94.211.76</td><td>Primary C2 server IP address</td></tr><tr><td>IP Address</td><td>91.92.243.79</td><td>Secondary C2 server IP address</td></tr><tr><td>URL</td><td>hxxp://158.94.211.76:34567/ceoznp</td><td>C2 beacon endpoint</td></tr><tr><td>URL</td><td>hxxp://158.94.211.76:34567/ceoznp?ia=GEZHOV8LBB7PY4KX&amp;df=</td><td>C2 check-in URL with session parameter</td></tr><tr><td>URL</td><td>hxxp://158.94.211.76:34567/ceoznp?ia=UDP3HIP4P5SH3U5R&amp;df=</td><td>C2 check-in URL with alternate session</td></tr><tr><td>Domain</td><td>aryamint.com</td><td>C2 infrastructure domain</td></tr><tr><td>Domain</td><td>scan.aryamint.com</td><td>C2 infrastructure subdomain</td></tr><tr><td>File Hash (SHA256)</td><td>5446b24959c1c2707accfc257aaac61819c01d1ed65bca910a7e8be1787d20b</td><td>Obfuscated JS malware sample</td></tr><tr><td>File Name</td><td>PURCHASE ORDER_12258.js</td><td>Phishing lure filename</td></tr><tr><td>File Name</td><td>QUOTE_B2026.js</td><td>Phishing lure filename</td></tr><tr><td>File Name</td><td>CKML220066 – MSRS no. 812399.js</td><td>Phishing lure filename</td></tr><tr><td>File Name</td><td>QUOTATION2026115.js</td><td>Phishing lure filename</td></tr><tr><td>Registry Key</td><td>HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;random&gt;</td><td>Persistence registry key</td></tr><tr><td>File Path</td><td>%USERPROFILE%&lt;random letters&gt;&lt;random letters&gt;.js</td><td>Malware installation path</td></tr><tr><td>HTTP Header</td><td>X-A:</td><td>C2 command delivery header</td></tr><tr><td>HTTP Header</td><td>X-S:</td><td>C2 session ID header</td></tr><tr><td>HTTP Pattern</td><td>POST body: a=iz&amp;b=&lt;data&gt;</td><td>C2 check-in POST body pattern</td></tr><tr><td>Query Parameter</td><td>ia=&lt;session_id&gt;</td><td>C2 session identifier parameter</td></tr><tr><td>Query Parameter</td><td>df=0</td><td>C2 telemetry upload parameter</td></tr><tr><td>Query Parameter</td><td>ex=&lt;token&gt;</td><td>C2 file download parameter</td></tr><tr><td>Query Parameter</td><td>sb=&lt;token&gt;</td><td>C2 loader/stage parameter</td></tr><tr><td>Query Parameter</td><td>vc=&lt;token&gt;</td><td>C2 payload URL parameter</td></tr><tr><td>Crypto IV</td><td>sixteenbyteslong</td><td>Static AES initialization vector (plaintext)</td></tr><tr><td>Encoded IV</td><td>76E6F6C63756479726E6565647879637</td><td>AES IV in reversed hex encoding</td></tr><tr><td>Suricata Rule ID</td><td>85006579</td><td>Detection rule for C2 traffic</td></tr><tr><td>Suricata Rule ID</td><td>85006580</td><td>Detection rule for C2 traffic</td></tr><tr><td>Suricata Rule ID</td><td>85006581</td><td>Detection rule for C2 traffic</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/hackers-use-fake-purchase-orders-to-deploy-js-monoglyphrat/">Hackers Use Fake Purchase Orders to Deploy JS.MonoGlyphRAT Targeting US Enterprises</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://i3.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi75S1dePL_Fh0VHZW7L30Oi6smtqlSiES1J9rV2vkpCwdY3nghYjpuIJB8tjRgUcN4QHykWw_gd7Snso4SxF9EQ8Nqpn2JDkgHdoUlSxRawFC4naSNUv7zEz8v59r4WaSFtjdtyn_SZvUbg-HVfDKGWNzU8yJ06xnckEm0fjW8j1kG5MTF0zPXZ9oPmw/s16000/Fake%20Purchase%20Orders%20Deploy%20JS.MonoGlyphRAT%20Malware.webp?ssl=1" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151758</post-id>	</item>
		<item>
		<title>CISA and Partners Warns of Cyberattacks Targeting U.S.-based Automatic Tank Gauge Systems</title>
		<link>https://cybersecuritynews.com/cyberattacks-targeting-u-s-based-automatic-tank-gauge-systems/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 15:52:01 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151769</guid>

					<description><![CDATA[<p>A serious wave of cyberattacks is now targeting a piece of infrastructure that most people never think about. Automatic Tank Gauge systems, commonly known as ATG systems, are used across the United States to remotely monitor fuel levels, liquid volumes, temperatures, and potential leaks in storage tanks. These systems sit quietly in the background, keeping [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/cyberattacks-targeting-u-s-based-automatic-tank-gauge-systems/">CISA and Partners Warns of Cyberattacks Targeting U.S.-based Automatic Tank Gauge Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A serious wave of cyberattacks is now targeting a piece of infrastructure that most people never think about. </p>



<p class="wp-block-paragraph">Automatic Tank Gauge systems, commonly known as ATG systems, are used across the United States to remotely monitor fuel levels, liquid volumes, temperatures, and potential leaks in storage tanks. </p>



<p class="wp-block-paragraph">These systems sit quietly in the background, keeping operations running at gas stations, farms, chemical plants, and transportation hubs. Now, threat actors are actively going after them.</p>



<p class="wp-block-paragraph">ATG systems are deployed across the Energy, Chemical, Food and Agriculture, and Transportation sectors. They are critical because they automate what would otherwise require constant manual oversight. </p>



<p class="wp-block-paragraph">But that same network connectivity that makes them useful has also made them a target. Attackers are exploiting the fact that many of these systems are left exposed to the open internet, often with weak or default passwords still in place.</p>



<p class="wp-block-paragraph"><a href="https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems" id="https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems" target="_blank" rel="noreferrer noopener nofollow">CISA, in a report</a> shared with Cyber Security News (CSN), along with the FBI, NSA, DOE, EPA, TSA, DOT, and USDA, confirmed active malicious cyber activity targeting U.S.-based ATG systems. </p>



<p class="wp-block-paragraph">The agencies noted that threat actors are compromising internet-exposed devices and actively modifying them through direct command execution. The U.S. government has not yet attributed the activity to any specific nation-state or threat group.</p>



<p class="wp-block-paragraph">The attacks are not theoretical. Threat actors are gaining access, running commands, and in some cases taking full control of these systems as if they were standing right in front of the hardware. </p>



<p class="wp-block-paragraph">Once inside, they can change network settings, adjust tank volume readings, alter pump controls, and disable the alerts that operators rely on to catch dangerous problems early.</p>



<p class="wp-block-paragraph">The consequences could reach well beyond a network intrusion. A compromised ATG system can create what experts call a &#8220;denial of view&#8221; condition, where operators can no longer see accurate fill levels. </p>



<p class="wp-block-paragraph">Left unchecked, this could lead to physical damage to tank infrastructure, environmental hazards, or spills from relay failures.</p>



<h2 id="h-cisa-and-partners-warns-of-cyberattacks" class="wp-block-heading"><strong>CISA and Partners Warns of Cyberattacks</strong></h2>



<p class="wp-block-paragraph">The attack methods described in the advisory are not exotic, but they are effective. Threat actors exploit authentication bypass flaws and hardcoded credentials to slip past device management interfaces without a valid login. </p>



<p class="wp-block-paragraph">Once they have a foothold, they use operating system command execution and SQL injection to run arbitrary code and manipulate the underlying databases that manage tank data.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/unifi-os-vulnerabilities-privilege-escalation/" id="150736" target="_blank" rel="noreferrer noopener">From there, privilege escalation gives attackers full administrator control</a> over both the device software and the operating system. </p>



<p class="wp-block-paragraph">They can make devices report false readings, suppress safety alarms, or cause components to malfunction in ways that are hard to detect until real damage is done. The simplicity of these entry points is especially concerning given how widely ATG devices are deployed across critical industries.</p>



<h2 id="h-steps-to-protect-atg-systems-now" class="wp-block-heading"><strong>Steps to Protect ATG Systems Now</strong></h2>



<p class="wp-block-paragraph">CISA and its partner agencies have outlined clear steps that ATG owners and operators should take immediately. The most urgent action is removing these systems from direct internet exposure. </p>



<p class="wp-block-paragraph">The ATG serial port, which defaults to TCP ports 8001, 9001, or 10001, should never be publicly accessible. If remote access is truly needed, it must be protected behind a firewall, an access control list, or a VPN.</p>



<p class="wp-block-paragraph">Operators should change any default passwords right away and set strong, unique credentials for every interface, including the serial port. Where possible, phishing-resistant multifactor authentication should be enabled. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/memory-corruption-access-vulnerabilities-patched/" id="90127" target="_blank" rel="noreferrer noopener">Keeping software patched and working with certified service providers</a> to apply the latest manufacturer updates is equally important.</p>



<p class="wp-block-paragraph">Organizations should enable detailed logging and regularly <a href="https://cybersecuritynews.com/unauthorized-access-attempts-in-active-directory/" id="106529" target="_blank" rel="noreferrer noopener">audit those logs for signs of unauthorized access</a>, unusual alarm activity, or unexpected configuration changes. </p>



<p class="wp-block-paragraph">Any suspected incidents should be reported to CISA at report@cisa.gov or by calling 888-282-0870. The FBI also accepts complaints through the Internet Crime Complaint Center at www.ic3.gov.</p>



<p class="wp-block-paragraph">The threat to ATG systems is a reminder that industrial control devices are in the crosshairs of attackers. Leaving them exposed and unprotected is no longer an option.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/cyberattacks-targeting-u-s-based-automatic-tank-gauge-systems/">CISA and Partners Warns of Cyberattacks Targeting U.S.-based Automatic Tank Gauge Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/CISA-and-Partners-Warns-of-Cyberattacks-Targeting-U.S.-based-Automatic-Tank-Gauge-Systems.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151769</post-id>	</item>
		<item>
		<title>Five OpenClaw 0-Days let Attackers to Hijack Trusted AI Agent Access</title>
		<link>https://cybersecuritynews.com/five-openclaw-0-days/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 14:15:22 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151775</guid>

					<description><![CDATA[<p>Five zero-day flaws in OpenClaw allowed attackers to bypass trust boundaries and hijack AI agent access across multiple messaging platforms. OpenClaw, which integrates AI agents with services such as Slack, Discord, Microsoft Teams, Matrix, and Telegram, relies heavily on user-defined allowlists to determine who can interact with an agent. This trust model assumes that only [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/five-openclaw-0-days/">Five OpenClaw 0-Days let Attackers to Hijack Trusted AI Agent Access</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Five zero-day flaws in OpenClaw allowed attackers to bypass trust boundaries and <a href="https://cybersecuritynews.com/openclaw-0-click-vulnerability/" target="_blank" rel="noreferrer noopener">hijack AI agent access</a> across multiple messaging platforms.</p>



<p class="wp-block-paragraph">OpenClaw, which integrates AI agents with services such as Slack, Discord, Microsoft Teams, Matrix, and Telegram, relies heavily on user-defined allowlists to determine who can interact with an agent.</p>



<p class="wp-block-paragraph">This trust model assumes that only explicitly approved identities can issue commands to agents that may have access to sensitive data, internal APIs, or system-level execution capabilities.</p>



<p class="wp-block-paragraph">However, Philip Garabandic found that this trust model breaks down due to improper identity resolution during allowlist processing.</p>



<h2 id="h-five-openclaw-0-days" class="wp-block-heading"><strong>Five OpenClaw 0-Days</strong></h2>



<p class="wp-block-paragraph">The vulnerabilities stem from a recurring design flaw in which human-readable identifiers, such as display names, are resolved to stable user IDs during service initialization.</p>



<p class="wp-block-paragraph">Because display names are mutable across most chat platforms, attackers can impersonate trusted users simply by renaming themselves to match an allowlisted identity.</p>



<p class="wp-block-paragraph">This issue was initially identified in <a href="https://cybersecuritynews.com/hacking-groups-exploit-openclaw/" target="_blank" rel="noreferrer noopener">OpenClaw’s Telegram integration </a>and patched under advisory GHSA-mj5r-hh7j-4gxf.</p>



<p class="wp-block-paragraph">Despite the fix, the same root cause persisted across five additional channel extensions, specifically<a href="https://cybersecuritynews.com/microsoft-tool-migrate-slack-to-teams/" target="_blank" rel="noreferrer noopener"> Slack</a>, <a href="https://cybersecuritynews.com/discord-end-to-end-encryption-default/" target="_blank" rel="noreferrer noopener">Discord</a>, <a href="https://cybersecuritynews.com/hackers-using-new-matrix-push-c2/" target="_blank" rel="noreferrer noopener">Matrix,</a> <a href="https://cybersecuritynews.com/hackers-targeting-users-who-lodged/" target="_blank" rel="noreferrer noopener">Zalo</a>, and <a href="https://cybersecuritynews.com/hackers-use-teams-steal-credentials/" target="_blank" rel="noreferrer noopener">Microsoft Teams.</a></p>



<p class="wp-block-paragraph">Each implementation independently reintroduced the same insecure pattern, highlighting a broader issue in distributed development and inconsistent security enforcement.</p>



<p class="wp-block-paragraph">At the core of the vulnerability is a flawed startup resolution process. While runtime checks typically validate stable user IDs, the initialization logic resolves allowlist entries via directory lookups based on mutable fields such as displayName or username.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG-u-NvQgveLockF5djx1JgFh59EXAp9nMCzy5OCCnB0CAZDc96OdCxcoleg62LZf7XvmuzGF7RW9BHbSMRvb4cxsXfjrGRU5k96kvYksEhxYbFLwajan5fGWv6h8VNYhlnTD9CZzzdLupKC6Qrn2q0EGVVBU5F6ZFpqLBRUj04MZzA6Acx6El4dreF8s/s1600/Screenshot%202026-06-03%20181458%20%281%29.webp" alt="Example view after running full base on juice shop(source : medium /infosecwriteups)"/><figcaption class="wp-element-caption">Example view after running full base on juice shop(source: Philip Garabandic / Infosecwriteups)</figcaption></figure>



<p class="wp-block-paragraph">If an attacker changes their display name to match an allowlisted user before a service restart, the system may incorrectly bind the attacker’s ID into the trusted allowlist.</p>



<p class="wp-block-paragraph">Once this occurs, the attacker gains full control over agent interactions while the legitimate user is silently excluded.</p>



<p class="wp-block-paragraph">The vulnerabilities were identified using a specialized AI-driven static analysis tool called agentgg, which generates custom detectors based on historical advisories.</p>



<p class="wp-block-paragraph">By analyzing prior <a href="https://cybersecuritynews.com/openclaw-vulnerabilities/" target="_blank" rel="noreferrer noopener">OpenClaw vulnerabilities</a>, the tool developed targeted detection logic for recurring anti-patterns, ultimately identifying a flaw replicated across multiple modules.</p>



<p class="wp-block-paragraph">Each finding has since been acknowledged and addressed by OpenClaw maintainers, with fixes that enforce strict ID-based matching and gate name-based resolution behind explicit configuration flags.</p>



<p class="wp-block-paragraph">From a security perspective, this class of <a href="https://cybersecuritynews.com/mitre-releases-top-25-most-dangerous-software/" target="_blank" rel="noreferrer noopener">vulnerability aligns with CWE-639</a>, which describes bypassing authorization through user-controlled identifiers.</p>



<p class="wp-block-paragraph">The impact is particularly severe in AI agent environments, where compromised access can translate into arbitrary command execution, data exfiltration, or lateral movement within integrated systems.</p>



<p class="wp-block-paragraph"><a href="https://infosecwriteups.com/one-agent-five-zero-days-turning-past-cves-into-sast-rules-650c32b20032" target="_blank" rel="noreferrer noopener nofollow">According to Philip Garabandic</a>, the incident highlights that patching one component does not eliminate the underlying vulnerability class.</p>



<p class="wp-block-paragraph">Without systemic detection mechanisms, the same flaw can silently propagate across parallel implementations.</p>



<p class="wp-block-paragraph">By operationalizing past incident data into automated detection workflows, organizations can prevent repeated failures and strengthen trust boundaries in increasingly complex AI-driven architectures.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/five-openclaw-0-days/">Five OpenClaw 0-Days let Attackers to Hijack Trusted AI Agent Access</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Five-OpenClaw-0-Days-let-Attackers-to-Hijack-Trusted-AI-Agent-Access.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151775</post-id>	</item>
		<item>
		<title>WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks</title>
		<link>https://cybersecuritynews.com/wordpress-plugin-vulnerability-exposes-2/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 14:11:42 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151762</guid>

					<description><![CDATA[<p>A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8, the vulnerability impacts Kirki plugin versions 6.0.0 through 6.0.6. The issue [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/wordpress-plugin-vulnerability-exposes-2/">WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A critical security flaw in the widely used Kirki <a href="https://cybersecuritynews.com/wordpress-plugin-vulnerability-admin-access/" target="_blank" rel="noreferrer noopener">WordPress plugin has exposed </a>over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions.</p>



<p class="wp-block-paragraph">Tracked as CVE-2026-8206 with a CVSS score of 9.8, the vulnerability impacts Kirki plugin versions 6.0.0 through 6.0.6.</p>



<p class="wp-block-paragraph">The issue allows unauthenticated attackers to escalate privileges by abusing a flawed <a href="https://cybersecuritynews.com/password-reset-poisoning-attack/" target="_blank" rel="noreferrer noopener">password reset mechanism</a>, ultimately enabling full compromise of administrator accounts.</p>



<p class="wp-block-paragraph">The vulnerability was discovered by security researcher Choigyeongmin and reported through the Wordfence Bug Bounty Program, earning a reward of $6,436.</p>



<p class="wp-block-paragraph">Wordfence validated the issue on May 8, 2026, and quickly deployed firewall protections for premium users on May 9, ahead of public disclosure.</p>



<h2 id="h-wordpress-plugin-vulnerability-exposes-websites" class="wp-block-heading"><strong>WordPress Plugin Vulnerability Exposes</strong> <strong>Websites</strong></h2>



<p class="wp-block-paragraph">Kirki, a popular plugin used for WordPress customizer enhancements and page building, exposes a REST API endpoint responsible for handling password reset requests.</p>



<p class="wp-block-paragraph">The vulnerability exists in the handle_forgot_password() function, where user input is improperly trusted during the reset process.</p>



<p class="wp-block-paragraph">In a secure implementation, a password reset request should send a reset link only to the email address associated with the targeted user account.</p>



<p class="wp-block-paragraph">However, in the vulnerable versions, the plugin accepts both username and email parameters without verifying their relationship.</p>



<p class="wp-block-paragraph">When a valid username is supplied, the plugin correctly identifies the user account. However, it continues to use the attacker-controlled email address provided in the request.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwpeAqFfWqsstCDTATyhyphenhyphen-M2Dv8xM46jxh9GS3-PSrrH0yv_mnCietBnp0pqyWGiZfshyphenhyphenpVEnu8_WPF788T6N3-foyWW6n1mZ725j1b4-SgUeoYTnqqG3ZaoHH5-J5YewaZQmHXsoiZjCi5nL72_G81ngSyZwsY3kJ6s_6TnhPE65FgreDIhj6VbSrNX0/s1600/Screenshot%202026-06-03%20164438%20%281%29.webp" alt="Attack path and Wordfence firewall blocking exploitation attempts(source :Wordfence)"/><figcaption class="wp-element-caption">Attack path and Wordfence firewall blocking exploitation attempts(source: Wordfence)</figcaption></figure>



<p class="wp-block-paragraph">This logic flaw enables a straightforward exploitation scenario. An attacker submits a password reset request with a legitimate username, such as an administrator, alongside an arbitrary email address they control.</p>



<p class="wp-block-paragraph">The plugin then generates a valid reset token and sends it to the attacker’s email instead of the legitimate user&#8217;s.</p>



<p class="wp-block-paragraph">Using the reset link, the attacker can set a new password and <a href="https://cybersecuritynews.com/wordpress-plugin-flaw-lets-attackers-bypass-authentication/" target="_blank" rel="noreferrer noopener">gain unauthorized access</a> to the account. Successful exploitation can lead to complete site compromise.</p>



<p class="wp-block-paragraph">Attackers may install malicious plugins, <a href="https://cybersecuritynews.com/hackers-hide-backdoor-in-trusted-wordpress-plugins/" target="_blank" rel="noreferrer noopener">inject backdoors</a>, create rogue administrator accounts, or deploy persistent webshells, aligning with common post-exploitation techniques mapped to privilege escalation and persistence tactics.</p>



<p class="wp-block-paragraph"><a href="https://www.wordfence.com/blog/2026/06/unauthenticated-privilege-escalation-vulnerability-patched-in-kirki-wordpress-plugin/" target="_blank" rel="noreferrer noopener nofollow">Wordfence reported the flaw</a> to Themeum on May 15, 2026, and a patch was released in version 6.0.7 just three days later.</p>



<p class="wp-block-paragraph">Mitigation is straightforward but urgent. Website administrators are strongly advised to update the Kirki plugin to version 6.0.7 or later immediately.</p>



<p class="wp-block-paragraph">Additional protections are available through Wordfence firewall rules, with premium users already protected and free users scheduled to receive coverage on June 8, 2026.</p>



<p class="wp-block-paragraph">Given the ease of exploitation and high impact, this vulnerability represents a significant<a href="https://cybersecuritynews.com/critical-wordpress-plugin-vulnerability-3/" target="_blank" rel="noreferrer noopener"> risk to WordPress environments</a>, particularly those with exposed user enumeration or publicly accessible login functionality. Prompt patching and monitoring for suspicious password reset activity are essential to prevent compromise.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/wordpress-plugin-vulnerability-exposes-2/">WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/WordPress-Plugin-Vulnerability-Exposes-500000-Websites-to-Privilege-Escalation-Attacks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151762</post-id>	</item>
		<item>
		<title>Hackers Using AI Tools to Automate Active Directory Attacks and EDR Evasion</title>
		<link>https://cybersecuritynews.com/hackers-using-ai-red-team-tools/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 13:47:15 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151766</guid>

					<description><![CDATA[<p>A threat actor used AI-assisted tools to automate Active Directory discovery and test endpoint detection and response (EDR) evasion techniques, highlighting the rise of AI-supported post-exploitation frameworks. The activity was identified after a suspicious endpoint triggered alerts tied to payloads stored in a user directory. Investigation revealed a collection of malicious components forming a structured [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-using-ai-red-team-tools/">Hackers Using AI Tools to Automate Active Directory Attacks and EDR Evasion</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A threat actor used AI-assisted tools to automate Active Directory discovery and test <a href="https://cybersecuritynews.com/mockingjay-bypass-edr/" target="_blank" rel="noreferrer noopener">endpoint detection and response (EDR)</a> evasion techniques, highlighting the rise of AI-supported post-exploitation frameworks.</p>



<p class="wp-block-paragraph">The activity was identified after a suspicious endpoint triggered alerts tied to payloads stored in a user directory.</p>



<p class="wp-block-paragraph">Investigation revealed a collection of malicious components forming a structured attack toolkit. These included customized Cobalt Strike profiles designed to mimic legitimate web traffic.</p>



<p class="wp-block-paragraph">Telegram bot–based <a href="https://cybersecuritynews.com/shelby-malware-steal-data-abusing-github/" target="_blank" rel="noreferrer noopener">command-and-control channel</a> to hide communications within trusted infrastructure.</p>



<p class="wp-block-paragraph">Python scripts capable of injecting shellcode into legitimate Windows executables while maintaining normal functionality. A Cloudflare Worker was also used as a redirector to obscure the true backend C2 server.</p>



<h2 id="h-hackers-use-ai-red-team-tools" class="wp-block-heading"><strong>Hackers Use AI Red Team Tools</strong></h2>



<p class="wp-block-paragraph">A key finding was the presence of partially AI-generated Python scripts, many written in Russian, alongside a Git repository that contained a broader automation framework.</p>



<p class="wp-block-paragraph">This framework combined an automated AD discovery panel with a controlled lab environment used to iteratively develop and test malware against leading EDR platforms such as <a href="https://cybersecuritynews.com/best-endpoint-protection-solutions-for-msps-mssps/" target="_blank" rel="noreferrer noopener">Sophos, CrowdStrike, and Microsoft Defender</a><a href="https://cybersecuritynews.com/best-endpoint-protection-solutions-for-msps-mssps/">.</a></p>



<p class="wp-block-paragraph">The AD discovery system did not operate as a fully autonomous large language model. Instead, it followed a structured decision tree model, collecting results from executed tasks, selecting predefined next steps, and dispatching actions to remote agents.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik-fpm6uTrhCQL-p2bSHDaEK5wC1Oi2t_ZTu3ePWZWOO_mfdJViDtt4l6hW_Vp7sgZp5811QpXwzWOGyu7w1qHNqxgSmngc33dseqAl-gCidjwX8wGBmAjRX7-Ld40Q2LqOesJCQpmHi8cAsF8xuRDOcyYBsH_cLZEDVCE2-Hr19sbbX9hnkEyi0qYZnU/s1600/Screenshot%202026-06-03%20173237%20%281%29.webp" alt="Diagram showing AI’s role in the malware development workflow (source : sophos)"/><figcaption class="wp-element-caption"><em>Diagram showing AI’s role in the malware development workflow</em> (source : sophos)</figcaption></figure>
</div>


<p class="wp-block-paragraph">This allowed semi-automated reconnaissance across enterprise environments while maintaining predictable execution paths. The threat actor built the testing environment using virtual machines provisioned through Ludus.</p>



<p class="wp-block-paragraph">Multiple Windows Server 2022 systems were configured to evaluate bypass techniques against different EDR agents, alongside a separate Ubuntu system hosting a Sliver command-and-control server.</p>



<p class="wp-block-paragraph">Development was supported by an AI-native IDE, Cursor, and coordinated through multiple AI agents with assigned roles.</p>



<p class="wp-block-paragraph">One primary AI agent, powered by <a href="https://cybersecuritynews.com/claude-opus-to-build-a-working-chrome-exploit-chain/" target="_blank" rel="noreferrer noopener">Claude Opus,</a> managed orchestration and rule-setting. In contrast, others handled testing, operational security improvements, documentation, and infrastructure deployment.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEim1yy84HcQDvN-Cn0N1GDPUz76gx1heRKhQ143KNqjmOSd9SfA7EN0EbLOnZPXbFchE-s7T5Q6Z00Zj7KSPjVZ36UgjDQKFdmL7NSm9jVZUlMGgYOu_P7s63SxnKEe09SphRTNLtjsm1dBu4DuL05OUZlH4dsfrm3_-gN223cKpc8tL3DpmJF4W3KsrK0/s1600/Screenshot%202026-06-03%20173253%20%281%29.webp" alt=""/><figcaption class="wp-element-caption"><em>Article ingestion and technique mapping instructions for AI agents</em> (source : sophos)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Communication between agents and the code repository was managed<a href="https://cybersecuritynews.com/kali-linux-integrates-claude-ai/" target="_blank" rel="noreferrer noopener"> using the Model Context Protocol,</a> enabling automated commits and iterative development cycles.</p>



<p class="wp-block-paragraph">The framework also incorporated research on external threats. AI agents were instructed to ingest publicly available security blogs, extract attack techniques, map them to MITRE ATT&amp;CK, and reproduce them within the lab.</p>



<p class="wp-block-paragraph">Sources included well-known security firms and red team research providers. This process enabled rapid prototyping of attack techniques based on real-world methodologies.</p>



<p class="wp-block-paragraph">At the core of the framework was a modular payload generator written in Python that produced executables in Rust and Go.</p>



<p class="wp-block-paragraph">These payloads were wrapped in layers of encryption and evasion logic, allowing attackers to test over 70 different techniques.</p>



<p class="wp-block-paragraph">While initial success rates were low, repeated iterations reportedly improved bypass effectiveness, though results remain partially unverified.</p>



<p class="wp-block-paragraph"><a href="https://www.sophos.com/en-us/blog/pointing-a-cursor-at-evading-detection" target="_blank" rel="noreferrer noopener nofollow">Sophos researchers assess</a> that this framework, while presented as red team tooling, is likely intended for real-world intrusions, including ransomware deployment and data theft.</p>



<p class="wp-block-paragraph">The use of AI significantly accelerates development cycles but does not fundamentally change defensive requirements.</p>



<p class="wp-block-paragraph">Organizations are advised to maintain strong security baselines, including timely patching, multi-factor authentication, and comprehensive EDR deployment, as attackers increasingly use AI to identify and exploit defensive gaps.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/hackers-using-ai-red-team-tools/">Hackers Using AI Tools to Automate Active Directory Attacks and EDR Evasion</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Hackers-Using-AI-generated-red-team-tools-to-Automate-Active-Directory-Attacks-and-EDR-Evasion.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151766</post-id>	</item>
		<item>
		<title>Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections</title>
		<link>https://cybersecuritynews.com/apache-activemq-header-injection-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 12:47:14 +0000</pubDate>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151750</guid>

					<description><![CDATA[<p>A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross-site scripting and response manipulation attacks in affected deployments. Tracked as CVE-2026-42253, the issue impacts both Apache ActiveMQ and Apache ActiveMQ Web components. The flaw originates from the MessageServlet within [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/apache-activemq-header-injection-vulnerability/">Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A critical <a href="https://cybersecuritynews.com/apache-activemq-vulnerability-3/" target="_blank" rel="noreferrer noopener">vulnerability in Apache ActiveMQ</a> has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross-site scripting and response manipulation attacks in affected deployments.</p>



<p class="wp-block-paragraph">Tracked as CVE-2026-42253, the issue impacts both Apache ActiveMQ and Apache ActiveMQ Web components.</p>



<p class="wp-block-paragraph">The flaw originates from the MessageServlet within the ActiveMQ web console API, which copies all Java Message Service (JMS) message properties directly into HTTP response headers without applying validation or sanitization.</p>



<p class="wp-block-paragraph">This behavior creates a dangerous attack surface that allows adversaries to craft JMS messages with malicious header values, resulting in HTTP response header injection.</p>



<p class="wp-block-paragraph">Because HTTP headers play a critical role in enforcing browser-side security controls such as<a href="https://cybersecuritynews.com/jenkins-gatling-plugin-vulnerability/" target="_blank" rel="noreferrer noopener"> Content Security Policy (CSP)</a>, X-Frame-Options, and Strict-Transport-Security (HSTS), attackers can abuse this flaw to overwrite or inject headers that weaken security protections.</p>



<h2 id="h-apache-activemq-vulnerability" class="wp-block-heading"><strong>Apache ActiveMQ Vulnerability</strong></h2>



<p class="wp-block-paragraph">In real-world scenarios, this could enable cross-site scripting (XSS), session hijacking, or<a href="https://cybersecuritynews.com/svg-clickjacking-attack/" target="_blank" rel="noreferrer noopener"> clickjacking attacks</a>, especially when the ActiveMQ web console is exposed to untrusted users or integrated into enterprise workflows.</p>



<p class="wp-block-paragraph">The vulnerability affects Apache ActiveMQ versions before 5.19.7 and versions from 6.0.0 up to but not including 6.2.6. Similarly, Apache ActiveMQ Web versions before 5.19.7 and 6.x versions before 6.2.6 are also vulnerable.</p>



<p class="wp-block-paragraph">The <a href="https://lists.apache.org/thread/j9vmlc410ht5f28fc98gx75jcbq62j00" target="_blank" rel="noreferrer noopener nofollow">Apache Software Foundation has addressed the issue</a> by disabling and deprecating the MessageServlet component in patched releases, significantly reducing the attack surface.</p>



<p class="wp-block-paragraph">In parallel, another important flaw, <a href="https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-49157</a>, has been identified in Apache ActiveMQ involving incorrect default permissions.</p>



<p class="wp-block-paragraph">This vulnerability allows authenticated low-privilege users to retain access to Jolokia broker management endpoints.</p>



<p class="wp-block-paragraph">Due to overly permissive default authorization settings, non-admin users could execute sensitive broker operations such as creating or deleting queues, actions typically restricted to administrative roles.</p>



<p class="wp-block-paragraph">This flaw raises concerns about privilege escalation and unauthorized broker manipulation in multi-user environments.</p>



<p class="wp-block-paragraph">Both vulnerabilities highlight systemic risks in management interfaces<a href="https://cybersecuritynews.com/hackers-exploit-whatsup-rce-vulnerability/" target="_blank" rel="noreferrer noopener"> exposed via web consoles and APIs</a>, particularly when input validation and access control mechanisms are insufficient.</p>



<p class="wp-block-paragraph">Attackers targeting enterprise messaging systems could chain these issues to manipulate broker behavior while simultaneously weakening frontend security protections.</p>



<p class="wp-block-paragraph">Security researchers Vishal Shukla, pyn3rd, uname, and 4ra1n were credited with discovering the header injection flaw. At the same time, Leon Johnson reported the Jolokia permission issue.</p>



<p class="wp-block-paragraph">Organizations using Apache ActiveMQ are strongly advised to upgrade immediately to versions 5.19.7 or 6.2.6, as both vulnerabilities have been remediated in those versions.</p>



<p class="wp-block-paragraph">Additionally, administrators should review the exposure of the ActiveMQ web console, restrict access to trusted networks, and audit message-handling logic for the unsafe propagation of user-controlled data into HTTP responses.</p>



<p class="wp-block-paragraph">Given ActiveMQ’s widespread use in enterprise messaging and microservices architectures, these vulnerabilities pose a significant risk if left unpatched, particularly in environments where web console access is not tightly controlled.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/apache-activemq-header-injection-vulnerability/">Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Critical-Apache-ActiveMQ-Vulnerability-Allows-malicious-security-header-Injections-.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151750</post-id>	</item>
		<item>
		<title>Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege</title>
		<link>https://cybersecuritynews.com/ivanti-itsm-vulnerability-admin-privilege/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 12:44:59 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151756</guid>

					<description><![CDATA[<p>Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access.  The flaw, tracked as CVE-2026-9614, affects both cloud and on-premises deployments and has been assigned a CVSS score of 8.8, indicating a significant security risk in enterprise [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/ivanti-itsm-vulnerability-admin-privilege/">Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Ivanti has disclosed a high-severity <a href="https://cybersecuritynews.com/ivanti-neurons-itsm-vulnerabilities/" target="_blank" rel="noreferrer noopener">vulnerability in its Ivanti Neurons for ITSM</a> platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access.</p>



<p class="wp-block-paragraph"> The flaw, tracked as CVE-2026-9614, affects both cloud and on-premises deployments and has been assigned a CVSS score of 8.8, indicating a significant security risk in enterprise environments. The vulnerability stems from improper access control, categorized under CWE-284.</p>



<p class="wp-block-paragraph">According to Ivanti, a remote authenticated attacker can <a href="https://cybersecuritynews.com/ivanti-endpoint-manager-authentication-bypass/" target="_blank" rel="noreferrer noopener">exploit this issue</a> without requiring user interaction, enabling unauthorized elevation to administrator-level permissions.</p>



<p class="wp-block-paragraph">The CVSS vector highlights that the attack can be executed over the network with low complexity and limited privileges, while potentially impacting confidentiality, integrity, and availability.</p>



<h2 id="h-ivanti-itsm-vulnerability" class="wp-block-heading"><strong>Ivanti ITSM Vulnerability</strong></h2>



<p class="wp-block-paragraph">Ivanti Neurons for ITSM is widely used for IT service management workflows, including ticketing, asset tracking, and automation.</p>



<p class="wp-block-paragraph">Administrative access within such platforms can expose sensitive organizational data and allow attackers to manipulate system configurations or create persistent backdoors.</p>



<p class="wp-block-paragraph">For example, an attacker with compromised low-level credentials could exploit CVE-2026-9614 to <a href="https://cybersecuritynews.com/ivanti-itsm-vulnerability/" target="_blank" rel="noreferrer noopener">elevate privileges </a>and modify user roles, effectively taking control of the ITSM environment. The vulnerability impacts on-premises versions 2025.4 and earlier.</p>



<p class="wp-block-paragraph">Ivanti has released patches to address the issue in version 2025.4 Patch 1, as well as backported fixes in 2025.3 Patch 1 and 2025.2 Patch 1.</p>



<p class="wp-block-paragraph">Organizations running affected versions are strongly advised to update immediately through the Ivanti License System portal.</p>



<p class="wp-block-paragraph">For cloud customers, Ivanti has already applied fixes across all environments. The company confirmed that patches were deployed during updates rolled out on May 24 and 25, specifically in versions 2026.1 Patch 9 and 2026.2 Patch 1.</p>



<p class="wp-block-paragraph">Additional updates were later issued to resolve a separate logging issue affecting<a href="https://cybersecuritynews.com/chrome-to-add-new-protect-your-ip-address/" target="_blank" rel="noreferrer noopener"> IP address tracking</a>. However, this secondary bug is unrelated to the core vulnerability.</p>



<p class="wp-block-paragraph">At the time of disclosure, Ivanti stated that there is no evidence of active exploitation in the wild. However, given the ease of exploitation and the potential impact, the company issued an out-of-band security advisory to accelerate remediation efforts.</p>



<p class="wp-block-paragraph"><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US" id="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US" target="_blank" rel="noreferrer noopener nofollow">Ivanti also noted</a> that there are currently no publicly available indicators of compromise associated with this vulnerability.</p>



<p class="wp-block-paragraph">As a precaution, organizations are encouraged to audit role-based access controls and verify that administrative privileges are restricted to intended users. Misconfigured roles could increase exposure and make exploitation easier.</p>



<p class="wp-block-paragraph">Security teams should prioritize patching and conduct internal reviews of access permissions within their ITSM deployments. Given the critical role these platforms play in enterprise operations, timely remediation is essential to prevent potential abuse by threat actors.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/ivanti-itsm-vulnerability-admin-privilege/">Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Ivanti-ITSM-Vulnerability-let-Attackers-Gain-Admin-Privilege-.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151756</post-id>	</item>
	</channel>
</rss>
