<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Mon, 01 Jun 2026 16:07:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>Microsoft Office for the Web and Teams Hit by File Access Outage</title>
		<link>https://cybersecuritynews.com/microsoft-office-teams-file-access/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:07:30 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151546</guid>

					<description><![CDATA[<p>Microsoft experienced a service disruption affecting users&#8217; ability to open files through Office for the Web and Microsoft Teams, with the company confirming resolution after investigating elevated error rates across its online productivity platform. The incident, tracked internally under MO1329446 in the Microsoft 365 Admin Center, began with widespread user reports of file-access failures across [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-office-teams-file-access/">Microsoft Office for the Web and Teams Hit by File Access Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft experienced a service disruption affecting users&#8217; ability to open files through Office for the Web and Microsoft Teams, with the company confirming resolution after investigating elevated error rates across its online productivity platform.</p>



<p class="wp-block-paragraph">The incident, tracked internally under MO1329446 in the Microsoft 365 Admin Center, began with widespread user reports of file-access failures across web-based Office experiences.</p>



<p class="wp-block-paragraph">Users attempting to open documents, spreadsheets, or presentations via the browser-based Office suite or Teams encountered errors, disrupting collaboration workflows for potentially millions of enterprise users globally.</p>



<p class="wp-block-paragraph">Microsoft&#8217;s engineering team initially acknowledged the issue, stating they were &#8220;investigating reports that some users are unable to open files in Office for the Web or <a href="https://cybersecuritynews.com/microsoft-teams-vulnerability-spoofing/" target="_blank" rel="noreferrer noopener">Microsoft Teams</a>.&#8221; Shortly after, the team confirmed detection of elevated error rates spanning multiple Office for the Web services.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<div class="embed-x"><blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr">We’re investigating reports that some users are unable to open files in Office for the web or Microsoft Teams. For more information, please see MO1329446 in the admin center.</p>&mdash; Microsoft 365 Status (@MSFT365Status) <a href="https://x.com/MSFT365Status/status/2061445951143686267?ref_src=twsrc%5Etfw">June 1, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></div>
</div></figure>



<p class="wp-block-paragraph">Engineers conducted service telemetry analysis to identify the failure scope, correlating error patterns across service dependencies to determine the root cause and remediation path.</p>



<p class="wp-block-paragraph">The cross-dependency investigation suggests the disruption may have stemmed from a shared backend component or infrastructure layer serving multiple Microsoft 365 services simultaneously, a pattern consistent with prior Azure-backed service incidents.</p>



<p class="wp-block-paragraph">Microsoft has not yet publicly disclosed whether the incident originated from a code deployment, configuration change, or underlying infrastructure fault.</p>



<p class="wp-block-paragraph">Microsoft confirmed that the impact is no longer occurring and has published final<a href="https://admin.cloud.microsoft/?#/servicehealth/:/alerts/MO1329446" target="_blank" rel="noreferrer noopener nofollow"> incident details under MO1329446</a> in the Microsoft 365 Admin Center. Affected organizations with active Microsoft 365 subscriptions can review the post-incident report through their admin portals for detailed timelines and remediation steps.</p>



<p class="wp-block-paragraph">Enterprises relying on Microsoft 365 for critical workflows are advised to monitor the <a href="https://status.cloud.microsoft/" target="_blank" rel="noreferrer noopener nofollow">Microsoft 365 Service Health Dashboard</a> for real-time status updates and configure admin center alerts to receive proactive notifications during future service disruptions.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-office-teams-file-access/">Microsoft Office for the Web and Teams Hit by File Access Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Microsoft-Office-Teams-File-Access.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151546</post-id>	</item>
		<item>
		<title>Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</title>
		<link>https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:06:10 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151532</guid>

					<description><![CDATA[<p>Attackers are actively exploiting misconfigurations in Docker and Kubernetes environments to break out of containers and take full control of the underlying host systems. What was once a niche concern has grown into a serious and escalating threat, with attackers running multi-stage operations that extend well beyond a single compromised container. Modern container platforms are [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/">Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Attackers are actively exploiting misconfigurations in Docker and Kubernetes environments to break out of containers and take full control of the underlying host systems. </p>



<p class="wp-block-paragraph">What was once a niche concern has grown into a serious and escalating threat, with attackers running <a href="https://cybersecuritynews.com/storm-1977-hackers-compromised-200-crypto-mining-containers/" id="102714" target="_blank" rel="noreferrer noopener">multi-stage operations that extend well beyond a single compromised container</a>.</p>



<p class="wp-block-paragraph">Modern container platforms are designed to isolate applications from one another and from the host. But that isolation is only as strong as the configuration behind it. </p>



<p class="wp-block-paragraph">When settings are applied carelessly or left at insecure defaults, the wall between a container and its host becomes dangerously thin, giving attackers a direct path to escalate privileges.</p>



<p class="wp-block-paragraph"><a href="https://securelist.com/container-attack-vectors/120010/" id="https://securelist.com/container-attack-vectors/120010/" target="_blank" rel="noreferrer noopener nofollow">Researchers at Securelist said in a report</a> shared with Cyber Security News (CSN) that these attacks have evolved into multi-stage scenarios involving supply chain compromises, Kubernetes secrets theft, orchestration API abuse, and container escape attempts. </p>



<p class="wp-block-paragraph">In one notable case, the APT group TeamPCP compromised Checkmarx KICS across multiple attack chains, poisoning a Docker Hub repository to steal Kubernetes secrets.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The threat is not limited to exotic zero-day exploits. Misconfigurations are far more common as the root cause of successful breaches than complex kernel vulnerabilities. Attackers look for the low-hanging fruit first, and insecure container configurations remain plentiful across enterprise environments.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153"></a></p>



<p class="wp-block-paragraph">Once inside a compromised container, an attacker rarely needs to do much to find something valuable. Containers routinely hold API keys, SSH keys, access tokens, service credentials, and Kubernetes ServiceAccount tokens. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgavsLD2zTD9w0od5U2yT07rCTkDzPMtoY0rC9j-llBboKbmY0XT2unuSMWppT2PnqgiqqL2tsO6C9CiFHflwGe4KsMNNIrDVGS9_wrSSdW7i-W8zk3e4iM7lf2xBoHB33dzaPqqxS8a2hEcoNj9XVpwbJFcLySmDLSm9szRCbrElFDBAt8IVisTtZHQJ4/s16000/Container%20escape%20attack%20(Source%20-%20Securelist).webp" alt="Container escape attack (Source - Securelist)" /><figcaption class="wp-element-caption">Container escape attack (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">These assets alone can be enough to pivot into cloud infrastructure or establish long-term persistence without ever escaping the container.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-attackers-abuse-docker-and-kubernetes-misconfigurations" class="wp-block-heading"><strong>Attackers Abuse Docker and Kubernetes Misconfigurations</strong></h2>



<p class="wp-block-paragraph">The most dangerous configuration a container operator can enable is the privileged flag. When a container runs with this setting, it receives all Linux capabilities and direct access to host devices, <a href="https://cybersecuritynews.com/apple-carplay-vulnerability-exploited/" id="125638" target="_blank" rel="noreferrer noopener">making it functionally equivalent to root access</a> on the host machine. </p>



<p class="wp-block-paragraph">Using a utility like <code>nsenter</code>, an attacker can spawn a shell outside the container and move freely on the underlying system.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Specific Linux capabilities also open the door to escapes when improperly assigned. The <code>CAP_SYS_ADMIN</code> capability allows a container to mount file systems and interact with kernel parameters. </p>



<p class="wp-block-paragraph">Combined with access to host directories through the <code>hostPath</code> parameter, an attacker can mount the host disk inside the container and overwrite critical system files. <code>CAP_SYS_MODULE</code> lets an attacker load a malicious kernel module that triggers a reverse shell from kernel space.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdbaY0pyQAeI6h5NunXS6q8SJM309I4QxDTlJawQ7-5nEIUPLAwJeu-DhEUkkyLXnKtd6ix4e32_ugWjltpU8u0EHXqP3o8I9BqAAc4sgGLzU_MKOe1q4s8Isosn2SQ3V_-x7ajnMdrnLE_wR90XrXQmE9x8-4GHqLTtELfYmE4f33QYy4WGCnjqM3a3Q/s16000/Container%20and%20C2%20Host%20(Source%20-%20Securelist).webp" alt="Container and C2 Host (Source - Securelist)" /><figcaption class="wp-element-caption">Container and C2 Host (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph"><code>CAP_SYS_PTRACE</code> becomes dangerous when the host PID namespace is shared via <code>hostPID: true</code>. </p>



<p class="wp-block-paragraph">An attacker can then attach to host processes, inject code, and extract sensitive data from memory. <code>CAP_NET_ADMIN</code> enables network stack manipulation and, when combined with <code>hostNetwork: true</code>, opens the door to traffic interception across the environment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Orchestration APIs present an equally serious risk. An exposed Docker API accessible over TCP without authentication gives an attacker remote administrative access to the host. </p>



<p class="wp-block-paragraph">A compromised Kubernetes token with weak RBAC policies can allow deployment of privileged pods and a full cluster takeover with just a few API calls.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-supply-chain-attacks-targeting-container-infrastructure" class="wp-block-heading"><strong>Supply Chain Attacks Targeting Container Infrastructure</strong></h2>



<p class="wp-block-paragraph">Beyond runtime misconfigurations, attackers are going after containers before they are even deployed. Supply chain attacks target the image build and delivery process, injecting malicious code at stages where organizations are least likely to look. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/docker-hub-pushing-malware/" id="63576" target="_blank" rel="noreferrer noopener">Developers who pull public images from Docker Hub without checking their origin</a> are especially vulnerable, since threat actors regularly publish tainted images that mimic legitimate tools.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgv1CP9QwXvWEp9iZXbEsZC7YiT335oYnPTt_A7vsoIJ3VcHoQdOolDXMO5Pl1q_5BL2GLjyA_QaodIpVVeM4nR-ERgaNFNZYVY7-Xh0Mj77zJO3I4RD1lQw_DaWoNvhjtLCkonVzjGEp0JpKT369l5ATMsJIHi93pVvswMiJnPxtyN8Dg_xyPOx7WrPKI/s16000/API%20request%20(Source%20-%20Securelist).webp" alt="API request (Source - Securelist)" /><figcaption class="wp-element-caption">API request (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">CI/CD pipelines are another high-value target. These systems hold elevated privileges and broad infrastructure access. </p>



<p class="wp-block-paragraph">By compromising a single pipeline stage, an attacker can modify Docker image builds, quietly adding hidden scripts or remote management tools, while the container appears legitimate on the outside.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">To defend against these threats, teams should audit container configurations regularly and avoid running containers with the privileged flag. </p>



<p class="wp-block-paragraph">All images should be verified before use, RBAC policies should be tightened, and CI/CD pipelines treated as critical infrastructure with strict access controls. Runtime monitoring and supply chain validation are essential parts of any secure container deployment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58b4745a-339e-4dcc-98be-1af61fa06db9/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYESW3ZSGG6&amp;Signature=XkZCdhuFz1DHDFobRwFSOODXX9I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEcaCXVzLWVhc3QtMSJGMEQCIE23BGGUciO%2BVdwMWXAk6%2BY3edaBHfA9hRX22S22pgUkAiAB2FpxNl%2FSd%2B1aG9TOezb7J2SUGarfeyWaWa%2B5kLBepCrzBAgQEAEaDDY5OTc1MzMwOTcwNSIM8%2F%2F%2FR75oPs4JnRNKKtAED7tJuB27uMAC6e%2FggkBMoEGGBpe0lYo0h%2B6tPlF5rdTPCx60oMxjooyOne84WMh4ZSz7aYCGYlUd9dMJ4yWYP3btZP%2Fc78DPwWSODPU6JyGX%2B30FqXXhTvA0yXCnjRZzWflnYLARyCVhRG4BmtKO%2BgPspJCZjeqt4qFeIfVS2INe7uFuLAYzJ9vG8M98RyryztctIae%2BGdfYBcSEo1xPbd%2FyKq%2F7a24N%2F55zYri0FwgxOjxPciWrOr1LUkHBBozyohGBTLUTAGBtG6PNlwWod7oPv%2FkFh%2Br6KDP73ThzoMW8d%2FdN4oAqLR5Tsvd7DidwnGN%2FDXHpNT7gBhGRppZiami%2BZhcXR4DYrGkQFvpnEPztNbnz8QltE0pIUonCm82JFoR7iu7tEL3nZzLV0qeD4SMnjOWwmEmpROS%2FmBqy%2FjfLCzDbTdrRr%2FuspQ0yv4r%2B6kRjXWM92lZQkR65uYqLqP6nrljn6eYc0zw3jA49wLVWcDD8h8rNeHElmdjvlaH7plD0fZZlBmGAVNhkg20c%2F5IxcZX1uJA8nb%2BtihsZAipv4h2rw7x6D4P9cTC6PYODxJoULtiUm4fJ2Zp8Puaec1KZmXLFB7wJjqsVsf0Wl7CCqoYFQACFt4FKNvGEnmiZKHOyA%2B%2F9hIhLDReyxRcDjQcKMw1%2BUBcS8%2FuA6%2BJXMhjsz8ZmgAgBWhYObjozNJ2ImptvrfLmJ37RHHPDBj7i0oaF7kKm5z0HZE85oTaQFOTc6LmsgOX5mEoSf4OvDjhacY8Flq0dadXzj711W2GbQzC1q%2FbQBjqZAa0Yeje4e%2BsPRrhFRaV23ZDb0JOI4J7jNVsj556obtAXijrkUubxqDVnDqfm%2BRfnXavDJ8SImj%2FOD1QY3Qe4w9oCxZr%2FO%2BfJu0yBgvMR9Bun%2FFaTl7XKArFQnFALulAVIKCSXfhuHukuOPHfMA5krIcZ2MIOgb8XGehqeyEuhUxqzFPZb94s9FXY%2BZcdPxROj54SpodVCpxKfg%3D%3D&amp;Expires=1780326153" target="_blank" rel="noreferrer noopener"></a></p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-docker-and-kubernetes-misconfigurations/">Attackers Abuse Docker and Kubernetes Misconfigurations to Compromise Host Systems</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Attackers-Abuse-Docker-and-Kubernetes-Misconfigurations-to-Compromise-Host-Systems.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151532</post-id>	</item>
		<item>
		<title>SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</title>
		<link>https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 14:42:22 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151509</guid>

					<description><![CDATA[<p>A well-known social engineering campaign called SmartApeSG is back in the spotlight, this time using ClickFix scripts to quietly plant remote access malware on Windows computers. The campaign lures victims through fake verification pages that trick them into running a malicious script without realizing the full damage it causes. What makes this wave especially concerning [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/">SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A well-known social engineering campaign called SmartApeSG is back in the spotlight, this time using ClickFix scripts to quietly plant remote access malware on Windows computers. </p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/new-clickfix-campaign-hijacks-facebook-sessions/" id="140399" target="_blank" rel="noreferrer noopener">campaign lures victims through fake verification pages</a> that trick them into running a malicious script without realizing the full damage it causes. </p>



<p class="wp-block-paragraph">What makes this wave especially concerning is that the attack does not stop at one piece of malware. It delivers a second, more powerful tool once it gains a foothold inside the system.</p>



<p class="wp-block-paragraph">The infection chain starts when a user visits a compromised or malicious website displaying a fake &#8220;verification&#8221; page. This page instructs the visitor to copy and run a PowerShell or similar script, which is the ClickFix technique. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVgRkQdnMT-xhExUADKQCBolc3NrEH_ie6saolBi0n9aASW67-Rz1IQW-7-Kfti7u696AU-9EMQwHAmX5xElHA8vUwoo3G4SksokJjq43Cau8VWbv1hxKMWhh7PzJyiaVcDHiIG-x0z0kyqAyS-YE-KDKkQS4GgCAkaOua8valHvPwtl5Dx0beXPiXiHM/s16000/Fake%20verification%20page%20with%20ClickFix%20instructions%20from%20the%20SmartApeSG%20campaign%20(Source%20-%20Internet%20Storm%20Center).webp" alt="Fake verification page with ClickFix instructions from the SmartApeSG campaign (Source - Internet Storm Center)" /><figcaption class="wp-element-caption">Fake verification page with ClickFix instructions from the SmartApeSG campaign (Source &#8211; Internet Storm Center)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once the script runs, it silently reaches out to attacker-controlled servers and pulls down the first stage of the infection. The victim sees nothing unusual on their screen, while the attacker gains quiet and persistent access to the machine.</p>



<p class="wp-block-paragraph"><a href="https://isc.sans.edu/diary/Unidentified+RAT+pushes+NetSupport+RAT/33034" id="https://isc.sans.edu/diary/Unidentified+RAT+pushes+NetSupport+RAT/33034" target="_blank" rel="noreferrer noopener nofollow">Internet Storm Center said in a report</a> shared with Cyber Security News (CSN) that they identified the campaign after observing a suspicious infection on May 27, 2026. </p>



<p class="wp-block-paragraph">Researcher Brad Duncan noted that an unidentified RAT had been generating encoded traffic to a command and control server since at least April 2026. </p>



<p class="wp-block-paragraph">The discovery confirmed that this campaign had been quietly running for several weeks before it was formally documented and published.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What sets this attack apart is its deliberate two-stage design. The first stage drops an unidentified RAT that sends encoded traffic to its C2 server over TCP port 443, making it blend in with regular web traffic. </p>



<p class="wp-block-paragraph">Once the initial RAT is in place, it pulls in a second payload: a malicious package of NetSupport Manager RAT, a legitimate remote access tool that attackers have repurposed to take unauthorized control of infected machines.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The entire process is built to stay quiet and survive reboots. After the NetSupport RAT is installed and made persistent on the host, the scripts used to set it up are deleted automatically, removing traces of the initial compromise. </p>



<p class="wp-block-paragraph">This cleanup step makes forensic investigation harder and reveals the careful level of planning behind the campaign.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-smartapesg-campaign-uses-clickfix-scripts" class="wp-block-heading"><strong>SmartApeSG Campaign Uses ClickFix Scripts</strong></h2>



<p class="wp-block-paragraph">The SmartApeSG campaign uses a fake browser verification page as its entry point, a tactic that has grown increasingly popular among threat actors. </p>



<p class="wp-block-paragraph">Visitors are told to run a script to &#8220;verify&#8221; their identity, which instead executes the ClickFix payload. The script then contacts attacker infrastructure to fetch a ZIP archive containing the initial RAT package from a remote server.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8HoF7khTCP2aQ0SWeh0GqbYtj9U8BMBpyYh2YHq9UKnIU5EEEQ2okNILhGUNVDsZEiSHUqTWbMzT9_fLJpHhrgoVwFCm-2cDBBFzND0hq9ROR_CHqmekIQ_x6fLlZ1ktUE6rF6JZR7Uk1JYi3JzRDKW548HxVfaGYcCjsOg4JwYxLxpf0ZOW4yqoqHw4/s16000/Initial%20RAT%20malware%20on%20an%20infected%20Windows%20host%20(Source%20-%20Internet%20Storm%20Center).webp" alt="Initial RAT malware on an infected Windows host (Source - Internet Storm Center)" /><figcaption class="wp-element-caption">Initial RAT malware on an infected Windows host (Source &#8211; Internet Storm Center)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once extracted and executed, the initial RAT begins sending encoded traffic to its C2 server at a fixed IP address over port 443. </p>



<p class="wp-block-paragraph">The use of encoded, non-SSL traffic on that port is unusual and helps the <a href="https://cybersecuritynews.com/macos-malware-leverages-google-ads/" id="149578" target="_blank" rel="noreferrer noopener">malware avoid detection tools that expect standard HTTPS</a> on that port. The RAT then pulls down follow-up files through the same C2 channel to prepare the system for the next stage of the attack.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-netsupport-rat-deployed-as-persistent-follow-up-payload" class="wp-block-heading"><strong>NetSupport RAT Deployed as Persistent Follow-Up Payload</strong></h2>



<p class="wp-block-paragraph">The second stage delivers a malicious NetSupport Manager RAT package via a CAB file that is fetched and extracted to the system. </p>



<p class="wp-block-paragraph">A batch script called <code>token.bat</code> handles the extraction and installation, while a VBScript file called <code>processor.vbs</code> triggers the batch script. Together, these components install the NetSupport RAT and configure it to run automatically whenever the system restarts.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Defenders are advised to monitor for unusual PowerShell execution tied to browser events, as this is a clear sign of the ClickFix technique being abused. Blocking access to suspicious or newly registered domains can also reduce the overall risk. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/security-teams-shrink-as-automation-rises/" id="100650" target="_blank" rel="noreferrer noopener">Security teams should watch for encoded traffic</a> over port 443 that does not follow normal SSL/TLS patterns, as this is a known behavior of the initial RAT in this chain. Since the domains and file hashes used in this campaign rotate daily, checking the @monitorsg feed on Mastodon is recommended for the latest indicators.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/14b73975-c061-42f4-9551-1922868ce458/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEU5GEO7XN&amp;Signature=lU%2FHhBMHq%2BDLO10cGYImLq2zP%2B4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEUaCXVzLWVhc3QtMSJIMEYCIQDBPDnWUoxrvQ2ev0ZFd6tDl6X1ZtoIeP3dH83XGgGOfgIhAIWWxZDAF0WVnKIL37%2BesdhucjjK58%2FKX00TVq334qbfKvMECA4QARoMNjk5NzUzMzA5NzA1Igy6%2FZJ9gjX0iwSjSr0q0AStCYaTlWOvm33LBx%2B4FWGEqke2%2BaHbNveiQo4qiw1HTtjIwXu9lJb3GzdzFmatz9M1hwj2isnpUxNDGWt0%2FJVJwrvMf4Uvm83KMpYxSzqRo2B0ppdm5ZNsWhOS2yJb06NFZSPE0aUCvkwDoxrpsVhLuYNzVKi4AS8P1D0HSwQHbEq1c3PM70GSay2PWuXLicGeI8%2FsZaqpWD%2FIteL%2BOWw4qmEZ9Hlm3KmuQ6lWo5%2BsMy3DPJDih0mzbaLJro6TYJYn8oZY3sMUY9faM36NMAKcLO%2BZ0Vsp%2BlybANx51xaqBJDbxHIn6K45O4AufZpdyIYcnLJek%2FnKeG9e15L3CjXBHyNOt0kaFc%2Fd6lOV9HF1QW%2BtEBGdiFtromvHm5pYusSrQ1RqshpUV5s0WUSIsBVo16sp62lGjiciGjqPP6DEx33Pf6l0ASYz0Rn4Ma7S%2B4cQo%2FF4Uu3snyQeZ8I6IG0xbA4qBFoeYmDaUrjQy4vUu3L6hbR3huIGBkkb6jbl9eEjk8X5Fls3DK15vsQdEL3yotDtlvpm9hd4fVFrHo%2BdvM3UCw16elSYZweYJXpbqivgAxAPW6ZS4FHbj7dOCx2A7ZRnvujsH%2Fk2d%2FRwcBapM10Wb2wuK1sz7mGLUCUAJeIuE8Iwjsj%2Fei18KIECOmbEDyEB3e9ts6m86DRlKfvO9%2FfWYYWMxLZ2ppnTV%2FUtFJRyKrA8yWtMUYrtvF%2Fz6Z%2B%2B7tpPGzq0Lwpqk2m7IzkfC0bmrPw5XfXhI1Gfb4r43XWUMW3HjVqbJO4mYu3yJlWvMIf%2B9dAGOpcB8OO9TcNgRdqDSBB8uELDumWZMUgFOvPSeNwAuLf6JfUFqhPmXPVIBazUqNkMe2x394v9ZQfZwiZhUlH6Xn1ANvP%2BuohcGQAL7yiivfvh5MvZu3WWjHxgAVenablX4c12coapXWao4iPVXCPuKWtHzEqN7BxD%2Buxr8uX6XZn%2FOcaEzt4uEiOTo%2BOb%2BOPwI5NAGVTsEb7ExA%3D%3D&amp;Expires=1780320938" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/secure-util.js</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/private-template?c66kjD5i</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>URL</td><td>hxxps[:]//hiddenplanetlab[.]top/signin/legacy-worker.js?18b3825af007e53d</td><td>SmartApeSG malicious URL observed May 27, 2026</td></tr><tr><td>IP Address</td><td>178.156.165[.]82</td><td>ClickFix script C2 traffic</td></tr><tr><td>IP Address</td><td>178.156.173[.]194</td><td>ClickFix script C2 traffic</td></tr><tr><td>URL</td><td>hxxps[:]//silverharvestnetwork[.]com/check</td><td>ClickFix script C2 traffic; also hosts initial RAT ZIP archive</td></tr><tr><td>IP Address</td><td>89.110.110[.]119:443</td><td>Initial RAT C2 server (TCP port 443, encoded traffic)</td></tr><tr><td>IP Address</td><td>185.163.47[.]217:443</td><td>NetSupport RAT C2 server</td></tr><tr><td>SHA256</td><td>1514b1268e9dc6d2f37137aa38c756cb4bf8186ac9235d6863b78e7f8bbbe976</td><td>ZIP archive containing initial RAT software package</td></tr><tr><td>SHA256</td><td>469bac8e10f50263e8ff0806e6ba126bb4cc660799129a8653eab3f8ec7201e5</td><td>processor.vbs — initial VBScript that runs token.bat</td></tr><tr><td>SHA256</td><td>9c7eda2c4d3aaa8746495741bef57a07de180f0409409faf0f91658e88ba33f5</td><td>token.bat — batch script that installs and persists NetSupport RAT</td></tr><tr><td>SHA256</td><td>7ba5481c873bb3081442561f749f590badd72ef249fddfe993e30b28dc0c2112</td><td>setup.cab — CAB file containing malicious NetSupport RAT package</td></tr><tr><td>File Path</td><td>C:\ProgramData\processor.vbs</td><td>Initial VBScript dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\token.bat</td><td>Batch script dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\setup.cab</td><td>CAB archive dropped on infected host</td></tr><tr><td>File Path</td><td>C:\ProgramData\UpdateInstaller\</td><td>Extraction directory for NetSupport RAT contents</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/smartapesg-campaign-uses-clickfix-scripts/">SmartApeSG Campaign Uses ClickFix Scripts to Infect Windows Hosts With RAT Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/SmartApeSG-Campaign-Uses-ClickFix-Scripts-to-Infect-Windows-Hosts-With-RAT-Malware.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151509</post-id>	</item>
		<item>
		<title>Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</title>
		<link>https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 14:34:58 +0000</pubDate>
				<category><![CDATA[Cyber Attack News]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151518</guid>

					<description><![CDATA[<p>A significant supply chain attack on June 1, 2026, targeting over 30 official packages under the @redhat-cloud-services npm scope. The campaign, dubbed &#8220;Miasma: The Spreading Blight,&#8221; is a new variant of the Mini Shai-Hulud malware family a sophisticated credential-stealing worm previously linked to threat actor group TeamPCP. This is not a typosquatting campaign. The attackers [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/">Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A significant supply chain attack on June 1, 2026, targeting over 30 official packages under the @redhat-cloud-services npm scope.</p>



<p class="wp-block-paragraph">The campaign, dubbed &#8220;Miasma: The Spreading Blight,&#8221; is a new variant of the <a href="https://cybersecuritynews.com/hackers-compromise-antv-packages/" target="_blank" rel="noreferrer noopener">Mini Shai-Hulud malware family</a>  a sophisticated credential-stealing worm previously linked to threat actor group TeamPCP.</p>



<p class="wp-block-paragraph">This is not a typosquatting campaign. The attackers hijacked a legitimate, trusted npm namespace and published backdoored versions of widely-used frontend components, API clients, and developer tooling.</p>



<p class="wp-block-paragraph">According to <a href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" target="_blank" rel="noreferrer noopener nofollow">Aikido</a> and <a href="https://research.jfrog.com/post/shai-hulud-miasma-redhat-cloud-services/" target="_blank" rel="noreferrer noopener nofollow">JFrog</a> detections, the malicious packages were published via GitHub Actions OIDC tokens, indicating the CI/CD pipeline itself was compromised, not individual developer accounts.</p>



<p class="wp-block-paragraph">Each poisoned package embeds a preinstall lifecycle hook in its <code>package.json</code>:</p>



<pre class="wp-block-preformatted">json<code>"scripts": { "preinstall": "node index.js" }</code></pre>



<p class="wp-block-paragraph">This executes a 4.2 MB obfuscated payload automatically during every <code>npm install</code>, before any application code runs. The loader uses a multi-stage decryption chain — numeric character arrays, a ROT-style transform, and AES-128-GCM blobs — to evade static detection, before dropping a transient Bun-based payload to <code>/tmp/p*.js</code> for execution.</p>



<p class="wp-block-paragraph">Once active, the malware performs a sweeping credential collection targeting:</p>



<ul class="wp-block-list">
<li><strong>GitHub tokens</strong> — classic, fine-grained, and GitHub Actions OIDC tokens</li>



<li><strong>Cloud credentials</strong> — AWS access keys, GCP service account files, Azure service principal and managed identity tokens</li>



<li><strong>Infrastructure secrets</strong> — Kubernetes service account tokens and kubeconfig files, HashiCorp Vault tokens</li>



<li><strong>Developer tooling</strong> — npm and PyPI publish tokens, SSH private keys, Docker registry credentials, GPG keys, <code>.env</code> files across the filesystem</li>
</ul>



<p class="wp-block-paragraph">In cloud environments, the malware goes beyond static files. It actively queries <a href="https://cybersecuritynews.com/typosquatted-npm-packages-steal-cloud-and-ci-cd-secrets/" target="_blank" rel="noreferrer noopener">AWS Secrets Manager</a>, SSM Parameter Store, Azure Key Vault, and GCP Secret Manager when permissions allow. GitHub Actions runners are a prime target: the payload reads secrets directly from runtime process memory, bypassing workflow log masking entirely.</p>



<p class="wp-block-paragraph">A notable evasion technique in this wave involves disguising exfiltration traffic to <code>api.anthropic.com/v1/api</code> — a legitimate-looking domain that blends into network logs at organizations using Anthropic services.</p>



<p class="wp-block-paragraph">The <code>/v1/api</code> path is not a valid Anthropic route, suggesting attackers chose it purely for camouflage. Defenders should hunt for node or Bun processes contacting this host from CI runners or developer machines.</p>



<p class="wp-block-paragraph">The malware also uses a GitHub dead-drop model, creating public repositories under victim accounts with the description <code>Miasma: The Spreading Blight</code> and committing stolen credentials as JSON result files.</p>



<p class="wp-block-paragraph">The malware installs persistent monitoring services — <code>kitty-monitor.service</code> on Linux and <code>com.user.kitty-monitor.plist</code> on macOS — that poll for remote instructions. It also injects hooks into AI developer tools including Claude, Codex, Gemini, Copilot, Kiro, and opencode, and adds VS Code folder-open tasks that re-execute the payload.</p>



<p class="wp-block-paragraph">Most critically, a destructive token monitor (<code>gh-token-monitor</code>) watches stolen GitHub tokens. If a token is revoked before persistence is removed, it can execute destructive commands such as wiping the user&#8217;s home directory.</p>



<p class="wp-block-paragraph">Incident responders must isolate machines and remove persistence before revoking any tokens.</p>



<h2 id="h-indicators-of-compromise" class="wp-block-heading"><strong>Indicators of Compromise</strong></h2>



<p class="wp-block-paragraph">Any project that installed the following package versions on or after June 1, 2026 should be treated as compromised: Here is the complete IOC table for all 31 compromised <code>@redhat-cloud-services</code> npm packages:</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>#</th><th>Package Name</th><th>Malicious Version</th></tr></thead><tbody><tr><td>1</td><td>@redhat-cloud-services/chrome</td><td>2.3.1</td></tr><tr><td>2</td><td>@redhat-cloud-services/compliance-client</td><td>4.0.3</td></tr><tr><td>3</td><td>@redhat-cloud-services/config-manager-client</td><td>5.0.4</td></tr><tr><td>4</td><td>@redhat-cloud-services/entitlements-client</td><td>4.0.11</td></tr><tr><td>5</td><td>@redhat-cloud-services/eslint-config-redhat-cloud-services</td><td>3.2.1</td></tr><tr><td>6</td><td>@redhat-cloud-services/frontend-components</td><td>7.7.2</td></tr><tr><td>7</td><td>@redhat-cloud-services/frontend-components-advisor-components</td><td>3.8.2</td></tr><tr><td>8</td><td>@redhat-cloud-services/frontend-components-config</td><td>6.11.3</td></tr><tr><td>9</td><td>@redhat-cloud-services/frontend-components-config-utilities</td><td>4.11.2</td></tr><tr><td>10</td><td>@redhat-cloud-services/frontend-components-notifications</td><td>6.9.2</td></tr><tr><td>11</td><td>@redhat-cloud-services/frontend-components-remediations</td><td>4.9.2</td></tr><tr><td>12</td><td>@redhat-cloud-services/frontend-components-testing</td><td>1.2.1</td></tr><tr><td>13</td><td>@redhat-cloud-services/frontend-components-translations</td><td>4.4.1</td></tr><tr><td>14</td><td>@redhat-cloud-services/frontend-components-utilities</td><td>7.4.1</td></tr><tr><td>15</td><td>@redhat-cloud-services/hcc-feo-mcp</td><td>0.3.1</td></tr><tr><td>16</td><td>@redhat-cloud-services/hcc-kessel-mcp</td><td>0.3.1</td></tr><tr><td>17</td><td>@redhat-cloud-services/hcc-pf-mcp</td><td>0.6.1</td></tr><tr><td>18</td><td>@redhat-cloud-services/host-inventory-client</td><td>5.0.3</td></tr><tr><td>19</td><td>@redhat-cloud-services/insights-client</td><td>4.0.4</td></tr><tr><td>20</td><td>@redhat-cloud-services/integrations-client</td><td>6.0.4</td></tr><tr><td>21</td><td>@redhat-cloud-services/javascript-clients-shared</td><td>2.0.8</td></tr><tr><td>22</td><td>@redhat-cloud-services/notifications-client</td><td>6.1.4</td></tr><tr><td>23</td><td>@redhat-cloud-services/patch-client</td><td>4.0.4</td></tr><tr><td>24</td><td>@redhat-cloud-services/quickstarts-client</td><td>4.0.11</td></tr><tr><td>25</td><td>@redhat-cloud-services/rbac-client</td><td>9.0.3</td></tr><tr><td>26</td><td>@redhat-cloud-services/remediations-client</td><td>4.0.4</td></tr><tr><td>27</td><td>@redhat-cloud-services/rule-components</td><td>4.7.2</td></tr><tr><td>28</td><td>@redhat-cloud-services/sources-client</td><td>3.0.10</td></tr><tr><td>29</td><td>@redhat-cloud-services/tsc-transform-imports</td><td>1.2.2</td></tr><tr><td>30</td><td>@redhat-cloud-services/types</td><td>3.6.1</td></tr><tr><td>31</td><td>@redhat-cloud-services/vulnerabilities-client</td><td>2.1.8</td></tr></tbody></table><figcaption class="wp-element-caption">If any of these package versions were installed in your environment on or after June 1, 2026, immediately treat all GitHub tokens, npm tokens, cloud credentials (AWS, GCP, Azure), Kubernetes service account tokens, SSH keys, and CI/CD secrets as compromised. Isolate affected machines before revoking any tokens to avoid triggering the Miasma dead-man switch.</figcaption></figure>



<h2 id="h-mitigation-steps" class="wp-block-heading"><strong>Mitigation Steps</strong></h2>



<ul class="wp-block-list">
<li>Run <code>npm uninstall</code> on all affected packages and regenerate lockfiles from trusted metadata</li>



<li>Use <code>npm ci --ignore-scripts</code> in CI pipelines as a temporary safeguard</li>



<li>Remove <code>kitty-monitor</code> and <code>gh-token-monitor</code> persistence files from all affected machines before revoking tokens</li>



<li>Inspect <code>.claude/settings.json</code>, <code>.vscode/tasks.json</code>, and <code>~/.config/index.js</code> for injected hooks</li>



<li>Audit npm and GitHub accounts for unexpected patch-version publishes or newly created repositories matching the <code>Miasma: The Spreading Blight</code> description</li>



<li>Rotate <strong>all</strong> exposed credentials — GitHub tokens, npm tokens, cloud keys, SSH keys, Vault tokens, and Kubernetes service account tokens — only after persistence is confirmed removed</li>



<li>Rebuild affected CI runners and developer workstations from clean images</li>
</ul>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/">Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Red-Hat-Cloud-Services-npm-Packages.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151518</post-id>	</item>
		<item>
		<title>Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</title>
		<link>https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 12:40:00 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151486</guid>

					<description><![CDATA[<p>Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/">Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. </p>



<p class="wp-block-paragraph">The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat group operating under several known aliases. </p>



<p class="wp-block-paragraph">Security researchers have been tracking a rapid surge in activity that shows no signs of stopping. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a>The threat group, known as Screening Serpens and also identified as UNC1549, Smoke Sandstorm, and Iranian Dream Job, has been active since at least 2022. </p>



<p class="wp-block-paragraph">Historically focused on Middle Eastern targets, the group expanded into Western Europe in late 2025. Their preferred targets sit inside high-value sectors including aerospace, defense manufacturing, and telecommunications. </p>



<p class="wp-block-paragraph">They reach victims through personalized social engineering, using fake job listings and spoofed meeting invitations to lure professionals into downloading malicious files.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Unit 42 researchers identified six new remote access Trojan (RAT) variants deployed between February and April 2026, grouped into two distinct malware families named MiniUpdate and MiniJunk V2. </p>



<p class="wp-block-paragraph"><a href="https://unit42.paloaltonetworks.com/screening-serpens-iran-nexus-apt-new-rat-variants/" id="https://unit42.paloaltonetworks.com/screening-serpens-iran-nexus-apt-new-rat-variants/" target="_blank" rel="noreferrer noopener nofollow">Unit 42 said in a report</a> shared with Cyber Security News (CSN) that the campaigns align closely with the conflict timeline, with coordinated attacks hitting entities in the U.S. and Israel in late March, followed by targets in the UAE and another Middle Eastern country in mid-April 2026.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Both <a href="https://cybersecuritynews.com/21-new-malware-families-mac-attack/" id="58089" target="_blank" rel="noreferrer noopener">malware families begin their infection chains through spear phishing</a>. Victims receive what appears to be a recruitment portal or a video conferencing app installer. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3MmeJv87D0iDibUFyZ51q7fXQppDakIPL8W0I6ySc4ne-Thg9FrW1Tp17qtqaOwR9lkVqb6Da_XmUHu6hBBMJAevwn2M1-ciyLZ5Am9EmynqNBS73GXDghJIh4R-yWulOIKnxzYLPYLm_9Rxam43HdVibWU8ueEk2y534eI4rq3Ygrup3UOaxpidzaYg/s16000/Contents%20of%20the%20archive%20(Source%20-%20Unit42).webp" alt="Contents of the archive (Source - Unit42)" /><figcaption class="wp-element-caption">Contents of the archive (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once they interact with the file, a silent multi-stage infection chain kicks off in the background, and the attacker quietly gains full control over the compromised machine.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-appdomainmanager-hijacking" class="wp-block-heading"><strong>AppDomainManager Hijacking</strong></h2>



<p class="wp-block-paragraph">The most significant technical leap in this campaign is the use of a technique called AppDomainManager hijacking. </p>



<p class="wp-block-paragraph">This method targets the initialization phase of .NET applications by modifying a legitimate configuration file, allowing malicious code to run before the host application even finishes loading. Since this happens so early, most security tools do not get a chance to detect it.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">By adding a few targeted XML lines to the application&#8217;s config file, attackers instruct the .NET runtime to disable its own security features. </p>



<p class="wp-block-paragraph">They turn off Event Tracing for Windows (ETW), the primary data source that modern endpoint detection and response (EDR) platforms rely on to monitor .NET activity. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtm0Rlqde_5botNHVggG36gy5kfLup-qFTCzxcvVm8fXjS69J3q4nM-N1lsEQdDvtaelxJydqYYVTZD3Tfr0k14tJDIXeT1tNLe91kRLXkk3IRLpU0iH-0Raid3Ue4qQhIUA4cbPRQHQGDKhyphenhyphenFrvxcTou3bxAzNkmh9zSXNwJ4UI0NrJgilUXqu5NLO8Y/s16000/A%20fake%20job%20description%20document,%20designed%20by%20the%20attacker%20to%20impersonate%20a%20global%20air%20carrier%20company%20(Source%20-%20Unit42).webp" alt="A fake job description document, designed by the attacker to impersonate a global air carrier company (Source - Unit42)" /><figcaption class="wp-element-caption">A fake job description document, designed by the attacker to impersonate a global air carrier company (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">They also bypass strong-name signature validation, ensuring that unsigned DLL files load without triggering security exceptions.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">This approach is described as a mature living-off-the-land technique because it requires no complex shellcode or memory patching. </p>



<p class="wp-block-paragraph">The attacker simply asks the system to turn off its own defenses using a file that looks entirely legitimate. The result is a payload running in a completely unmonitored, highly privileged environment with no alerts raised.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-infection-chain-and-social-engineering-tactics" class="wp-block-heading"><strong>Infection Chain and Social Engineering Tactics</strong></h2>



<p class="wp-block-paragraph">The MiniUpdate family was delivered through archives impersonating a global airline and a popular video conferencing platform. </p>



<p class="wp-block-paragraph">One archive contained six fake job description PDFs with believable job IDs and titles such as Senior Software Engineer, targeting IT and engineering professionals. </p>



<p class="wp-block-paragraph">A nested payload inside a file named Hiring <a href="https://cybersecuritynews.com/beware-of-fake-error-pages-that-linux-and-windows-systems/" id="117688" target="_blank" rel="noreferrer noopener">Portal.zip launched a fake error window</a> while the malware quietly installed itself.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU06lzihhv0GoeQ7NdAbLsJYsQ-RHnGDNnvG1_eLgI0k9JreE3RvJPu-IkWx3Z9Gm0JhUm4VByVNr4NuvI2hdT4LRYCsx4-t_6pWSdyleD3WUfcskKCbOQpB_b-5sp5oh-Au4VFkkrkgr-p52KtzUejCilEuH3pTEekNu7C3pXjvO14M0bjQj-6o7LVKE/s16000/Task%20Scheduler%20window%20showing%20the%20associated%20scheduled%20task%20(Source%20-%20Unit42).webp" alt="Task Scheduler window showing the associated scheduled task (Source - Unit42)" /><figcaption class="wp-element-caption">Task Scheduler window showing the associated scheduled task (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">For persistence, the malware used Windows Task Scheduler, creating a daily trigger at 09:30 local time. The MiniJunk V2 family used an older configuration method but added heavy code obfuscation and file size inflation to bypass automated scanning limits. </p>



<p class="wp-block-paragraph">Command-and-control traffic was routed through Azure-hosted domains that mimicked legitimate Windows service names, making network-level detection significantly harder.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Researchers recommend that defenders tune EDR platforms specifically to flag DLL sideloading and AppDomainManager hijacking behaviors, rather than relying solely on signature-based detection. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZP-Bih6fKjCGYjIwFlrPrJpOh3AvlKABPEzCqucnXARuf_LdGrOLUnn_cFDixejgCtkn2jEcms96QrFNzhUajHRbeGHQeF2IDJy98NVdi9RxTV3sP3lUsvS0IIOINANj-tbQyaTWHFFH9tvSLAsQ2VcK7oeA5wJPSiK-tQ297F52m1WW_tzGOyTCIThQ/s16000/MiniUpdate%20malware%20flow%20(Source%20-%20Unit42).webp" alt="MiniUpdate malware flow (Source - Unit42)" /><figcaption class="wp-element-caption">MiniUpdate malware flow (Source &#8211; Unit42)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Treating trusted, signed binaries that load unsigned modules as high-risk will help security teams catch these attacks much earlier. Organizations in aerospace, defense, and<a href="https://cybersecuritynews.com/north-korean-it-workers-mimic-as-us-organizations-for-job-offers/" id="84332" target="_blank" rel="noreferrer noopener"> technology should stay alert to fake job offers or meeting invitations</a> arriving through unofficial channels.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e868a215-4734-4916-b68d-a5b663703631/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.pdf?AWSAccessKeyId=ASIA2F3EMEYE22OPSLHT&amp;Signature=sFNBbK3T7Oeq3LuSwIR%2BK7oZ9Vs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEMaCXVzLWVhc3QtMSJGMEQCIDBC%2BDXHKOHmvpaxLskewWFhLoX%2Fitnc8kqQ1EdgK46LAiAQDflWNBZt67OP8zvjvWCBSPT32cbA%2FXvtTz2bYB7THyrzBAgLEAEaDDY5OTc1MzMwOTcwNSIMCoJ0bGUjZsneqUs3KtAExBIjvLKEfXyng%2Ff4qJH89Q%2B9rXhWqB5yD4%2F%2Bo%2BE4Mz8ib%2F9iEDDMVOQevlq2d%2B6EP%2F2XOhDhnRWHS0P2gd%2FmgmyjxbNCN5SEfn2wbQk8YLXFhiCJzZtvSuUYHixRyIDIfd90IIGAK5tbGniaf%2F7FmSHttbN4BvGc8LQg33MKx2WSfYxfIhfNJTbAc1w44E6uDfiGyhjjuwlux1GW%2F8zMDS%2BSyVLBN0Ygpky009dcek2SZIsCOSB92hzh6W0z07kKtoAhtftaj0uG3Eb2Aa6hGw2I8o%2BoBi7IgBTxbG5eZ5QwMzT9JC5CcxJBzelsMnBvw5ZnF95atuwdz9BK6es48%2BAA%2B7fh8a%2BcMFm2fNOhyi%2BT9hNOO8Fdf38nvoMtodG6zAmLsNjOfD9HaVxEMLrDouh23RD4a%2Bz%2Fm00V57JGcG6ZlF3IC17i2cdrw5%2B9etQ2FJ1n54S2n11UEpMYnYYJKXXj3ulgQ%2FyjK2e43RdZq460vTYhLM5Xyitl%2BpUXxdwbYyB%2FweCBbedLjb0F1A2PPwWbkjsFj2%2FhCnvWzjhvCAFatv0MKv1OhpNi%2FtCAQhHRDF4979eH6FEb2mIoGXADo0fhGeWYyPjM3ZOyhDrd4L0uP%2FMKsQNBPj64ZiHw%2Bf32z3oVmEpffzprdVLGsSwqEQbTdU7xI%2FhRNLIA3YKw3V%2FAVUVRSJjdX%2FC7estIxBx0N%2BH3nvId%2BHGItm%2BQC%2BkmACYVmAAOKbQWLrm4sXDG6tx1z%2FSB7i4MPdmoh80UhLGLuwUDylN9Eax9tgnqDpPVJTC%2BuPXQBjqZAaBCTSxGpLn%2FnAoFxc4sa27hPyQxu49uX6lgxZDU24Ps3sfDen%2Bq3axgPNYREk9AxVp2RiauM6GP6lYrzw2l7gGSJ9PJ19e4EcajxNPTbJbGyRUZ%2Fb4zs0bq%2FWx7a104w4OkhBKN%2FCFa%2Flnq27vRNoHe2dZXlfvUuyLWcQ8e%2BYTbwbcuGBAw3S4m8LnxZURPD9SJS6XAlwiKUA%3D%3D&amp;Expires=1780309930" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Domain</td><td><code>licencemanagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>LicenceSupporting.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>PeerDistSvcManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>ThemesManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>ThemesProviderManagers.azurewebsites[.]net</code></td><td>MiniJunk V2 C2 domain</td></tr><tr><td>Domain</td><td><code>NanoMatrix.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>QuantumWeave.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>ElementShift.azurewebsites[.]net</code></td><td>MiniJunk V2 U.S. Campaign C2</td></tr><tr><td>Domain</td><td><code>buisness-centeral.azurewebsites[.]net</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>buisness-centeral-transportation.azurewebsites[.]net</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>Buisness-centeral-transportation[.]com</code></td><td>MiniUpdate C2 domain</td></tr><tr><td>Domain</td><td><code>PremierHealthAdvisory[.]com</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>PremierHealthAdvisory.azurewebsites[.]net</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>Premier-HealthAdvisory.azurewebsites[.]net</code></td><td>MiniUpdate UAE Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltonsfinance[.]com</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltonsfinance.azurewebsites[.]net</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>Ramiltons-finance.azurewebsites[.]net</code></td><td>MiniUpdate Middle East Campaign C2</td></tr><tr><td>Domain</td><td><code>business-startup[.]org</code></td><td>Associated C2 infrastructure</td></tr><tr><td>Domain</td><td><code>business-startup.azurewebsites[.]net</code></td><td>Associated C2 infrastructure</td></tr><tr><td>Domain</td><td><code>docspace-y4cumb.onlyoffice[.]com</code></td><td>ONLYOFFICE payload delivery</td></tr><tr><td>Domain</td><td><code>docspace-twpf0e.onlyoffice[.]com</code></td><td>ONLYOFFICE payload delivery</td></tr><tr><td>URL</td><td><code>hxxps[:]//docspace-y4cumb.onlyoffice[.]com/storage/files/root/folder_3602000/file_3601577/v1/content.zip</code></td><td>MiniJunk V2 payload URL</td></tr><tr><td>URL</td><td><code>hxxps[:]//docspace-twpf0e.onlyoffice[.]com/storage/files/root/.../content.zip</code></td><td>MiniJunk V2 U.S. Campaign payload URL</td></tr><tr><td>URL</td><td><code>hxxps[:]//2117.filemail[.]com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm</code></td><td>MiniUpdate Israel payload URL</td></tr><tr><td>SHA256</td><td><code>44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250</code></td><td>MiniUpdate U.S. Campaign — Initial archive</td></tr><tr><td>SHA256</td><td><code>332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17</code></td><td>MiniUpdate U.S. Campaign — Hiring Portal.zip</td></tr><tr><td>SHA256</td><td><code>0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864</code></td><td>MiniUpdate U.S. Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d</code></td><td>MiniUpdate Israel Campaign — Initial archive</td></tr><tr><td>SHA256</td><td><code>d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2</code></td><td>MiniUpdate Israel Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad</code></td><td>MiniUpdate UAE/Middle East Campaign — UpdateChecker.dll</td></tr><tr><td>SHA256</td><td><code>74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27</code></td><td>MiniUpdate Middle East Campaign</td></tr><tr><td>SHA256</td><td><code>9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84</code></td><td>MiniJunk V2 Middle East — uevmonitor.dll</td></tr><tr><td>SHA256</td><td><code>B19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4</code></td><td>MiniJunk V2 Middle East — unbcl.dll</td></tr><tr><td>SHA256</td><td><code>8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b</code></td><td>MiniJunk V2 U.S. — Portable Platform.zip</td></tr><tr><td>SHA256</td><td><code>43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa</code></td><td>MiniJunk V2 U.S. — Connection.dll</td></tr><tr><td>SHA256</td><td><code>9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1</code></td><td>MiniJunk V2 U.S. — unbcl.dll</td></tr><tr><td>File Name</td><td><code>UpdateChecker.dll</code></td><td>MiniUpdate core RAT payload</td></tr><tr><td>File Name</td><td><code>uevmonitor.dll</code></td><td>MiniJunk V2 primary loader</td></tr><tr><td>File Name</td><td><code>Connection.dll</code></td><td>MiniJunk V2 U.S. Campaign RAT payload</td></tr><tr><td>File Name</td><td><code>unbcl.dll</code></td><td>Social engineering decoy DLL</td></tr><tr><td>File Name</td><td><code>Hiring Portal.zip</code></td><td>Malicious archive delivery file</td></tr><tr><td>File Name</td><td><code>Portable platform.zip</code></td><td>MiniJunk V2 U.S. Campaign delivery archive</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/iranian-hackers-abuse-appdomainmanager-hijacking/">Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Iranian-Hackers-Abuse-AppDomainManager-Hijacking-to-Evade-EDR-Detection.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151486</post-id>	</item>
		<item>
		<title>SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</title>
		<link>https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 12:27:32 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151485</guid>

					<description><![CDATA[<p>A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan&#8217;s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 Afghan Mustoufiats — regional revenue and finance directorates that form the fiscal backbone of the country. The attack [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/">SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan&#8217;s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. </p>



<p class="wp-block-paragraph">The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 Afghan Mustoufiats — regional revenue and finance directorates that form the fiscal backbone of the country.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attack began with a spear phishing email carrying a ZIP archive. Inside was a malicious shortcut file disguised with a PDF icon and a filename written in Pashto — the dominant language used by Afghan government workers. </p>



<p class="wp-block-paragraph">The lure posed as a list of employees invited to a seminar on psychological and intellectual warfare, showing that the attackers had precise knowledge of their targets&#8217; working environment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Analysts from Seqrite, in a <a href="https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/" target="_blank" rel="noreferrer noopener">report shared with Cyber Security News</a>, identified this campaign and attributed it to the SideCopy APT cluster with medium-to-high confidence. </p>



<p class="wp-block-paragraph">SideCopy operates under the broader Transparent Tribe, also known as APT36, umbrella — a group with a documented history of targeting South Asian government institutions. </p>



<p class="wp-block-paragraph">Seqrite Labs has been tracking this threat cluster for years as part of its global spear phishing monitoring program.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once the victim opened the shortcut file, the malware silently used mshta.exe — a legitimate Windows utility — to reach out to a compromised Afghan education domain and pull a remote payload. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/iranian-hackers-attack-telecom-companies-using-custom-tools-and-living-off-the-land-techniques/" id="53130" target="_blank" rel="noreferrer noopener">This technique is called Living-off-the-Land</a>, where attackers abuse built-in system tools to avoid triggering security alerts. The malware then decoded obfuscated JavaScript in memory and embedded itself in the Windows Registry, disguising its persistence entry as a Microsoft Edge process.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUhfUw__bbbIfKdpxBEJCESriaI2JgWyrXrfrF7jz9ZY0h8sqEyATN5KajThxFhmipQRJTF4EtHIzsozRYKEIw52EvadgdFnonUfFKi34rDK6jS0gNDYByRUP0k9RgEpAWjt-ckhP7Eq2lhuqenrkXGHgGEHhEmYNlhC9Wn11VplEP4aVVYXvTHyBad_c/s16000/Infection%20Chain%20(Source%20-%20Seqrite).webp" alt="Infection Chain (Source - Seqrite)" /><figcaption class="wp-element-caption">Infection Chain (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The final stage deployed XenoRAT 1.8.7, an open-source Remote Access Trojan available on GitHub, which established an encrypted connection to a bulletproof server in Frankfurt, Germany. </p>



<p class="wp-block-paragraph">This command-and-control infrastructure was entirely separate from the delivery domain — a deliberate design to ensure long-term access even if the delivery layer was discovered and shut down.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-sidecopy-hackers-deploy-persistent-xenorat-malware" class="wp-block-heading"><strong>SideCopy Hackers Deploy Persistent XenoRAT Malware</strong></h2>



<p class="wp-block-paragraph">The malware chain ran across five stages, each built to pass control to the next without triggering detection. After the shortcut file launched mshta.exe, it pulled an HTML Application payload from abimj.edu.af, a compromised Afghan education website. </p>



<p class="wp-block-paragraph">That payload contained obfuscated JavaScript which decoded itself in memory and dropped a .NET-based loader DLL to continue the infection.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9YXmAESYqqUjPIl9R88B51E9eP0TJB-Pbee2g3y9ks08_pE_EeZmncxpg-RBY89UBUN0EXjMnVxBS7LHUh3OZTMZaD7x1Ys8Rxag-kzJOKAs7hdZX9ExSd7Sg17DMMVhZLVmO_WYSAjXa5ZoLlSlLMABB2HM04UFF7LgQWStnRbn1329hhkJfXWbOoI4/s16000/A%20legitimate%20Microsoft%20binary%20(Source%20-%20Seqrite).webp" alt="A legitimate Microsoft binary (Source - Seqrite)" /><figcaption class="wp-element-caption">A legitimate Microsoft binary (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">That loader DLL downloaded an encoded, GZIP-compressed blob from attacker-controlled URLs and unpacked it entirely in memory. </p>



<p class="wp-block-paragraph">The shellcode that followed used reflective loading — allocating executable memory and injecting itself without writing the main payload to disk. This fileless approach makes the malware far harder to <a href="https://cybersecuritynews.com/the-role-of-antivirus-software-in-keeping-your-computer-safe/" id="91581" target="_blank" rel="noreferrer noopener">catch with conventional antivirus scanning</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">XenoRAT is a capable surveillance tool once active. It connects to a hard-coded IP address using encrypted TCP traffic and registers itself through both a Windows Scheduled Task named &#8220;XenoUpdateManager&#8221; and a Registry Run key. </p>



<p class="wp-block-paragraph">The malware runs a mutex called &#8220;clouda&#8221; to prevent duplicate instances, and it queries installed antivirus products before reporting back to its operators.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-persistence-mechanisms-and-infrastructure-exposure" class="wp-block-heading"><strong>Persistence Mechanisms and Infrastructure Exposure</strong></h2>



<p class="wp-block-paragraph">The decoy document dropped during execution was a real Afghan Ministry of Finance internal staff directory, listing Finance Directors, Revenue Chiefs, and Secretaries from all 34 provinces — complete with mobile numbers. </p>



<p class="wp-block-paragraph">This level of detail indicates the attackers conducted prior intelligence gathering, likely through earlier compromises of Afghan government networks.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The delivery domain abimj.edu.af resolved to IPs 103.132.98.224 and 103.132.98.226, both on a subnet belonging to Afghanistan&#8217;s own Ministry of Communication. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkWQUuutKQJ8-baB_BPTp65xYi1xm1iZ6wlPRJfFgMZlxBZMpZ5jjwlAuOEyIbMkH-g3JYAlKNoq_dSqF7M4r-_cQ1-SduKATM_jmSYyaTKAEwh96RV51SrdCOmK8WTBvCxA_x4E3eqCC0MYj7LiqAhp0ZHdR2o8TiGrNz5QwTl1mbqlT2O1jEmTxsYic/s16000/Shellcode%20Execution%20(Source%20-%20Seqrite).webp" alt="Shellcode Execution (Source - Seqrite)" /><figcaption class="wp-element-caption">Shellcode Execution (Source &#8211; Seqrite)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Staging malicious payloads on local Afghan infrastructure allowed traffic to blend with legitimate government communications, <a href="https://cybersecuritynews.com/network-monitoring-tools/" id="20062" target="_blank" rel="noreferrer noopener">bypassing network monitoring tools</a>. </p>



<p class="wp-block-paragraph">The RAT&#8217;s C2 server at 185.235.137.106 was hosted on AS59711, a Bulgaria-registered provider with Frankfurt data center presence previously linked to SideCopy activity.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Security teams should monitor for unusual mshta.exe executions, unexpected Registry Run keys mimicking Windows processes, and outbound traffic to unrecognized European hosting providers. </p>



<p class="wp-block-paragraph">Enforcing application allow-listing, auditing scheduled tasks regularly, and restricting HTA execution from public directories are effective mitigations. Seqrite released detections under signatures including Link.Downloader.50744.GC and Script.Netloader.50745.GC to help identify compromised systems.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dcfb058f-2246-4f2d-8225-b3ab7a32c8bd/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.pdf?AWSAccessKeyId=ASIA2F3EMEYE6NOQVOG3&amp;Signature=%2B3xlhM1krTM1zHQ%2BoLiUj1deNZY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEIaCXVzLWVhc3QtMSJIMEYCIQCucW5r81%2BwGe2WAKjrsZkQ3cKCoYbH8lBWxdn88KqmQQIhAJrfaB3O7%2FPIqqvrF44wvhKSKzx9y1elFOlYHnn6o0OeKvMECAsQARoMNjk5NzUzMzA5NzA1IgxpKs%2FrrG8DT2AS1gwq0AS8wjW0SIgi6cvRozOwyyegzVE0h%2BDK6T9dxS1SLllTj70b89qOGQW2Vy7EbQq9EosThlhCNUYzoqxUQb%2Fhdg3w8m4VgTJAZvm%2B8tVH12yvIoNjgcN77B3XKuyRPa1CwWRO1S8DwhOLBeeev%2FQsuXFCJn32M4cf0qTIJ1A4OdcAXEk%2Ffiykc41K0O6DFEukKYyelQ3vo8wqNNinrxoWMWh5XC1vcSLfVciPkKY%2BGjus39QeL92sdFVWDZq0kp4Fgd1xAx1KFKg1s8Y6Ee7xpKmbit78ib2%2BYd0VYkdcT9TNpCujx94BMzDv6Tb4pDVfD0BIXnrnFjsesnV%2B3llWHVyUo51rxkeFr4aYTNKEPIfY4euzT4IP4GvhPu%2Box80Iwx9VLAqcw6Fy0%2BS05fFF7oVflMbLkjBegINJbaHzdtv5Vg%2B%2Bs26Fis1lHtJC8jTMBYs4yoUtHp9pMiHAlv2rA1px8SXyUe2zelJIZAMyGLyb%2FK5tK3chpZ3VQHR8Xssmf%2Bv7QhYLm6Ki35jbSltLuiSXZ20yg4WK7qoDQGT37%2BPd9VUvvmcU4t6TDcaIwsz5SaeTZy5IawsZspEO5%2F7ZUq36cYAbLWZsSzGNLpdSfyWaAkd32dSM8C%2BzMdRwHjaMQxO83KMjfIIZHf6BXFQ3LJWE8hv4%2FF9MCc%2BB%2Fww3StknrFPf%2FeOw3Dj%2FUsw%2BsUqwg3eVh9JxYtP2rK1eUHYhs5HeQzJ5q%2F6RkZfkAedSCEhKoFjeMe3X1lFj9FFWM4VPU5poTeyk1Y0UJdxQtA2eyModMLCo9dAGOpcBvNY97O4VQ8P6IVvLDirultyvvJ9CJQbyYJbaJwa6zIy4keQf4B6fGZGS2ZKt6mSzVO5ADBIzhN7lFfq0nqhIBRS6JvYPxS8PMOiRjCrCg0PurEByHFOfXfEGVbNL%2B87chB%2BON8o0AXrJqo%2Bx06YEhgqDfh5%2FAuS3k6pHlv4wkNntnes2amGDwNg8YxSQdGmpr5O2qf6dWQ%3D%3D&amp;Expires=1780309854" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>SHA256</td><td>194B912C242604D6F9A79369F22338C58A13CE0CC2ED280CE505075808BC2F14</td><td>ZIP archive (initial delivery)</td></tr><tr><td>SHA256</td><td>3B4194BDFE40D94031A94B30397FFD8A4B09D0A4057668E897B8BDCD1703DD01</td><td>Malicious LNK file</td></tr><tr><td>SHA256</td><td>DF9173A28C0B0B878C10A53D35CD7CE6F6ED66D207B6B7C4FF723721F1C027AB</td><td>Decoy PDF document</td></tr><tr><td>SHA256</td><td>A63E90EE57A1F213A8FE76EF1A6CFF5AE9ED7EBCEDA258431533825E648C0C67</td><td>ugayt.hta payload</td></tr><tr><td>SHA256</td><td>5833917BD137804F5A021D2CB37ADFE5C4B7B67DBB06D59C3B9C5CF393835E45</td><td>noway.bat (persistence batch file)</td></tr><tr><td>SHA256</td><td>99127C8C67D90E2776BEEB85281F9C68399BF4567B07A6B638D68B760212E88D</td><td>zuidrt.hta (Stage-2 HTA payload)</td></tr><tr><td>SHA256</td><td>8F2D979EF33B2900351C94C7335275A9342C75189E1A901998E90A539E944A1A</td><td>WayBroad.dll (Stage-1 Loader DLL)</td></tr><tr><td>SHA256</td><td>0019212F25EB04BBB33BB194879C095265DB7855D6003BDD777CF0CBB90EB772</td><td>Aotestpass.dll (Stage-2 Loader DLL)</td></tr><tr><td>SHA256</td><td>9AE3D785486022AF82EA92E51B26E3F55C1BBA88A7BE2AD9790F4240E8499D14</td><td>XenoRAT final payload</td></tr><tr><td>IP Address</td><td>185.235.137.106</td><td>XenoRAT C2 server (HZ Hosting, Frankfurt)</td></tr><tr><td>IP Address</td><td>103.132.98.224</td><td>Delivery domain resolved IP (Afghan MoCIT)</td></tr><tr><td>IP Address</td><td>103.132.98.226</td><td>Delivery domain resolved IP (Afghan MoCIT)</td></tr><tr><td>Domain</td><td>abimj.edu.af</td><td>Compromised Afghan education domain used for payload delivery</td></tr><tr><td>URL</td><td>hxxp://abimj.edu.af/index.php</td><td>Stage-1 remote HTA/PHP payload endpoint</td></tr><tr><td>URL</td><td>hxxp://abimj.edu.af/institute/cloudiyaf/document.pdf</td><td>Decoy PDF download URL</td></tr><tr><td>URL</td><td>hxxps://abimj.edu.af/institute/10/</td><td>Stage-2 payload download URL</td></tr><tr><td>URL</td><td>hxxps://abimj.edu.af/institute/7/</td><td>Alternate Stage-2 URL (Windows 7 targets)</td></tr><tr><td>File Name</td><td>zuidrt.hta</td><td>Persistent HTA payload stored in Public folder</td></tr><tr><td>File Name</td><td>noway.bat</td><td>Hidden batch file for registry persistence execution</td></tr><tr><td>File Name</td><td>ayui.vmxx</td><td>Disguised encoded Stage-2 payload blob</td></tr><tr><td>File Name</td><td>ayhui.vmxx</td><td>Reconstructed intermediate shellcode container</td></tr><tr><td>Registry Key</td><td>HKCU\Software\Microsoft\Windows\CurrentVersion\Run &#8220;Edgre&#8221;</td><td>Persistence Run key masquerading as Microsoft Edge</td></tr><tr><td>Mutex</td><td>clouda</td><td>XenoRAT single-instance mutex</td></tr><tr><td>Scheduled Task</td><td>XenoUpdateManager</td><td>Persistence scheduled task created by XenoRAT</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/sidecopy-hackers-deploy-persistent-xenorat-malware/">SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/SideCopy-Hackers-Deploy-Persistent-XenoRAT-Malware-to-Target-Afghanistan-Finance-Ministry.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151485</post-id>	</item>
		<item>
		<title>Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server</title>
		<link>https://cybersecuritynews.com/plesk-command-execution-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 11:39:32 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151489</guid>

					<description><![CDATA[<p>A newly disclosed critical vulnerability in Plesk, tracked as CVE-2026-44962, is raising serious security concerns after researchers confirmed it can allow authenticated users to execute arbitrary operating system commands on affected servers. The issue, published in the National Vulnerability Database and GitHub Advisory Database, affects the APS Application Catalog component and has been assigned a [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/plesk-command-execution-vulnerability/">Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly disclosed critical<a href="https://cybersecuritynews.com/plesk-vulnerability/" target="_blank" rel="noreferrer noopener"> vulnerability in Plesk</a>, tracked as CVE-2026-44962, is raising serious security concerns after researchers confirmed it can allow authenticated users to execute arbitrary operating system commands on affected servers.</p>



<p class="wp-block-paragraph">The issue, published in the National Vulnerability Database and <a href="https://github.com/advisories/GHSA-2785-qq7p-x3cj" target="_blank" rel="noreferrer noopener nofollow">GitHub Advisory Database</a>, affects the APS Application Catalog component and has been assigned a critical CVSS score due to its high impact on confidentiality, integrity, and availability.</p>



<p class="wp-block-paragraph">The vulnerability stems from an XPath injection flaw in the APS Catalog search functionality.</p>



<h2 id="h-plesk-command-execution-vulnerability" class="wp-block-heading"><strong>Plesk Command</strong> <strong>Execution</strong> <strong>Vulnerability</strong></h2>



<p class="wp-block-paragraph">Specifically, user-supplied input is improperly handled and directly incorporated into XPath queries without adequate sanitization.</p>



<p class="wp-block-paragraph">This weakness, categorized under CWE-643, allows attackers to manipulate query logic and control how data is retrieved from XML-based storage.</p>



<p class="wp-block-paragraph">In practice, a low-privileged, authenticated user can <a href="https://cybersecuritynews.com/vmware-fusion-toctou-vulnerability/" target="_blank" rel="noreferrer noopener">exploit this flaw to escalate privileges</a> and execute arbitrary commands on the underlying server.</p>



<p class="wp-block-paragraph">Because the attack requires only network access and minimal privileges and does not depend on user interaction, it significantly lowers the barrier for exploitation in real-world environments.</p>



<p class="wp-block-paragraph">The vulnerability also operates with a changed scope, meaning it can impact resources beyond its original security boundary.</p>



<p class="wp-block-paragraph">Security researchers note that <a href="https://cybersecuritynews.com/injection-attacks/" target="_blank" rel="noreferrer noopener">XPath injection vulnerabilities</a> are particularly dangerous in web applications that rely on XML data processing, as they can bypass traditional input validation controls.</p>



<p class="wp-block-paragraph">In this case, the improper neutralization of input enables attackers to craft malicious queries that effectively alter backend execution behavior.</p>



<p class="wp-block-paragraph">Plesk has acknowledged the issue and released patched versions to address the flaw. The vulnerability has been fixed in Plesk versions 18.0.76.2 and 18.0.75.1, which were made available in late February 2026.</p>



<p class="wp-block-paragraph">Users are strongly advised to update their installations immediately to mitigate the risk of exploitation. For environments where immediate patching is not feasible, Plesk has provided a temporary workaround.</p>



<p class="wp-block-paragraph">Administrators can turn off the APS Catalog functionality by modifying the panel configuration file at /usr/local/psa/admin/conf/panel.ini.</p>



<p class="wp-block-paragraph">While this reduces exposure, it is not a substitute for applying the official security update. The vulnerability was responsibly<a href="https://support.plesk.com/hc/en-us/articles/38633651286679-Vulnerability-CVE-2026-44962-in-Plesk-s-APS-Catalog" target="_blank" rel="noreferrer noopener nofollow"> disclosed by security researcher Georgii Shutiaev</a>, who collaborated with Plesk to ensure coordinated remediation.</p>



<p class="wp-block-paragraph">At the time of publication, there is no public evidence of active exploitation. However, given the attack&#8217;s simplicity and high impact, threat actors could rapidly weaponize it.</p>



<p class="wp-block-paragraph">Organizations using Plesk, particularly in shared hosting or multi-tenant environments, should treat this vulnerability as a priority.</p>



<p class="wp-block-paragraph">Immediate patching, access control review, and monitoring for suspicious command execution activity are critical steps to prevent potential compromise.</p>



<p class="wp-block-paragraph">This incident highlights the ongoing risks of improper input handling in web applications. It reinforces the importance of secure coding practices and timely patch management in reducing the attack surface.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/plesk-command-execution-vulnerability/">Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Critical-Plesk-Vulnerability-Let-Users-execute-arbitrary-commands-on-the-server.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151489</post-id>	</item>
		<item>
		<title>Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East</title>
		<link>https://cybersecuritynews.com/iran-linked-hackers-destroy-it-backups-and-recovery-systems/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 10:49:34 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151466</guid>

					<description><![CDATA[<p>Iran-linked hackers have launched a sweeping campaign of digital destruction across the United States and the Middle East, wiping IT systems, erasing backups, and dismantling recovery infrastructure at multiple organizations. The attacks, carried out under a pro-Iranian persona called &#8220;Ababil of Minab,&#8221; went far beyond data theft, leaving victims with little ability to restore their [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/iran-linked-hackers-destroy-it-backups-and-recovery-systems/">Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Iran-linked hackers have launched a sweeping campaign of digital destruction across the United States and the Middle East, wiping IT systems, erasing backups, and dismantling recovery infrastructure at multiple organizations. </p>



<p class="wp-block-paragraph">The attacks, carried out under a pro-Iranian persona called &#8220;Ababil of Minab,&#8221; went far beyond data theft, leaving victims with little ability to restore their systems.</p>



<p class="wp-block-paragraph">The campaign first surfaced in late March and early April 2026, when Ababil of Minab claimed responsibility for breaching the Los Angeles County Metropolitan Transportation Authority (LA Metro) and destroying its data. </p>



<p class="wp-block-paragraph">LA Metro confirmed the breach on April 2, 2026. Hours after attackers deleted virtual machines from inside the agency&#8217;s management console, the transit authority reported that riders could not load fare on the TAP Mobile App.</p>



<p class="wp-block-paragraph">Analysts at Gambit Security found that Ababil of Minab is not an independent hacktivist group as they claim. </p>



<p class="wp-block-paragraph">Forensic evidence links the operation to Black Shadow, an Iran-linked group attributed by the Israel National Cyber Directorate to Iran&#8217;s Ministry of Intelligence and Security. </p>



<p class="wp-block-paragraph"><a href="https://gambit.security/blog-posts/babil-of-minab-iran-mois-destruction-campaign" id="https://gambit.security/blog-posts/babil-of-minab-iran-mois-destruction-campaign" target="_blank" rel="noreferrer noopener nofollow">Gambit Security said in a report</a> shared with Cyber Security News that attackers used scripted automation and hands-on keyboard techniques to destroy IT, virtualization, and backup infrastructure.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Beyond LA Metro, the campaign hit the South Florida Regional Transportation Authority, a company called UNIMAC, and a consumer GPS tracking service named Vyncs. </p>



<p class="wp-block-paragraph">Investigators identified additional victims in Israel and Turkey across the media, higher education, and insurance sectors. The breadth of the operation signals a deliberate, coordinated effort rather than opportunistic hacking.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_Gkpfu7Kl_tiGDeGxWRVui4tuX13-Yb_IDIicwD_xoEF4k8H5NA-uqw7XsgsE7zQByfPhgsFS-nSSWAMrxAjWG6OOHK7lNq1lNVp6SWTWes-aEEomYvv4CSRQ4nAH6DVi_aLvTiVly8p-Esj7CYkNbVWz-_ueS05wa9mIP0-isz34uM9Iua4bIph40-0/s16000/Backup%20chain%20deletion%20(Source%20-%20Gambit).webp" alt="Backup chain deletion (Source - Gambit)" /><figcaption class="wp-element-caption">Backup chain deletion (Source &#8211; Gambit)</figcaption></figure>
</div>


<p class="wp-block-paragraph">What makes this campaign stand out is how methodically the attackers eliminated any chance of recovery. They hunted down backup systems, dropped entire database chains, and <a href="https://cybersecuritynews.com/malformed-zip-files-bypass-antivirus-and-edr-detections/" id="144672" target="_blank" rel="noreferrer noopener">deleted operating system files to prevent restoration</a>. </p>



<p class="wp-block-paragraph">In one incident, the attacker used an AI chatbot to refine a custom destruction script, adding an unsettling dimension to state-linked cyber activity.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-iran-linked-hackers-destroy-it-backups-and-recovery-systems" class="wp-block-heading"><strong>Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems</strong></h2>



<p class="wp-block-paragraph">The attackers relied on two core methods: automated scripts and direct, manual interaction with system tools. At LA Metro, they powered off and deleted virtual machines through the organization&#8217;s own virtualization platform. </p>



<p class="wp-block-paragraph">At UNIMAC, they wiped three storage volumes and renamed new partitions &#8220;Minab&#8221; as a calling card. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a>At Vyncs, the group ran a custom Python script called main.py that iterated through 58 SQL Server targets and dropped every database. </p>



<p class="wp-block-paragraph">All 58 executions succeeded with zero failures. While the script ran, the attacker manually deleted 16 daily SQL backup files, then destroyed core <a href="https://cybersecuritynews.com/konni-rat-exploit-windows-explorer/" id="97774" target="_blank" rel="noreferrer noopener">Windows system folders through Windows Explorer</a>, causing their own remote session to drop and confirming total destruction.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">At the South Florida Regional Transportation Authority, attackers gained access through a proxied remote desktop connection, took databases offline, and used a secure deletion tool to overwrite the web hosting directory, including a dedicated SQL backup folder. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7ecfra1A7H27gxLdDBDy9EdGweMOQOJG-wYhW55C5-9tV7rnSjf7hWiul-qG0KRDd40c6KnvCjxJ6qbr2-Tycn6VtJzcELeGueeOmqUqlJTbEm_tHPyCNDpAYYD05gNBz3xmcMG0I6SJtImECPLYsAXZQ7lXTUFE1yi7ttsDXft1OD90FQ4Ok2W1JqSw/s16000/Scripted%20SQL%20Server%20database%20deletion%20via%20main.py%20(Source%20-%20Gambit).webp" alt="Scripted SQL Server database deletion via main.py (Source - Gambit)" /><figcaption class="wp-element-caption">Scripted SQL Server database deletion via main.py (Source &#8211; Gambit)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Every step showed an attacker who understood exactly where critical data lived and how to ensure it could never be recovered.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-custom-tools-and-attribution-evidence" class="wp-block-heading"><strong>Custom Tools and Attribution Evidence</strong></h2>



<p class="wp-block-paragraph">Alongside the destruction, investigators uncovered two custom data theft tools. The first involved compressing stolen files and uploading them to the victim&#8217;s own public website, then pulling them back through an attacker-controlled server. </p>



<p class="wp-block-paragraph">The second was a bespoke C++ tool called FileFiend, which scanned drives and network shares before sending stolen files to a hardcoded command-and-control server.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attackers also built a Flask-based file receiver for accepting uploads from compromised environments. Although file transfers were encrypted, the key was sent in the same request as the data, making it readable to anyone monitoring traffic. </p>



<p class="wp-block-paragraph">When visitors hit a nonexistent page on the attacker&#8217;s server, they were redirected to the FBI&#8217;s official website.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/pentest-swarm-ai-tool/" id="151427" target="_blank" rel="noreferrer noopener">The strongest attribution link to Black Shadow came from a staging server</a> that previously hosted a fake mental health support site targeting Israeli soldiers in August 2025. </p>



<p class="wp-block-paragraph">That same server was found transferring stolen files into this campaign&#8217;s infrastructure. Organizations in critical infrastructure, transportation, and education should urgently review access controls, backup isolation practices, and incident response readiness.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4f09b407-eb18-4a6a-941a-8a6a5817a232/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.pdf?AWSAccessKeyId=ASIA2F3EMEYE2DSHY77P&amp;Signature=uCsn8GUzI6vcwB7XBwek7VHjxeQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEAaCXVzLWVhc3QtMSJHMEUCICeZfKF6mYl%2FUyUlwNqR3QYAG2hjsOJqR84%2BoZriZ5crAiEAxN%2B7x9dE33l4lrlq1xh5rlYsU1gxXQAFedw2jA9GqoYq8wQICRABGgw2OTk3NTMzMDk3MDUiDDQ1j6SFUcZ10qb6SyrQBCB8XjB2oK3JAftu7PpINmUB4n0PRAw8bQXyNq4cBA69DjFCn7ePWQBP%2BZcHeW7%2Fh6%2Bpg5U5FSt1GuZBxF84LJe0NsahGJ1qWGYTUVkutuHALg134npuiugtfcRCwl3I8Zu6%2BiFy1KsQNlVxWdjWHZFcgkXVVCvrMFOWh%2FOMvX%2FzUmuE4MDvC51nh5DsCorVxgWHDP7K94JVm502DdxaJxtXN5JfNdFnpRSmdd9RLjy0Wh1KynYoLXKovATVnxHqUhTbQNryTB6uBfy0Ssrnp6LBnub4DsDEmZd68RBJolvfnvdy3YPt9bWktWZtaygj%2FKFcKuNSlTEeXL9fXffOWy9dE4VRPKIOcfR4W6PAmd0fVWNmG16verrjnuw39l0UBEJ9U7s4LjeRFEMUu3TP8EwkrXBp418th4RVDmEif7WrDhmDaqlvFrGA0kc%2FqkRonPMN2YOPt0PDVg1X0eS77grkWh%2Bn0f5TU1pDLMGd01Qv9C0awhwT43dGFosdaD2R085bY0MddnPpwQTjzgqX%2FI%2BoVWAyvmxYFGOfO7g9VcWCvbhbtcCUsKUCb%2FweI0GxVIHQ7JBfWFFXPx73as5R%2BhGLdgJTHKW4FzfGVGafFftXUG9SLOhvGaYEcKl%2BKC92%2BNNfhLfF0ErblBRGJOIlqmOAZNu3p4dtHdl1KIn%2Fuuula4xOuHU4I2p2zUeRUfd%2Bx7IEu8LaA0cKQSLvQRmdQs8%2FH4rllNrBMTrbcGXNrL051aM3EJDo7YeF6ywU4yUkInORwnLLOQDd2EmegVf9JaMws%2Bz00AY6mAEkd2byZj4iK%2BHgkGymI7lnoaZaRPvcIXTlQnARG8Rn5zqMoVS2l%2FMBvQKcOzTGFk2AAuVAiai3rFnty7Ltwu6wLVwBBKTarKYi%2BtFJbyyk4b%2BDxx%2Bq70XdDcTpeeqix6sv4VBPBzIJ52VQa3XpMp%2BMEPWAPOLIyubN1bGpf70YQDEtkO6yNYmUu%2FmqUXwvKcdJzM27JisbeA%3D%3D&amp;Expires=1780301391" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IPv4</td><td>31.172.87.20</td><td>Operator staging server; served TLS for nefeshhope[.]com</td></tr><tr><td>IPv4</td><td>212.83.61.213</td><td>FileFiend C2, hardcoded in 81a2535</td></tr><tr><td>IPv4</td><td>66.85.26.183</td><td>FileFiend C2, hardcoded in c8cc422 and 33a6b49</td></tr><tr><td>IPv4</td><td>195.20.17.129</td><td>FileFiend C2, hardcoded in d76a943</td></tr><tr><td>IPv4</td><td>46.246.125.131</td><td>Source IP of propaganda site</td></tr><tr><td>IPv4</td><td>146.70.233.83</td><td>Served TLS for nefeshhope[.]com</td></tr><tr><td>IPv4</td><td>91.193.19.198</td><td>Attacker-controlled exit node</td></tr><tr><td>IPv4</td><td>89.36.231.56</td><td>Served TLS for feedback.nefeshhope[.]com</td></tr><tr><td>IPv4</td><td>84.200.89.52</td><td>Served TLS for nefeshhope[.]com</td></tr><tr><td>IPv4</td><td>46.30.190.173</td><td>Served TLS for members.nefeshhope[.]com</td></tr><tr><td>Domain</td><td>nefeshhope[.]com</td><td>Operator-controlled site</td></tr><tr><td>Domain</td><td>members.nefeshhope[.]com</td><td>Observed communicating with A.ExE Go tunneler</td></tr><tr><td>Domain</td><td>banujcobaar[.]com</td><td>Redirected nefeshhope[.]com</td></tr><tr><td>SHA-256</td><td>81a25357d027d0f04a43139377d5d58384b8e9b0770e699cdcc37e600641cf90</td><td>FileFiend / Exchangedb.exe</td></tr><tr><td>SHA-256</td><td>c8cc4225d1e21324ef419adbb1c10dd0578fb034b5f5d7b8000f0aae1871c061</td><td>FileFiend / Exchangedb.exe</td></tr><tr><td>SHA-256</td><td>33a6b4900c2fbfb3c2d816947871eade800d0c0e2a2680871700fd6e640e5f20</td><td>FileFiend / Exchangedb.exe</td></tr><tr><td>SHA-256</td><td>d76a94309240a7e2f11a89fab54a6853628e976a5ff19084b1b0894c89e6a742</td><td>FileFiend</td></tr><tr><td>SHA-256</td><td>f6db77be038980e9dbbf9f11e0f7ae7d2d4d3f1a53199958f1f55137dde5efd3</td><td>A.ExE Go tunneler communicating with members.nefeshhope[.]com</td></tr><tr><td>SHA-256</td><td>1c699720034367ba9761a8d31c854fd444e8e3c8c31c520a39c543cf95286029</td><td>Go tunneler; served from 45.150.108.61</td></tr><tr><td>SHA-256</td><td>38965a60835a5ee3eaefd3d0bffa97c0e4f0c5cd74d31d8053bedeea14f536ee</td><td>Go tunneler; served from 45.150.108.61</td></tr><tr><td>File Path</td><td>C:\Users\casio\Desktop\uploader v3\temp uploader v3\temp uploader v3.cpp</td><td>Developer source path in FileFiend</td></tr><tr><td>File Path</td><td>F:\OH~FileFiend(Uploader)\uploader v3\x64\Release\temp uploader v3.pdb</td><td>PDB path in FileFiend v4</td></tr><tr><td>Filename</td><td>Exchangedb.exe</td><td>Decoy filename for FileFiend uploader</td></tr><tr><td>TLS Subject</td><td>O=Acme Cloud Solutions Inc, CN=localhost, emailAddress=admin@acmecloud.example</td><td>Self-signed certificate on Flask receiver</td></tr><tr><td>Tool</td><td>proxychains</td><td>Used for proxied RDP and download tunneling</td></tr><tr><td>Tool</td><td>xfreerdp</td><td>Used for proxied RDP access</td></tr><tr><td>Tool</td><td>axel</td><td>Linux CLI download accelerator used in exfiltration</td></tr><tr><td>Tool</td><td>http.flask.py</td><td>Custom Flask receiver</td></tr><tr><td>Tool</td><td>WipeFile</td><td>Windows utility for secure file deletion</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/iran-linked-hackers-destroy-it-backups-and-recovery-systems/">Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Iran-Linked-Hackers-Destroy-IT-Backups-and-Recovery-Systems-in-Cyberattack-targeting-Middle-East.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151466</post-id>	</item>
		<item>
		<title>New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors</title>
		<link>https://cybersecuritynews.com/new-drivesurge-threat-actor-uses-clickfix/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 10:14:29 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151465</guid>

					<description><![CDATA[<p>A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. Using a combination of fake browser update pages and a social engineering trick known as ClickFix, this operation ran largely undetected until now. What makes DriveSurge especially dangerous is not just its scale, but [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/new-drivesurge-threat-actor-uses-clickfix/">New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. </p>



<p class="wp-block-paragraph">Using a combination of fake browser update pages and a social engineering trick known as ClickFix, this operation ran largely undetected until now. </p>



<p class="wp-block-paragraph">What makes DriveSurge especially dangerous is not just its scale, but the deep sophistication built into its infrastructure to automate malware delivery at massive scale.</p>



<p class="wp-block-paragraph">DriveSurge works by injecting malicious code into high-reputation, legitimate websites without the knowledge of site owners or their visitors. </p>



<p class="wp-block-paragraph">When someone visits one of these compromised sites, hidden code quietly routes them through a Traffic Distribution System, or TDS. This system profiles each visitor and decides what to serve them next, making the attack feel natural and highly targeted at the same time.</p>



<p class="wp-block-paragraph"><a href="https://www.silentpush.com/blog/drivesurge/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=drivesurge" id="https://www.silentpush.com/blog/drivesurge/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=drivesurge" target="_blank" rel="noreferrer noopener nofollow">Silent Push researchers said in a report</a> shared with Cyber Security News that they identified DriveSurge as the primary driver behind a massive surge in ClickFix and Fake Update campaigns across the web. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLyJThuIzj_HxmuNQx10oeKbPMbZ40-eprtSuECgr8nnYYnBCTt4X9zHGaxvU3jgIRUEBT0NJNt0Z8lcDD_ZwSCB5iPGsTo_FehjU3EZh_30HENuRerpDlpYj-SqujLRsgUsBd9kNsANU55HcC1ddCFIHlNBE5QSH-03wu0RpYb7kps62zDLPjfX0o8LQ/s16000/Temporary%20email%20service%20provider%20tempmail%5B.%5Dso%20provides%20long-term%20use%20services%20(Source%20-%20Silent%20Push).webp" alt="Temporary email service provider tempmail[.]so provides long-term use services (Source - Silent Push)" /><figcaption class="wp-element-caption">Temporary email service provider tempmail[.]so provides long-term use services (Source &#8211; Silent Push)</figcaption></figure>
</div>


<p class="wp-block-paragraph">According to their analysis, DriveSurge operates as a specialized Initial Access Broker using a Pay-Per-Install model, where payment is collected each time a victim device is successfully infected. Those confirmed infection leads are then sold to other threat actors operating downstream.</p>



<p class="wp-block-paragraph">Researchers uncovered eight distinct technical fingerprints that map out DriveSurge&#8217;s malicious infrastructure, from how scripts are injected into victim sites to the registration patterns used for its domains. </p>



<p class="wp-block-paragraph">This level of operational detail points to a threat actor that has invested serious time into building a repeatable, scalable infection system. The group has <a href="https://cybersecuritynews.com/41-of-success-logins-across-websites/" id="96515" target="_blank" rel="noreferrer noopener">compromised thousands of websites that redirect visitors to malware</a>, all without site owners ever knowing.</p>



<p class="wp-block-paragraph">The campaign targets a wide range of browsers, including Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. </p>



<p class="wp-block-paragraph">Victims encounter either a fake browser update page or a ClickFix prompt, both designed to look completely routine and trustworthy. That familiarity is exactly what makes both methods so effective against everyday users.</p>



<h2 id="h-new-drivesurge-threat-actor-uses-clickfix-and-fake-updates" class="wp-block-heading"><strong>New DriveSurge Threat Actor Uses ClickFix and Fake Updates</strong></h2>



<p class="wp-block-paragraph">DriveSurge deploys two main methods to trick users into installing malware on their own devices. In the Fake Update scenario, a compromised site displays a convincing browser update prompt that impersonates a well-known browser. </p>



<p class="wp-block-paragraph">Clicking the update button triggers the download of a ZIP file containing multiple DLL files and a &#8220;Browser Update.exe&#8221; file that is actually malware.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxLFIfzQ66USSuSzaq1vlmU4-KED_hXt_qog6qszo3R140DyuXU8cvOFSVIZzi8KVoTDCswkucwbHZRmmb0Tk9vK_xm3zZoiiTAVIb0A_B6nAhnEZlvAbqRd77OFm1s5IHL8YSBav2k6Q5Cf3PkE46OpcfjIXDZdCdpB8lk1LPjGvw91UPKop3NPyvYFc/s16000/Mozilla%20Firefox%20Update%20page%20triggered%20on%20the%20compromised%20site%20(Source%20-%20Silent%20Push).webp" alt="Mozilla Firefox Update page triggered on the compromised site (Source - Silent Push)" /><figcaption class="wp-element-caption">Mozilla Firefox Update page triggered on the compromised site (Source &#8211; Silent Push)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The ClickFix method works differently. A <a href="https://cybersecuritynews.com/beware-of-fake-error-pages-that-linux-and-windows-systems/" id="117688" target="_blank" rel="noreferrer noopener">fake error message instructs the victim</a> to copy and paste a command into their terminal or PowerShell window, which then silently installs malware. </p>



<p class="wp-block-paragraph">In one confirmed instance, the <a href="https://cybersecuritynews.com/hackers-deliver-asyncrat-via-fake-verification-prompt/" id="111267" target="_blank" rel="noreferrer noopener">ClickFix prompt tried to pull malicious code</a> from an IP address already flagged in active threat intelligence feeds. Both methods exploit the trust people naturally place in familiar websites and routine-looking browser prompts.</p>



<p class="wp-block-paragraph">The underlying zTDS infrastructure uses obfuscation techniques, including Base64 encoding and string manipulation, to hide malicious redirect code inside normal-looking page elements. </p>



<p class="wp-block-paragraph">A failover mechanism cycles through multiple backup servers to ensure the payload reaches the victim even if one delivery domain goes down. Researchers confirmed the TDS has been in active use since at least 2022.</p>



<h2 id="h-macos-targeting-and-a-cross-platform-victim-strategy" class="wp-block-heading"><strong>MacOS Targeting and a Cross-Platform Victim Strategy</strong></h2>



<p class="wp-block-paragraph">Analysis of obfuscated JavaScript files tied to DriveSurge revealed the attack chain does not only target Windows machines. One analyzed payload delivered macOS malware, showing that DriveSurge is actively building a cross-platform victim pool. </p>



<p class="wp-block-paragraph">The payload used a multi-stage shell command that downloaded a secondary file, executed it, and then deleted itself immediately to reduce forensic traces.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjTb0YA2_JepYZgIDH_ry_l402obhu9Hrwv7AQoh1_IrJvnfJULx-yJHsym4zuk4GA1z4BXkrQyuMOMA6eLid9Y5TIkf7HV3ZzgH8n4nLDI76Hd0knKXxe0mBnwTl1X1nYadqiPdkJ9FthWrTWX4DTaSUPbwTzBuNxvL_KJ5FTlpmy5BmXTGEfksvXTq4/s16000/Compromised%20site%20(Source%20-%20Silent%20Push).webp" alt="Compromised site (Source - Silent Push)" /><figcaption class="wp-element-caption">Compromised site (Source &#8211; Silent Push)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Researchers also discovered a separate Advertisement Distribution System linked to the campaign. This system collects device metadata and uses behavioral signals like mouse movements, scrolls, and clicks to confirm human presence before delivering content. </p>



<p class="wp-block-paragraph">Organizations are advised to <a href="https://cybersecuritynews.com/hackers-attacking-mobile-users-leveraging-pwa-javascript/" id="107644" target="_blank" rel="noreferrer noopener">monitor for unusual external JavaScript injections</a>, audit third-party scripts loading from unrecognized domains, and ensure web-facing content management systems remain fully patched and access-controlled.</p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Domain</td><td>beacontrace[.]bond</td><td>Malicious zTDS inject domain serving t.js script</td></tr><tr><td>Domain</td><td>jclforwarding[.]com</td><td>Compromised site used to serve Fake Update / ClickFix content</td></tr><tr><td>Domain</td><td>check[.]first-node[.]rocks</td><td>Malicious domain serving fake Mozilla Firefox update page</td></tr><tr><td>Domain</td><td>cptoptious[.]com</td><td>zTDS delivery domain used in obfuscated payload</td></tr><tr><td>Domain</td><td>newtdsone[.]shop</td><td>zTDS delivery domain used in obfuscated payload</td></tr><tr><td>Domain</td><td>captioto[.]com</td><td>zTDS delivery domain used in obfuscated payload</td></tr><tr><td>Domain</td><td>banerpanel[.]live</td><td>Advertisement Distribution System (ADS) panel domain</td></tr><tr><td>Domain</td><td>testio[.]ecartdev[.]com</td><td>Payload and development server identified in analysis</td></tr><tr><td>Domain</td><td>ycyfugihih[.]cfd</td><td>Domain linked to DriveSurge registration email pivot</td></tr><tr><td>Domain</td><td>brightson[.]icu</td><td>Pre-weaponized DriveSurge infrastructure domain</td></tr><tr><td>Domain</td><td>coverlink[.]icu</td><td>Pre-weaponized DriveSurge infrastructure domain</td></tr><tr><td>Domain</td><td>datumprobe[.]icu</td><td>Pre-weaponized DriveSurge infrastructure domain</td></tr><tr><td>Domain</td><td>webgleam[.]info</td><td>Domain identified via Fingerprint 3 infrastructure pattern</td></tr><tr><td>Domain</td><td>cptoptions[.]com</td><td>Suspicious domain loaded into jclforwarding[.]com</td></tr><tr><td>Domain</td><td>banerpanel[.]live</td><td>ADS domain serving casino slot machine advertisement</td></tr><tr><td>Email</td><td>thiagorivera197151[@]ycyfugihih[.]cfd</td><td>DriveSurge domain registration email (Fingerprint 6 pivot)</td></tr><tr><td>Email</td><td>samuel_jordan16[@]flixtrend[.]net</td><td>Second DriveSurge domain registration email (Fingerprint 7 pivot)</td></tr><tr><td>IP Address</td><td>46[.]226[.]166[.]57</td><td>C2 server hosting macOS payload; URL: hxxp://46[.]226[.]166[.]57/ce3cbfc887?force=1</td></tr><tr><td>File Hash (SHA256)</td><td>90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc</td><td>ZIP file downloaded via fake Mozilla Firefox update page</td></tr><tr><td>File Hash (SHA256)</td><td>7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d</td><td>macOS payload binary retrieved from C2 server</td></tr><tr><td>File Hash (SHA256)</td><td>29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea</td><td>Malicious server body SHA256 (Fingerprint 4)</td></tr><tr><td>File Hash (SHA256)</td><td>a84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf</td><td>Malicious server body SHA256 (Fingerprint 4 alternate)</td></tr><tr><td>File Hash (SHA256)</td><td>428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6</td><td>Data hash linked to jclforwarding[.]com web resources</td></tr><tr><td>File Name</td><td>t.js</td><td>Malicious injected JavaScript file (Fingerprint 1 pattern)</td></tr><tr><td>File Name</td><td>Browser Update.exe</td><td>Fake browser update executable dropped via ZIP file</td></tr><tr><td>File Name</td><td>script.js</td><td>Injected JavaScript file served by check[.]first-node[.]rocks</td></tr><tr><td>File Name</td><td>banner-js[.]php</td><td>Script loaded into compromised sites via banerpanel[.]live</td></tr><tr><td>File Name</td><td>changelog.txt</td><td>Publicly accessible file on zTDS server confirming TDS version history</td></tr><tr><td>URL</td><td>hxxps[://]newtdsone[.]shop/jsrepo?rnd=</td><td>zTDS payload fetch URL embedded in obfuscated JavaScript</td></tr><tr><td>URL</td><td>hxxps[://]cptoptious[.]com/jsrepo?rnd=</td><td>zTDS payload fetch URL embedded in obfuscated JavaScript</td></tr><tr><td>URL</td><td>hxxps[://]captioto[.]com/jsrepo?rnd=</td><td>zTDS payload fetch URL embedded in obfuscated JavaScript</td></tr><tr><td>URL</td><td>hxxp://46[.]226[.]166[.]57/ce3cbfc887?force=1</td><td>C2 URL delivering macOS malware payload</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/new-drivesurge-threat-actor-uses-clickfix/">New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/New-DriveSurge-Threat-Actor-Uses-ClickFix-and-Fake-Updates-to-Infect-Website-Visitors.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151465</post-id>	</item>
		<item>
		<title>Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage</title>
		<link>https://cybersecuritynews.com/microsoft365-mfa-setup-failure/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 09:48:05 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151480</guid>

					<description><![CDATA[<p>Microsoft is currently investigating a service disruption affecting users attempting to set up multi-factor authentication (MFA) or access the self-service sign-in portal at mysignins.microsoft.com. The issue was officially acknowledged by the company&#8217;s Microsoft 365 Status account on X (formerly Twitter) on June 1, 2026. The company&#8217;s official statement read: &#8220;We&#8217;re investigating an issue where some [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft365-mfa-setup-failure/">Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft is currently investigating a service disruption affecting users attempting to set up multi-factor authentication (MFA) or access the self-service sign-in portal at mysignins.microsoft.com. The issue was officially acknowledged by the company&#8217;s Microsoft 365 Status account on X (formerly Twitter) on June 1, 2026.</p>



<p class="wp-block-paragraph">The company&#8217;s official statement read: &#8220;We&#8217;re investigating an issue where some users may be unable to setup MFA or access the mysignins.microsoft.com website.&#8221; Microsoft has directed affected organizations to reference incident <a href="https://admin.cloud.microsoft/?#/servicehealth/:/alerts/MO1329260" target="_blank" rel="noreferrer noopener">tracking code MO1329260</a> in the Microsoft 365 Admin Center for real-time updates and remediation guidance.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<div class="embed-x"><blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr">We’re investigating an issue where some users may be unable to setup MFA or access the <a href="https://t.co/nvKILPBBVJ">https://t.co/nvKILPBBVJ</a> website. For more information, please see MO1329260 in the admin center.</p>&mdash; Microsoft 365 Status (@MSFT365Status) <a href="https://x.com/MSFT365Status/status/2061379221662880104?ref_src=twsrc%5Etfw">June 1, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></div>
</div></figure>



<p class="wp-block-paragraph">The outage directly impacts users&#8217; ability to enroll in or <a href="https://cybersecuritynews.com/tycoon-2fa-aitm-kit-bypasses-mfa/" target="_blank" rel="noreferrer noopener">modify MFA settings</a>, a critical security control for enterprise environments. The mysignins.microsoft.com portal allows end users to manage their authentication methods, review recent sign-in activity, and configure security info without requiring IT helpdesk intervention.</p>



<p class="wp-block-paragraph">Disruption to this service can create bottlenecks in onboarding workflows, account recovery processes, and security policy enforcement.</p>



<p class="wp-block-paragraph">Organizations enforcing Conditional Access policies that require MFA registration may find new or existing users temporarily locked out of Microsoft 365 services as a downstream effect of this outage.</p>



<h2 id="h-what-administrators-should-do" class="wp-block-heading"><strong>What Administrators Should Do</strong></h2>



<ul class="wp-block-list">
<li>Navigate to the Microsoft 365 Admin Center and search for incident MO1329260 under Service Health for the latest status updates</li>



<li>Temporarily consider adjusting Conditional Access policies to avoid locking out users who cannot complete MFA setup during the outage window</li>



<li>Monitor the @MSFT365Status Twitter/X account for real-time incident updates</li>



<li>Document affected users to prioritize MFA re-enrollment once the service is restored</li>
</ul>



<p class="wp-block-paragraph">Microsoft has not yet disclosed the root cause or an estimated time to resolution. The company routinely publishes post-incident reviews for significant service disruptions, which are made available through the Admin Center after resolution.</p>



<p class="wp-block-paragraph">Administrators and security teams are advised to stay on alert, as outages affecting MFA infrastructure can create temporary security gaps if not properly managed.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<div class="embed-x"><blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr">We’ve completed a failover to alternate healthy infrastructure to mitigate the impact and are closely monitoring service telemetry to ensure full recovery. For more information, please see MO1329260 in the admin center.</p>&mdash; Microsoft 365 Status (@MSFT365Status) <a href="https://x.com/MSFT365Status/status/2061385598800109843?ref_src=twsrc%5Etfw">June 1, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></div>
</div></figure>



<p class="wp-block-paragraph">Update:</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft365-mfa-setup-failure/">Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Microsoft365-MFA-Setup-Failure.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151480</post-id>	</item>
	</channel>
</rss>
