<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Mon, 01 Jun 2026 03:16:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild</title>
		<link>https://cybersecuritynews.com/windows-netlogon-0-click-rce/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 03:16:44 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151436</guid>

					<description><![CDATA[<p>The critical Windows Netlogon remote code execution (RCE) vulnerability tracked as CVE-2026-41089 is now under active exploitation in the wild, significantly raising the risk profile for unpatched Windows Server environments. The flaw affects Windows servers configured as domain controllers and allows unauthenticated remote attackers to execute arbitrary code with SYSTEM-level privileges by sending specially crafted [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-netlogon-0-click-rce/">Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The critical Windows Netlogon remote code execution (RCE) vulnerability tracked as CVE-2026-41089 is now under active exploitation in the wild, significantly raising the risk profile for unpatched Windows Server environments.</p>



<p class="wp-block-paragraph">The flaw affects Windows servers configured as domain controllers and allows unauthenticated remote attackers to execute arbitrary code with SYSTEM-level privileges by sending specially crafted Netlogon network requests.</p>



<p class="wp-block-paragraph">Disclosed and patched as part of Microsoft’s <a href="https://cybersecuritynews.com/microsoft-patch-tuesday-may-2026/" target="_blank" rel="noreferrer noopener">May 2026 Patch Tuesday release</a>, CVE-2026-41089 is rated critical due to its combination of remote exploitability, lack of required user interaction, and the potential for complete domain takeover.</p>



<p class="wp-block-paragraph">The Center for Cybersecurity Belgium (CCB) has issued a dedicated warning highlighting this vulnerability among the 118 flaws addressed in the May 2026 patch bundle, 16 of which are classified as critical.</p>



<h2 id="h-windows-netlogon-0-click-rce-exploited" class="wp-block-heading"><strong>Windows Netlogon 0-Click RCE Exploited</strong></h2>



<p class="wp-block-paragraph">To exploit CVE-2026-41089, an attacker only needs network access to a vulnerable domain controller’s Netlogon service. By sending a specially crafted Netlogon network request, the adversary can trigger improper handling within the service, leading to arbitrary code execution under SYSTEM privileges.</p>



<p class="wp-block-paragraph">No prior authentication, local access, or user interaction is required, making this an ideal candidate for automated exploitation, lateral movement, and rapid domain compromise once an attacker gains a foothold in the network.</p>



<p class="wp-block-paragraph">Microsoft has released security updates for all supported versions of Windows Server from 2012 onward, covering domain controllers across a wide range of enterprise deployments.</p>



<p class="wp-block-paragraph">Given the central role of Active Directory in identity, access control, and authentication, compromise of a domain controller via Netlogon can enable attackers to deploy malware, create or modify accounts, disable security controls, and pivot across critical systems.</p>



<h2 id="h-urgent-patch-monitoring-and-detection-guidance" class="wp-block-heading"><strong>Urgent Patch, Monitoring, and Detection Guidance</strong></h2>



<p class="wp-block-paragraph">The <a href="https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102" target="_blank" rel="noreferrer noopener nofollow">CCB strongly recommends</a> that organizations prioritize the deployment of patches for CVE-2026-41089 after appropriate testing, treating this as a top-tier emergency remediation item.</p>



<p class="wp-block-paragraph">Domain controllers, especially those exposed to untrusted or segmented networks, should be patched first to reduce the window of exposure.</p>



<p class="wp-block-paragraph">In addition to patching, organizations are urged to upscale monitoring and detection efforts for suspicious Netlogon-related activity. This includes scrutinizing anomalous authentication behavior, unusual domain controller traffic, and potential signs of privilege escalation or new administrative account creation following Netlogon events. Early detection is critical to contain intrusions leveraging this vulnerability, especially given its active exploitation status.</p>



<p class="wp-block-paragraph">Security teams should also revisit network segmentation and access controls around domain controllers, ensuring that only necessary systems and services can communicate with Netlogon over the relevant ports.</p>



<p class="wp-block-paragraph">Combined with rapid patch deployment and enhanced monitoring, these steps are essential to mitigate the immediate threat posed by CVE-2026-41089 in ongoing exploitation campaigns.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP </strong></p>
<p>The post <a href="https://cybersecuritynews.com/windows-netlogon-0-click-rce/">Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Windows-Netlogon-0-Click-RCE.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151436</post-id>	</item>
		<item>
		<title>Microsoft Releases KB5089573 for Windows 11 to Fix Patch Tuesday Install Issues</title>
		<link>https://cybersecuritynews.com/microsoft-kb5089573-windows-11/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sun, 31 May 2026 02:22:11 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151432</guid>

					<description><![CDATA[<p>Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release. The update brings OS builds to 26200.8524 and 26100.8524, respectively, resolving a widely reported error that prevented many systems from completing the monthly security [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-kb5089573-windows-11/">Microsoft Releases KB5089573 for Windows 11 to Fix Patch Tuesday Install Issues</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release.</p>



<p class="wp-block-paragraph">The update brings OS builds to 26200.8524 and 26100.8524, respectively, resolving a widely reported error that prevented many systems from completing the monthly security update.</p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/microsoft-patch-tuesday-may-2026/" target="_blank" rel="noreferrer noopener">May 2026 Patch Tuesday security update</a> (KB5089549) triggered installation failures on a subset of Windows 11 devices, with error code 0x800f0922 halting the process.</p>



<p class="wp-block-paragraph">The failure specifically targeted devices with limited free space on the EFI System Partition (ESP), particularly those with 10 MB or less available. Affected systems would progress through the initial installation phases but crash during the reboot phase at approximately 35–36% completion, leaving devices in an inconsistent state.</p>



<p class="wp-block-paragraph">Microsoft had previously issued a Known Issue Rollback (KIR) as a temporary workaround, automatically propagating relief to consumer and non-managed business devices.</p>



<p class="wp-block-paragraph">An alternative registry-based workaround — modifying the <code>EspPaddingPercent</code> value under <code>HKLM\SYSTEM\CurrentControlSet\Control\Bfsvc</code> — was also available for enterprise admins. However, KB5089573, released on May 26, 2026, permanently resolves the issue and eliminates the need for either workaround.</p>



<h2 id="h-kb5089573-cumulative-update" class="wp-block-heading"><strong>KB5089573</strong> &#8211; <strong>Cumulative Update</strong></h2>



<p class="wp-block-paragraph">Beyond the critical ESP fix, KB5089573 is a production-quality cumulative update delivered via two phases: a gradual rollout for staged device delivery and a normal rollout for broad general availability. The update incorporates several notable components:</p>



<ul class="wp-block-list">
<li>AI Component Refresh: Image Search, Content Extraction, Semantic Analysis, and Settings Model are all updated to version 1.2605.856.0, reflecting Microsoft&#8217;s continued push to deepen on-device AI capabilities in Windows 11.</li>



<li>Personalization Improvements: Added on May 28, 2026, as part of the gradual rollout phase.</li>



<li>Servicing Stack Update (KB5092734): Build 26100.8519 improves the reliability and robustness of the Windows update installation infrastructure itself, ensuring devices can cleanly receive future patches.</li>
</ul>



<p class="wp-block-paragraph">The <a href="https://support.microsoft.com/en-gb/topic/may-26-2026-kb5089573-os-builds-26200-8524-and-26100-8524-preview-f378c8ae-0170-47c9-a1e9-dfef978c8e17" target="_blank" rel="noreferrer noopener nofollow">update is available through multiple channels</a> with no prerequisites beyond having a compatible Windows 11 25H2 or 24H2 device:</p>



<ol class="wp-block-list">
<li>Navigate to Start → Settings → Windows Update → Advanced options → Optional updates</li>



<li>Select the available update and click Download and Install</li>



<li>Alternatively, download the standalone package directly from the Microsoft Update Catalog using the KB number</li>



<li>Enterprise environments can be deployed via Windows Update for Business or WSUS</li>
</ol>



<p class="wp-block-paragraph">Microsoft has confirmed there are no known issues with KB5089573 at the time of release.</p>



<p class="wp-block-paragraph">Should removal be necessary, Microsoft advises using the <code>DISM /online /get-packages</code> command to identify the package name, followed by the <code>DISM/Remove-Package</code> option with the LCU package name as the argument.</p>



<p class="wp-block-paragraph">Notably, running the Windows Update Standalone Installer (<code>wusa.exe</code>) with the <code>/uninstall</code> switch will not work because the combined package includes the Servicing Stack Update (SSU), which cannot be removed post-installation. Microsoft strongly recommends against removing security updates given the inherent risk exposure.</p>



<p class="wp-block-paragraph">Given the critical nature of the ESP space issue impacting a broad segment of enterprise and consumer devices, IT administrators and end users alike are advised to prioritize KB5089573 during their next maintenance window.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-kb5089573-windows-11/">Microsoft Releases KB5089573 for Windows 11 to Fix Patch Tuesday Install Issues</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/Microsoft-KB5089573-Windows-11.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151432</post-id>	</item>
		<item>
		<title>GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition</title>
		<link>https://cybersecuritynews.com/gitlab-patches-duo-ai-dos-flaws/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Sat, 30 May 2026 16:28:35 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[GitLab]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151336</guid>

					<description><![CDATA[<p>GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as security patch releases for self‑managed instances. These builds fix several vulnerabilities across Duo AI [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/gitlab-patches-duo-ai-dos-flaws/">GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform.</p>



<p class="wp-block-paragraph">On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as<a href="https://cybersecuritynews.com/gitlab-security-update-2/" target="_blank" rel="noreferrer noopener"> security patch</a> releases for self‑managed instances.</p>



<p class="wp-block-paragraph">These builds fix several vulnerabilities across Duo AI workflow runners, the Wiki component, GraphQL WorkItem APIs, operations, pipelines, and authentication endpoints, and GitLab is urging all administrators to upgrade without delay.</p>



<p class="wp-block-paragraph">GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take any action.</p>



<h2 id="h-gitlab-fixes-duo-ai-dos-flaws" class="wp-block-heading"><strong>GitLab Fixes Duo AI, DoS</strong> <strong>Flaws</strong></h2>



<p class="wp-block-paragraph">The most severe issue is a high‑impact access control flaw in Duo AI workflow runners, tracked as CVE‑2026‑4868, which affects GitLab EE from 18.8 up to but not including 18.10.7, 18.11.4, and 19.0.1.</p>



<p class="wp-block-paragraph">Under specific conditions, an authenticated user could trigger certain Duo AI workflows to execute under another user’s identity due to improper user identity resolution in the workflow runner logic, with a CVSS 3.1 score of 8.2.</p>



<p class="wp-block-paragraph">This could enable lateral movement or privilege abuse within AI‑assisted workflows if left unpatched.</p>



<p class="wp-block-paragraph">GitLab also fixed a <a href="https://cybersecuritynews.com/gitlab-vulnerabilities-xss-and-dos/" target="_blank" rel="noreferrer noopener">denial‑of‑service vulnerability</a> in the Wiki component, tracked as CVE‑2026‑1402, which impacts GitLab CE/EE from 17.1 through unpatched 18.10, 18.11, and 19.0 branches.</p>



<p class="wp-block-paragraph">Due to insufficient input validation, an authenticated user could craft content that exhausts resources and renders the Wiki unavailable, earning a CVSS score of 6.5.</p>



<p class="wp-block-paragraph">In parallel, CVE‑2026‑6713 addresses incorrect <a href="https://cybersecuritynews.com/graphql-security-2024-report/" target="_blank" rel="noreferrer noopener">authorization checks in the GraphQL</a> WorkItem API that could allow unauthenticated users to enumerate private projects under certain conditions, rated 5.3 on the CVSS scale.</p>



<p class="wp-block-paragraph">Several medium‑severity authorization issues have also been resolved in GitLab EE operations and Duo features.</p>



<p class="wp-block-paragraph">CVE‑2026‑5296 fixes improper authorization in the Duo Workflows API that could let a developer‑role user bypass flow restrictions when foundational flows are enabled at the group level.</p>



<p class="wp-block-paragraph">CVE‑2026‑2601 corrects missing authorization checks that could <a href="https://cybersecuritynews.com/gitlab-vulnerabilities/" target="_blank" rel="noreferrer noopener">expose sensitive deployment</a> data to developer‑level users.</p>



<p class="wp-block-paragraph">Additionally, CVE‑2026‑8716 corrects an incorrect name resolution behavior in pipelines that could allow access to CI data from a different ref type.</p>



<p class="wp-block-paragraph">CVE‑2026‑2710 ensures that blocked Project Access Tokens cannot access private resources via certain authentication endpoints.</p>



<p class="wp-block-paragraph">All of these flaws are remediated in versions 19.0.1, 18.11.4, and 18.10.7, which also bundle multiple stability and performance backports, including updates to <a href="https://cybersecuritynews.com/zlib-buffer-overflow-vulnerability/" target="_blank" rel="noreferrer noopener">zlib</a>, <a href="https://cybersecuritynews.com/nginx-poolslip-vulnerability/" target="_blank" rel="noreferrer noopener">nginx</a>, Mattermost, Elasticsearch indexer, and GitLab Shell.</p>



<p class="wp-block-paragraph">The updates do not introduce new database migrations and, in typical multi‑node deployments, can be rolled out without downtime when following <a href="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/" target="_blank" rel="noreferrer noopener nofollow">GitLab’s zero‑downtime guidance</a>.</p>



<p class="wp-block-paragraph">Organizations running affected versions are strongly advised to prioritize upgrades, monitor their instances for abuse of Duo AI or Wiki features, and align with GitLab’s published best practices for securing self‑managed deployments.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><b>Uncover Shadow APIs, close OWASP gaps </b>— <a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Join a Free Webinar</a> to secure every API at runtime.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/gitlab-patches-duo-ai-dos-flaws/">GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/GitLab-Patches-Multiple-Duo-AI-DoS-and-Authorization-Flaws-in-Community-and-Enterprise-Edition.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151336</post-id>	</item>
		<item>
		<title>Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others</title>
		<link>https://cybersecuritynews.com/pentest-swarm-ai-tool/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sat, 30 May 2026 12:00:55 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[CyberPedia]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151427</guid>

					<description><![CDATA[<p>Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. Developed by Armur AI, it gives security professionals live, coordinated access to the full offensive stack, including nmap, SQLMap, Burp Suite, ZAP, and Metasploit, all driven by an AI [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/pentest-swarm-ai-tool/">Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence.</p>



<p class="wp-block-paragraph">Developed by Armur AI, it gives security professionals live, coordinated access to the full offensive stack, including <a href="https://cybersecuritynews.com/nmap-7-96-released/" target="_blank" rel="noreferrer noopener">nmap</a>, <a href="https://cybersecuritynews.com/web-application-pentesting-tools/" target="_blank" rel="noreferrer noopener">SQLMap, Burp Suite, ZAP, and Metasploit</a>, all driven by an AI model of your choice.</p>



<h2 id="h-what-makes-it-a-true-swarm" class="wp-block-heading"><strong>What Makes It a True Swarm</strong></h2>



<p class="wp-block-paragraph">Most tools marketed as &#8220;multi-agent&#8221; are actually pipelines — a single planner LLM dispatching specialists in a predetermined order: recon → classify → exploit → report. Pentest Swarm AI breaks this mold with three swarm-intelligence primitives:</p>



<ul class="wp-block-list">
<li><strong>Stigmergy</strong> — agents coordinate by reading and writing findings to a shared PostgreSQL-backed blackboard (pgvector), not via a central planner. Each finding carries a <em>pheromone weight</em> that biases other agents toward high-value paths and decays over time, letting stale attack paths die naturally.</li>



<li><strong>Emergence</strong> — attack chains form without any agent prescribing them; a recon finding wakes the classifier, a high-severity CVE match triggers the exploit agent, and exploit results cycle back into the board.</li>



<li><strong>Decentralization</strong> — each agent runs its own trigger predicate, so adding or removing an agent requires no orchestrator rewrite.</li>
</ul>



<p class="wp-block-paragraph">The platform ships with eight ProjectDiscovery tools stable out of the box — <code>subfinder</code>, <code>httpx</code>, <code>nuclei</code>, <code>naabu</code>, <code>katana</code>, <code>dnsx</code>, <code>gau</code> — plus a fully parsed nmap XML adapter with scope validation. sqlmap, Burp MCP bridge, Metasploit, and ZAP adapters are queued for Wave 2 of the roadmap, making the platform progressively more powerful without requiring a platform overhaul.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8_9JHpCyNfqTh-nd-uskD4fGd8RfrcIzm73EAYfLMfgY_pmXeGOe95FomgceiYBxUmHy5DRM6htu-Gjccjn6_yJvCakMsLeFNzhNYpe4Lf7i1zEsVlHe1NclrK7sHHoliTWdnCzanMz-98LUoevjn5U3UJATa0xDi8EoVSTlAVp_AdFpsWEZ4WDkC4O8R/s16000/demo-flashy.gif" alt=""/></figure>



<p class="wp-block-paragraph">Getting started requires just one API key and one command:</p>



<pre class="wp-block-preformatted">bash<code>export PENTESTSWARM_ORCHESTRATOR_API_KEY=sk-ant-your-key-here
pentestswarm scan example.com --scope example.com --swarm --follow</code></pre>



<p class="wp-block-paragraph">It supports Claude (default, with prompt caching enabled for recon and classifier agents), Ollama for fully air-gapped local deployments, and any OpenAI-compatible model, giving teams the flexibility to balance cost, privacy, and capability. No GPU, no local model download required when using the cloud path.</p>



<p class="wp-block-paragraph">Every campaign produces submission-ready output across four formats Markdown, HTML, JSON, and SARIF queried directly from the blackboard by a dedicated report agent.</p>



<p class="wp-block-paragraph">Findings are automatically deduplicated, CVSS v3.1 scored per the FIRST specification, and scoped: the <code>--scope</code> flag is enforced both at the tool layer and the executor layer for defense-in-depth, making it safe for CI/CD pipelines and <a href="https://cybersecuritynews.com/bug-bounty-platforms/" target="_blank" rel="noreferrer noopener">bug-bounty programs</a>.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>Tool</th><th>Architecture</th><th>Executes</th><th>Memory</th><th>True Swarm</th></tr></thead><tbody><tr><td><strong>Pentest Swarm AI</strong></td><td>Stigmergic blackboard</td><td>Yes</td><td>pgvector + pheromones</td><td><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /></td></tr><tr><td><a href="https://cybersecuritynews.com/pentestgpt/" target="_blank" rel="noreferrer noopener">PentestGPT</a></td><td>Single-agent ReAct</td><td>Suggests</td><td>None</td><td><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/274c.png" alt="❌" class="wp-smiley" style="height: 1em; max-height: 1em;" /></td></tr><tr><td><a href="https://cybersecuritynews.com/pentagi-penetration-testing-tool/" target="_blank" rel="noreferrer noopener nofollow">PentAGI</a></td><td>4 agents + planner</td><td>Yes</td><td>pgvector</td><td>Pipeline only</td></tr><tr><td><a href="https://cybersecuritynews.com/hexstrike-ai/" target="_blank" rel="noreferrer noopener">HexStrike</a></td><td>MCP tool wrapper</td><td>Delegates</td><td>Stateless</td><td><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/274c.png" alt="❌" class="wp-smiley" style="height: 1em; max-height: 1em;" /></td></tr></tbody></table><figcaption class="wp-element-caption">Table based on Pentest Swarm AI Comparison</figcaption></figure>



<h2 id="h-github-actions-amp-mcp-integration" class="wp-block-heading"><strong>GitHub Actions &amp; MCP Integration</strong></h2>



<p class="wp-block-paragraph">A ready-made GitHub Action ships with SARIF output, enabling automated pentesting directly within any CI/CD workflow. The <code>pentestswarm mcp serve</code> command exposes the entire swarm as an <a href="https://cybersecuritynews.com/mcp-server/" target="_blank" rel="noreferrer noopener">MCP server</a>, integrating natively with Claude Desktop and Cursor for IDE-level offensive security testing.</p>



<p class="wp-block-paragraph">Licensed under AGPL-3.0, Pentest Swarm AI is free for red teams, bug-bounty hunters, and internal security pipelines, with the copyleft clause ensuring that any commercial SaaS fork must return improvements to the open-source community. The project is <a href="https://github.com/Armur-Ai/Pentest-Swarm-AI" target="_blank" rel="noreferrer noopener nofollow">available on GitHub</a>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><b>Uncover Shadow APIs, close OWASP gaps </b>— <a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Join a Free Webinar</a> to secure every API at runtime.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/pentest-swarm-ai-tool/">Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/Pentest-Swarm-AI-Tool.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151427</post-id>	</item>
		<item>
		<title>Google Chrome&#8217;s Device-Bound Session Credentials Now GA to Block Account Takeovers</title>
		<link>https://cybersecuritynews.com/chromes-device-bound-session-credentials/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sat, 30 May 2026 03:57:59 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151417</guid>

					<description><![CDATA[<p>Google has officially moved Device Bound Session Credentials (DBSC) to general availability in the Chrome browser on Windows, delivering a powerful defense against one of the most persistent threats in modern cybersecurity session cookie theft. Previously available in beta for Google Workspace users, DBSC is now enabled by default across all Workspace customers, Individual subscribers, [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/chromes-device-bound-session-credentials/">Google Chrome&#8217;s Device-Bound Session Credentials Now GA to Block Account Takeovers</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Google has officially moved Device Bound Session Credentials (DBSC) to general availability in the <a href="https://cybersecuritynews.com/151-chrome-vulnerabilities-patched/" target="_blank" rel="noreferrer noopener">Chrome browser on Windows</a>, delivering a powerful defense against one of the most persistent threats in modern cybersecurity session cookie theft.</p>



<p class="wp-block-paragraph">Previously available in beta for Google Workspace users, DBSC is now enabled by default across all Workspace customers, Individual subscribers, and personal Google accounts.</p>



<p class="wp-block-paragraph">Session cookies are small files websites use to remember authenticated users, but they&#8217;ve long been a lucrative target for threat actors. Malware families like infostealer trojans routinely harvest these cookies to hijack active sessions, <a href="https://cybersecuritynews.com/active-directory-authentication-bypass/" target="_blank" rel="noreferrer noopener">bypassing multi-factor authentication</a> entirely, a technique known as a pass-the-cookie attack.</p>



<p class="wp-block-paragraph">DBSC directly counters this threat by cryptographically binding a session cookie to the specific device the user authenticated from. Even if malware successfully exfiltrates a cookie from the compromised endpoint, that cookie becomes essentially useless on any other machine. This significantly raises the operational cost for attackers relying on stolen session tokens to maintain persistent access.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1lMbnirLuUwmceLpEuCMjYV1gJNXvHEIwPPaDKWsZ6B5bfECdpllWphdLOIMJuCIrgxw6eM1Y_Ed55aZUNSK0rSfiPcJb_601FfaXKpqvN5HTjuHTWfEzZXl_y81EyGm7isxVn4EJhqQqejQu7eXbXKKjs75hHkwdMyc7zD4y5UbQ_lS-XOLMBziP5Ket/s16000/Prevent%20account%20takeovers%20with%20Device%20.webp" alt=""/></figure>



<p class="wp-block-paragraph">Google has further amplified DBSC&#8217;s defensive value by integrating it with Context-Aware Access (CAA). Organizations leveraging both capabilities can enforce more granular access policies based on device attributes, user behavior, and environmental signals, adding an additional layer of verification beyond initial authentication.</p>



<p class="wp-block-paragraph">Workspace administrators can now monitor DBSC binding events directly through the security investigation tool&#8217;s audit logs, enabling security teams to detect anomalies and track session integrity across their environment.</p>



<p class="wp-block-paragraph">Notably, DBSC requires no administrative action to enable; it is active by default and cannot be disabled through the Admin console.</p>



<h2 id="h-rollout-timeline-and-availability" class="wp-block-heading"><strong>Rollout Timeline and Availability</strong></h2>



<p class="wp-block-paragraph"><a href="https://workspaceupdates.googleblog.com/2026/05/prevent-account-takeovers-with-DBSC-now-generally-available-in-the-Chrome-browser-for-Windows.html" target="_blank" rel="noreferrer noopener nofollow">Google began a gradual rollout on May 25, 2026</a>, covering both Rapid Release and Scheduled Release domains, with full feature visibility expected within 60 days. The feature is broadly available to:</p>



<ul class="wp-block-list">
<li>All Google Workspace customers</li>



<li>Workspace Individual subscribers</li>



<li>Users with personal Google accounts</li>
</ul>



<p class="wp-block-paragraph">DBSC represents a meaningful architectural shift in post-authentication security. Rather than relying solely on perimeter controls or MFA at login, it extends trust verification throughout the session lifecycle.</p>



<p class="wp-block-paragraph">For enterprise security teams, this reduces exposure to credential-based lateral movement and post-exploitation persistence techniques commonly used by advanced threat actors.</p>



<p class="wp-block-paragraph">Security teams are encouraged to review audit logs within the Google Admin console to baseline normal DBSC binding behavior and flag any deviations that may indicate active session hijacking attempts.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP </strong></p>
<p>The post <a href="https://cybersecuritynews.com/chromes-device-bound-session-credentials/">Google Chrome&#8217;s Device-Bound Session Credentials Now GA to Block Account Takeovers</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/Chromes-Device-Bound-Session-Credentials.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151417</post-id>	</item>
		<item>
		<title>GREYVIBE Hackers Leverage ChatGPT and Google Gemini to Fuel Cyberattacks</title>
		<link>https://cybersecuritynews.com/greyvibe-hackers-chatgpt-and-google-gemini/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Sat, 30 May 2026 03:37:31 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151355</guid>

					<description><![CDATA[<p>GREYVIBE hackers are increasingly leveraging generative AI tools such as ChatGPT and Google Gemini to enhance cyberattack operations. The campaign, active since at least August 2025, primarily targets Ukraine and related entities across the government, military, and civilian sectors, highlighting a growing convergence between artificial intelligence and modern cyber warfare. WithSecure researchers identified GREYVIBE as [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/greyvibe-hackers-chatgpt-and-google-gemini/">GREYVIBE Hackers Leverage ChatGPT and Google Gemini to Fuel Cyberattacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">GREYVIBE hackers are increasingly leveraging generative AI tools such as<a href="https://cybersecuritynews.com/single-line-of-code-can-jailbreak-11-ai-models/" target="_blank" rel="noreferrer noopener"> ChatGPT and Google Gemini</a> to enhance cyberattack operations.</p>



<p class="wp-block-paragraph">The campaign, active since at least August 2025, primarily targets Ukraine and related entities across the government, military, and civilian sectors, highlighting a growing convergence between artificial intelligence and modern cyber warfare.</p>



<p class="wp-block-paragraph">WithSecure researchers identified GREYVIBE as a previously untracked threat group exhibiting consistent overlaps in infrastructure, tooling, and operational behavior across multiple campaigns.</p>



<p class="wp-block-paragraph">While no definitive attribution has been established, the group’s activities strongly align with Russian state interests, particularly intelligence-gathering objectives linked to the ongoing Russia-Ukraine conflict.</p>



<p class="wp-block-paragraph">Supporting evidence includes Russian-language artifacts, Moscow time zone activity patterns, and targeting aligned with Ukrainian institutions.</p>



<h2 id="h-greyvibe-abuses-chatgpt-gemini-ai" class="wp-block-heading"><strong>GREYVIBE Abuses ChatGPT, Gemini AI</strong></h2>



<p class="wp-block-paragraph">GREYVIBE employs a multi-vector attack strategy, combining<a href="https://cybersecuritynews.com/chatgpt-malware-and-phishing/" target="_blank" rel="noreferrer noopener"> spear-phishing emails</a>, fake CAPTCHA verification pages, and fraudulent websites to distribute malware.</p>



<p class="wp-block-paragraph">In spear-phishing campaigns, attackers impersonate Ukrainian government agencies and distribute malicious archives via cloud services such as Google Drive.</p>



<p class="wp-block-paragraph">These payloads execute decoy documents while silently initiating infection chains using custom loaders.</p>



<p class="wp-block-paragraph">Another notable tactic involves <a href="https://cybersecuritynews.com/lumma-stealer-exploits-fake-captcha-pages/" target="_blank" rel="noreferrer noopener">fake CAPTCHA pages</a> designed to trick victims into executing malicious commands under the guise of verification steps.</p>



<p class="wp-block-paragraph">Additionally, the group operates deceptive “adult club” websites targeting Ukrainian individuals, particularly military personnel.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj98usJCuWmAfBtJ9doHuoE4ulbzoF9-Tmz47JOP2SpSaLF3qR2TCJ4SaE4WcG-Wdi6UfvSSOpaPNKF9bT7L4KRLUJ5zSH_2Z4yRcf4dfQJeUAb6j2BZVbKkSxA4rtPUHstNTqloyQUPkcpMEjdWw6jOp2NyYCDoVPbyxHIFt26AqWkJEvbNH3vU-4XSq0/s1600/Screenshot%202026-05-29%20173220%20%281%29.webp" alt=" Example of fake captcha site and prompted instructions (Ukrainian)(source : withsecure labs)"/><figcaption class="wp-element-caption"> Example of fake captcha site and prompted instructions (Ukrainian) (Source: Withsecure labs)</figcaption></figure>



<p class="wp-block-paragraph">These platforms not only deliver malware such as FallSpy for Android and PhantomRelay for Windows, but also engage in social engineering through fake personas on messaging platforms like Telegram.</p>



<p class="wp-block-paragraph">A key finding in the report is GREYVIBE’s systematic use of generative AI across the attack lifecycle.</p>



<p class="wp-block-paragraph">Tools such as ChatGPT, Google Gemini, and Ideogram AI were reportedly used to generate phishing lures, develop malware components, and support post-compromise activities.</p>



<p class="wp-block-paragraph">Researchers observed AI-generated code patterns in obfuscators and loaders such as DAYLIGHT and TEASOUP, as well as in the development of LegionRelay, a custom <a href="https://cybersecuritynews.com/beware-of-weaponized-screenconnect-app/" target="_blank" rel="noreferrer noopener">PowerShell-based remote access trojan</a>.</p>



<p class="wp-block-paragraph">This AI-assisted approach appears to help the group compensate for limited technical sophistication while accelerating development cycles.</p>



<p class="wp-block-paragraph">It also reduces reliance on reused code, making traditional attribution methods more difficult. However, the group’s reliance on AI has introduced flaws.</p>



<p class="wp-block-paragraph"><a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noreferrer noopener nofollow">WithSecure identified</a> design weaknesses in LegionRelay that exposed backend functionality, enabling researchers to monitor attacker activity over time.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmJuK_FLIJTrAlXn9z9hFN_HW0WrxW7uWtnee6jqAtWy9dDRLHk9yrbVMs7-swTMXXabyGzVcd44uyTQQiXGWGmBCIah4Aux5l2Q8gOAccOhyphenhyphenEYDQn3GrldJG7jXsz_7M4j4Z1-vxiIIX4PGtcnR4AFk29X_8YiJoeXpJBVsCczEF7op-Y99HdnKAdcSs/s1600/Screenshot%202026-05-29%20173133%20%281%29.webp" alt=" Examples of LLM markers present across images used by GREYVIBE (source : withsecure labs)"/><figcaption class="wp-element-caption"> Examples of LLM markers present across images used by GREYVIBE (Source: Withsecure labs)</figcaption></figure>



<p class="wp-block-paragraph">GREYVIBE’s malware toolkit includes PhantomRelay, a modular RAT that uses WebSockets for command execution, and FallSpy, an Android spyware that exfiltrates sensitive data, including contacts, location, and device information.</p>



<p class="wp-block-paragraph">LegionRelay further extends its capabilities by enabling file theft, screenshot capture, and exfiltration of messaging data.</p>



<p class="wp-block-paragraph">Despite its effectiveness, GREYVIBE demonstrates signs of operational immaturity. Researchers noted poor operational security practices, including uploading test samples to public platforms and inconsistent tooling.</p>



<p class="wp-block-paragraph">At the same time, overlaps with known cybercrime infrastructure suggest possible links to former or active cybercriminal actors, indicating a hybrid threat model.</p>



<p class="wp-block-paragraph">The emergence of GREYVIBE underscores how generative AI is reshaping the threat landscape. By lowering technical barriers and enabling rapid tool development, AI is empowering even moderately skilled actors to conduct complex cyber operations, complicating detection, attribution, and defense efforts.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/greyvibe-hackers-chatgpt-and-google-gemini/">GREYVIBE Hackers Leverage ChatGPT and Google Gemini to Fuel Cyberattacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/GREYVIBE-hackers-Leverage-ChatGPT-and-Google-Gemini-to-Fuel-Cyberattacks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151355</post-id>	</item>
		<item>
		<title>Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild</title>
		<link>https://cybersecuritynews.com/palo-alto-vulnerability-exploited/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sat, 30 May 2026 02:45:22 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151405</guid>

					<description><![CDATA[<p>Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory on May 13, 2026, warning that CVE-2026-0257 enables a remote unauthenticated attacker to [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/palo-alto-vulnerability-exploited/">Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026.</p>



<p class="wp-block-paragraph">Palo Alto Networks published its security advisory on May 13, 2026, warning that CVE-2026-0257 enables a remote unauthenticated attacker to forge authentication override cookies and establish <a href="https://cybersecuritynews.com/octalyn-stealer-steals-vpn-configurations/" target="_blank" rel="noreferrer noopener">unauthorized VPN connections</a> through the GlobalProtect gateway.</p>



<p class="wp-block-paragraph">The vulnerability exists in a non-default feature called &#8220;authentication override,&#8221; which allows GlobalProtect portals and gateways to issue session cookies to authenticated users similar to a bearer token, so users don&#8217;t need to re-authenticate each session.</p>



<p class="wp-block-paragraph">The flaw is triggered only when the certificate used to encrypt and decrypt these authentication override cookies is shared with another feature, such as the HTTPS service of the portal or gateway.</p>



<p class="wp-block-paragraph">Because the decryption process in the <code>/usr/local/bin/gpsvc</code> binary performs no signature verification after decrypting the cookie, any attacker who can retrieve the public key from the exposed HTTPS certificate can forge a valid authentication cookie and bypass authentication entirely.</p>



<p class="wp-block-paragraph"><a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/" target="_blank" rel="noreferrer noopener nofollow">Rapid7 has identified the earliest exploitation</a> on May 17, 2026, with a first wave of attacks originating from IPs hosted on Vultr. On May 18, Rapid7 detected suspicious cookie-based authentication to local admin accounts across multiple customer environments.</p>



<p class="wp-block-paragraph">The attacker used the machine name <code>GP-CLIENT</code> and a spoofed MAC address (<code>aa:bb:cc:dd:ee:ff</code>) to masquerade as a legitimate endpoint.</p>



<p class="wp-block-paragraph">A second exploitation wave occurred on May 21, 2026, this time originating from the hosting provider Dromatics Systems, using machine name <code>DESKTOP-GP01</code>.</p>



<p class="wp-block-paragraph">In this wave, some victims had full VPN IP assignments granted after the cookie authentication, giving attackers direct access to internal networks. Across both waves, the consistent spoofed MAC address suggests a single threat actor behind both campaigns. Notably, 8 out of 10 impacted MDR customers saw only authentication probes, not full VPN session establishment.</p>



<h2 id="h-indicators-of-compromise" class="wp-block-heading"><strong>Indicators of Compromise</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>Indicator</th><th>Type</th></tr></thead><tbody><tr><td><code>104.207.144.154</code></td><td>Threat actor source IP (Wave 1)</td></tr><tr><td><code>146.19.216.119 / .120 / .125</code></td><td>Threat actor source IPs (Wave 2)</td></tr><tr><td><code>aa:bb:cc:dd:ee:ff</code></td><td>Spoofed MAC address (both waves)</td></tr><tr><td><code>GP-CLIENT</code></td><td>Machine name, Linux auth, May 17</td></tr><tr><td><code>DESKTOP-GP01</code></td><td>Machine name, Windows auth, May 21</td></tr></tbody></table><figcaption class="wp-element-caption"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</figcaption></figure>



<p class="wp-block-paragraph"><a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank" rel="noreferrer noopener">Organizations must upgrade to patched versions</a> immediately. Key fixed versions include PAN-OS 12.1.4-h6 / 12.1.7, PAN-OS 11.2.12, PAN-OS 11.1.15, and PAN-OS 10.2.18-h6, among others. Prisma Access 11.2.0 requires 11.2.7-h13 or later, and Prisma Access 10.2.0 requires 10.2.10-h36 or later.</p>



<h2 id="h-mitigations" class="wp-block-heading"><strong>Mitigations</strong></h2>



<p class="wp-block-paragraph">Organizations should take the following actions immediately:</p>



<ul class="wp-block-list">
<li>Upgrade all affected PAN-OS and Prisma Access instances to vendor-patched versions</li>



<li>Disable the authentication override feature if not operationally required</li>



<li>Generate a dedicated certificate exclusively for authentication override cookie encryption — never share it with the HTTPS service</li>



<li>Hunt for IOCs listed above across VPN and GlobalProtect authentication logs</li>



<li>Deploy detection rules available for InsightIDR/MDR: including &#8220;Suspicious Authentication – Palo Alto GlobalProtect Cookie Authentication to Local Admin Account&#8221;</li>
</ul>



<p class="wp-block-paragraph">Despite its medium CVSSv4 score, Rapid7 urges organizations to treat CVE-2026-0257 as a critical-priority vulnerability. An authentication bypass on an internet-facing enterprise VPN appliance represents a significant initial access vector, and with active exploitation confirmed and a public proof-of-concept script now available, the window for safe remediation is closing fast.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><b>Uncover Shadow APIs, close OWASP gaps </b>— <a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Join a Free Webinar</a> to secure every API at runtime.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/palo-alto-vulnerability-exploited/">Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/Palo-Alto-Vulnerability-Exploited.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151405</post-id>	</item>
		<item>
		<title>Post-quantum cryptography is not the future. It is your current reality.  </title>
		<link>https://cybersecuritynews.com/post-quantum-cryptography-is-not-the-future-it-is-your-current-reality/</link>
		
		<dc:creator><![CDATA[Kavichselvan]]></dc:creator>
		<pubDate>Fri, 29 May 2026 16:04:38 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151397</guid>

					<description><![CDATA[<p>For most of the last decade, post-quantum cryptography lived in a particular kind of conversation. It came up at security conferences. It appeared in NIST press releases. CISOs nodded politely when it surfaced in briefings, filed it under &#8220;things to deal with eventually,&#8221; and moved on to the quarter&#8217;s actual fires.&#160; That conversation is over. [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/post-quantum-cryptography-is-not-the-future-it-is-your-current-reality/">Post-quantum cryptography is not the future. It is your current reality.  </a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">For most of the last decade, post-quantum cryptography lived in a particular kind of conversation. It came up at security conferences. It appeared in NIST press releases. CISOs nodded politely when it surfaced in briefings, filed it under &#8220;things to deal with eventually,&#8221; and moved on to the quarter&#8217;s actual fires.&nbsp;</p>



<p class="wp-block-paragraph">That conversation is over. It ended this week.&nbsp;</p>



<p class="wp-block-paragraph">In the span of a few days, five separate signals landed. Each on its own is significant. Together, they are impossible to ignore. Western Digital announced PQC support in its product line. CNN ran a primetime segment on the quantum threat. The U.S. government committed roughly two billion dollars toward quantum computing initiatives. </p>



<p class="wp-block-paragraph">Reports surfaced of an executive order accelerating federal PQC adoption. And Apple publicly endorsed ML-KEM and ML-DSA, the NIST-finalized post-quantum algorithms, for protecting iMessage. </p>



<p class="wp-block-paragraph">Pick any one of those in isolation,&nbsp;and&nbsp;it&#8217;s&nbsp;notable. Stack them on the same week,&nbsp;and&nbsp;they&#8217;re&nbsp;a pattern. The companies, governments, and infrastructure providers who&nbsp;actually run&nbsp;the world&#8217;s encryption are not waiting anymore. They are building, shipping, and deploying.&nbsp;</p>



<p class="wp-block-paragraph">The question for everyone reading this is no longer whether post-quantum cryptography matters.&nbsp;It&#8217;s&nbsp;whether your organization is moving with the industry or quietly drifting behind it.&nbsp;</p>



<h2 id="h-the-two-threats-that-nbsp-don-t-nbsp-need-a-quantum-computer-nbsp" class="wp-block-heading"><strong>The two threats that&nbsp;don&#8217;t&nbsp;need a quantum computer</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The most expensive misconception in PQC strategy is the assumption that nothing bad happens until a cryptographically relevant quantum computer exists. That framing makes the threat feel distant, which makes it easy to defer, which is exactly why so many programs are still in planning instead of execution.&nbsp;</p>



<p class="wp-block-paragraph">Two threats are already active today, and neither one requires a working quantum computer to do damage.&nbsp;</p>



<p class="wp-block-paragraph">The first is Harvest Now, Decrypt Later, or HNDL. Adversaries, nation-states in particular, are intercepting and storing encrypted traffic right now. They don&#8217;t need to read it today. They need to read it in 2030, or 2035, or whenever a sufficiently powerful quantum computer comes online. Storage is cheap. Patience is free. </p>



<p class="wp-block-paragraph">The encryption protecting your VPN traffic, your TLS-secured APIs, and your long-lived sensitive communications becomes retroactively breakable the moment that hardware exists. For any data that needs to stay confidential for ten years or more (healthcare records, financial archives, intellectual property, government communications), the exposure window has already opened. </p>



<p class="wp-block-paragraph">The second is Trust Now, Forge Later, or TNFL. This is the integrity side of the same problem. Digital signatures that establish trust today, including root CA keys, code-signing keys, firmware signatures, and certificate hierarchies, can be forged retroactively once quantum capability arrives. </p>



<p class="wp-block-paragraph">The thing being attacked isn&#8217;t confidentiality. Its authenticity. Software supply chains, identity systems, secure boot, legal signatures, all of it depends on signatures whose security assumptions are quietly aging. </p>



<p class="wp-block-paragraph">Neither threat is theoretical. Both are operational right now. And both are why the organizations leading on PQC are not waiting for hardware to exist before they act.&nbsp;</p>



<h2 id="h-the-visibility-problem-nobody-is-talking-about-nbsp" class="wp-block-heading"><strong>The visibility problem nobody is talking about</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Here is the part that&nbsp;doesn&#8217;t&nbsp;make it into the headlines.&nbsp;</p>



<p class="wp-block-paragraph">When organizations finally do start their PQC programs, they&nbsp;almost always&nbsp;run into the same wall. Not algorithm selection. Not vendor support. Not budget. The wall is&nbsp;visible.&nbsp;</p>



<p class="wp-block-paragraph">Cryptography in a modern enterprise lives in six places at once, and most of them are not on anyone&#8217;s map. There is the application layer, where legacy systems hardcode RSA and ECC implementations that nobody on the current team built. There is the infrastructure layer (load balancers, VPN gateways, SSH endpoints), where deprecated cipher suites and long-lived keys often have no documented owner. </p>



<p class="wp-block-paragraph">There is cloud and SaaS, where the cryptographic boundary frequently lives outside the customer&#8217;s direct control. There is OT and IoT, where firmware-level cryptography can be operational for fifteen or twenty years without ever being upgraded. </p>



<p class="wp-block-paragraph">There is the PKI layer, where root and issuing CAs anchor trust for the entire organization. And there is the third-party and supply-chain layer, where vendors choose algorithms on your behalf and rarely tell you what they picked. </p>



<p class="wp-block-paragraph">When you&nbsp;actually run&nbsp;discovery against an enterprise environment, the findings are&nbsp;almost always&nbsp;the same. RSA-1024 running in production on services nobody&nbsp;maintains. Certificates with ten-year validity periods&nbsp;were issued before the&nbsp;current governance existed. Cryptographic keys hardcoded into application configs and CI/CD pipelines, with no rotation history and no dependency map. Third-party integrations using algorithms&nbsp;that&nbsp;the security team has no contractual right to audit.&nbsp;</p>



<p class="wp-block-paragraph">You cannot migrate cryptography you cannot see. You cannot prioritize what you have not inventoried. And you cannot defend a posture you cannot describe to your board.&nbsp;</p>



<h2 id="h-the-sequence-that-nbsp-actually-works-nbsp" class="wp-block-heading"><strong>The sequence that&nbsp;actually works</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The most consistent pattern across industries and organization sizes is that PQC programs fail in&nbsp;roughly the&nbsp;same way. They start with algorithm selection. They pick a pilot system. They get a small proof of concept working. And then they hit the wall of&nbsp;trying to scale that pilot across thousands of systems,&nbsp;they&nbsp;don&#8217;t&nbsp;have a complete inventory of.&nbsp;</p>



<p class="wp-block-paragraph">The sequence that works runs in the opposite direction.&nbsp;</p>



<p class="wp-block-paragraph">It starts with a Cryptography Bill of Materials, or CBOM. This is a live, continuously updated inventory of every cryptographic asset across the enterprise: algorithms, key lengths, certificates, libraries, protocols, ownership, business criticality. Not a one-time spreadsheet that goes stale within weeks. Operational infrastructure that stays current as your environment changes.&nbsp;</p>



<p class="wp-block-paragraph">With a CBOM in place, the second phase becomes possible: crypto-agility. This is the architectural property that lets you swap algorithms without rebuilding systems, deploy hybrid classical-plus-PQC key exchange without breaking compatibility, automate certificate lifecycle operations at enterprise scale, and migrate in phases instead of all at once. Crypto-agility does not replace your infrastructure. It is a capability layered on top of it.&nbsp;</p>



<p class="wp-block-paragraph">Once both are in place, the third phase, prioritization, becomes a rational exercise instead of a guessing game. Score every asset on three axes: algorithm vulnerability, data longevity, and business criticality. The intersection tells you what migrates&nbsp;immediately, what migrates in the next twelve to eighteen months, and what stays under continuous monitoring.&nbsp;</p>



<p class="wp-block-paragraph">Skip the inventory step, and everything downstream becomes guesswork. You make architectural decisions on incomplete information. You execute migration waves and discover dependencies mid-deployment. You spend resources on the wrong assets in the wrong order. The sequence is non-negotiable: inventory first, then agility, then prioritization.&nbsp;</p>



<h2 id="h-why-this-matters-now-specifically-nbsp" class="wp-block-heading"><strong>Why this matters now, specifically</strong>&nbsp;</h2>



<p class="wp-block-paragraph">NIST finalized the first three PQC standards in August 2024: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). That moment changed PQC from research to deployable engineering. Within months, organizations like Cloudflare, Google, Apple, Akamai, AWS, and Microsoft began shipping production deployments. </p>



<p class="wp-block-paragraph">Chrome made ML-KEM the default key exchange. Apple&#8217;s PQ3 protocol moved iMessage to hybrid ML-KEM ratcheting. Google set an internal target to complete its PQC migration by 2029. Cloudflare reports that over half of human internet traffic now runs through post-quantum key agreement. </p>



<p class="wp-block-paragraph">Behind those deployments, the regulatory floor is rising. CNSA 2.0 enforces PQC signing requirements for new National Security Systems acquisitions starting in 2027. NIST has signalled the deprecation of RSA and ECC after 2030. </p>



<p class="wp-block-paragraph">The September 2026 transition of legacy FIPS 140-2 validations to the historical list creates a convergence point: organizations modernizing to FIPS 140-3 are doing it under the same engineering load as the PQC migration itself. </p>



<p class="wp-block-paragraph">What this means in practice: organizations that started foundational work (the CBOM, the vendor conversations, the hardware assessments) in 2024 and 2025 are now executing migrations. Organizations starting that work today are still on the bridge. Both can get to the other side. The runway is different.&nbsp;</p>



<h2 id="h-what-the-visibility-layer-nbsp-actually-looks-nbsp-like-nbsp" class="wp-block-heading"><strong>What the visibility layer&nbsp;actually looks&nbsp;like</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This is where CBOM Secure fits&nbsp;into&nbsp;the conversation. It is the cryptographic posture management platform Encryption Consulting built specifically for this problem: the visibility gap that sits underneath every PQC program, every compliance audit, and every certificate lifecycle automation initiative.&nbsp;</p>



<p class="wp-block-paragraph">The platform runs nineteen production discovery sensors across the layers where cryptography actually lives. Cloud KMS (AWS, Azure, GCP). HSM APIs including Entrust nCipher, Thales Luna, IBM 4767/4768/4769, Yubico YubiHSM 2, and Fortanix DSM. KMIP servers, versions 1.0 through 2.1. Database TDE. Source code across seven languages. </p>



<p class="wp-block-paragraph">OS trust stores. Active Directory, LDAP, HashiCorp Vault, and the major filesystem formats. Everything normalizes into a single CBOM-compliant inventory exported in CycloneDX format. Every asset gets a risk score. Quantum-vulnerable cryptography is flagged automatically. Audit evidence for NIST SP 800-131A, FIPS 140-3, CNSA 2.0, CMMC 2.0, PCI DSS 4.0, and FedRAMP comes out of the same dataset, on demand. </p>



<p class="wp-block-paragraph">The pattern most organizations adopt: start with the CBOM, because without visibility,&nbsp;everything downstream is guesswork, and build from what the inventory reveals. The certificate automation, the PQC migration planning,&nbsp;and&nbsp;the compliance reporting all run off the same source of truth.&nbsp;</p>



<h2 id="h-what-path-is-your-organization-on-nbsp" class="wp-block-heading"><strong>What path is your organization on?</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This is the question worth taking back to your team this week.&nbsp;</p>



<p class="wp-block-paragraph">The headlines&nbsp;aren&#8217;t&nbsp;going to slow down. Western Digital, CNN, the U.S. government, the executive branch,&nbsp;and&nbsp;Apple. That was one week. There will be another week like it, and another after that. Every one of those announcements compresses the timeline for organizations that&nbsp;haven&#8217;t&nbsp;started, and&nbsp;widens the gap for organizations that have.&nbsp;</p>



<p class="wp-block-paragraph">There are roughly three paths from here. The first is to start the foundational work now. Build the CBOM. Identify the assets with the longest lead times. Begin the hybrid deployment conversations with vendors. Treat crypto-agility as an operating model rather than a project. </p>



<p class="wp-block-paragraph">The second is to wait one more quarter, one more budget cycle, one more strategic planning meeting, and start the same work later under more pressure. The third is to do nothing and discover, somewhere around 2028 or 2029, that the migration window has narrowed faster than the program can execute. </p>



<p class="wp-block-paragraph">Organizations on path one&nbsp;are&nbsp;building cryptographic agility&nbsp;by&nbsp;the way they push configuration updates. Organizations on path two are still buying themselves time. Organizations on path three are building a gap that compounds every quarter.&nbsp;</p>



<p class="wp-block-paragraph">The technology is ready. The standards are&nbsp;finalized. The deployments are happening at scale, in production, this week.&nbsp;</p>



<p class="wp-block-paragraph">What path is your organization on?&nbsp;</p>



<p class="wp-block-paragraph"><em>Encryption Consulting builds CBOM Secure, the cryptographic posture management platform behind the inventory layer described in this article. To see how a continuously updated CBOM maps against your environment, visit&nbsp;</em><a href="http://www.encryptionconsulting.com/" target="_blank" rel="noreferrer noopener"><em>www.encryptionconsulting.com</em></a><em>&nbsp;or reach out at&nbsp;</em><a href="mailto:info@encryptionconsulting.com" target="_blank" rel="noreferrer noopener"><em>info@encryptionconsulting.com</em></a><em>.</em>&nbsp;</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/post-quantum-cryptography-is-not-the-future-it-is-your-current-reality/">Post-quantum cryptography is not the future. It is your current reality.  </a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihK-YB_jGp7qGswbL4NUoF2Hts0C8708zmjlWTbnmaSfJc57gINFfjG-17ugbn9iK-VoUSrrnUHD80Hg1e6yyukD9p2eue8yKEkjgVTIsNDEOQ47DYqKRQSwFVUM0BACUJfJp_Ji-zR7MJQMAfyUAJAnDhThw5KDUum6tjtDAVECtnhI_NypYENKxkyHc/s16000/TTT%20-%202026-05-29T213542.225.webp?ssl=1" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151397</post-id>	</item>
		<item>
		<title>Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges</title>
		<link>https://cybersecuritynews.com/ransomware-uses-system-scheduled-task/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 29 May 2026 15:59:05 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151380</guid>

					<description><![CDATA[<p>A newly analyzed ransomware strain called The Gentlemen is raising serious alarms across the cybersecurity community. Built in the Go programming language and obfuscated with a tool called Garble, it combines powerful per-file encryption with an aggressive ability to spread itself silently across entire networks without any human intervention. Organizations in education, healthcare, transportation, and [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/ransomware-uses-system-scheduled-task/">Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly analyzed ransomware strain called The Gentlemen is raising serious alarms across the cybersecurity community. </p>



<p class="wp-block-paragraph">Built in the Go programming language and obfuscated with a tool called Garble, it combines powerful per-file encryption with an aggressive ability to spread itself silently across entire networks without any human intervention. </p>



<p class="wp-block-paragraph">Organizations in education, healthcare, transportation, and finance across North America, South America, Europe, Africa, and Asia have already felt its damaging impact.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The Gentlemen operates as a ransomware-as-a-service (RaaS) platform, meaning its core developers rent access to the malware to other criminals known as affiliates. </p>



<p class="wp-block-paragraph">It first emerged around mid-2025 as a closed group, then opened its doors to affiliates in September 2025. </p>



<p class="wp-block-paragraph">More recently, its operators forged a formal partnership with BreachForums, a well-known cybercriminal marketplace, actively recruiting penetration testers and initial access brokers to carry out attacks on their behalf.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Microsoft Threat Intelligence, which tracks the group behind the malware as Storm-2697, noted that the operators use double extortion tactics. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbZBwjYdUW5j13TWQ_uDLbBTGMWLpiz3pozrz1Szl11CFKOJ6C0B0wzZA0hm3DIgvNVD4Vu26MvTEMs89UJ3v1Fykppl_6BL4ufUbmqBmTgR1NECdClFveZIP2B64jElneRAYr_EbxmVF_xmPg43nUdLOJPvfpAOWiiBfeCf-j_Kqf75z82k9prqHa3Gs/s16000/Encryption%20mode%20command-line%20arguments%20(Source%20-%20Microsoft).webp" alt="Encryption mode command-line arguments (Source - Microsoft)" /><figcaption class="wp-element-caption">Encryption mode command-line arguments (Source &#8211; Microsoft)</figcaption></figure>
</div>


<p class="wp-block-paragraph">They encrypt a <a href="https://cybersecuritynews.com/hackers-weaponizing-svg-files-to-deliver-pureminer-malware/" id="128209" target="_blank" rel="noreferrer noopener">victim&#8217;s data and simultaneously steal sensitive files</a>, threatening to release the stolen information publicly if the ransom is not paid. </p>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/" id="https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/" target="_blank" rel="noreferrer noopener nofollow">Microsoft said in a report</a> shared with Cyber Security News (CSN) that the threat is already widely adopted and this new partnership could attract an even broader pool of criminal actors going forward.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What sets The Gentlemen apart is its layered attack strategy. It disables antivirus tools, deletes backups, clears system logs, and wipes forensic traces before encryption even begins. </p>



<p class="wp-block-paragraph">Once active, it can reach across a network and plant itself on other machines automatically, making containment far more difficult for incident responders and security teams.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The ransomware requires a build-specific password to execute, and operators can control nearly every aspect of its behavior through command-line arguments. </p>



<p class="wp-block-paragraph">These options include setting encryption speed, enabling network spreading, and choosing how the malware persists after a reboot. That level of operational control makes it unusually flexible and customizable for a criminal tool deployed at scale.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-ransomware-uses-system-scheduled-task" class="wp-block-heading"><strong>Ransomware Uses SYSTEM Scheduled Task</strong></h2>



<p class="wp-block-paragraph">One of the most technically notable behaviors in The Gentlemen is how it achieves the highest possible system privileges before encrypting local drives. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiebL8YrJvauSOa1_OX9mDpirrk9oA1VsLecFW-UryYxcAR5p0Gtg6lN5DFt2BcGOcKlbvm4F9a_3YxI15wl2uCKWlMNvPNIjI4vDaymGOU4ZMmwHabL9Y0AqvYbB0eF79PFmrZCCObH10ufeW27Fl0rNL4NQUFH62ybpvHrWXBJQbG1pnYrYp22MK_ZJw/s16000/The%20Gentlemen%20ransomware%E2%80%99s%20persistence%20mechanism%20(Source%20-%20Microsoft).webp" alt="The Gentlemen ransomware’s persistence mechanism (Source - Microsoft)" /><figcaption class="wp-element-caption">The Gentlemen ransomware’s persistence mechanism (Source &#8211; Microsoft)</figcaption></figure>
</div>


<p class="wp-block-paragraph">When the <a href="https://cybersecuritynews.com/wanttocry-ransomware-abuses-smb-services/" id="150538" target="_blank" rel="noreferrer noopener">ransomware receives the right command-line instruction</a>, it creates a Windows scheduled task named <code>gentlemen_system</code> that runs the malware executable under the SYSTEM account, which is the most powerful level of access on a Windows machine.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">To do this cleanly, it first deletes any existing task with that name, then registers and immediately triggers a fresh one. Once running under this elevated context, the malware sets an internal environment variable called <code>LOCKER_BACKGROUND=1</code> to signal that it is operating as a background encryption process with full privileges. </p>



<p class="wp-block-paragraph">This design allows the ransomware to reach and encrypt files that would otherwise be protected or inaccessible to standard user-level accounts.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-self-propagation-across-the-network" class="wp-block-heading"><strong>Self-Propagation Across the Network</strong></h2>



<p class="wp-block-paragraph">The Gentlemen does not stop at a single machine. When its spreading feature is activated, it transforms into a self-propagating worm capable of deploying itself to every system it can reach on the local network. </p>



<p class="wp-block-paragraph">It stages its own binary in a shared folder, copies it across administrative network shares, and attempts to execute it on remote hosts using eight different methods simultaneously.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/beyondtrust-privilege-management-for-windows/" id="118733" target="_blank" rel="noreferrer noopener">These methods include PsExec, Windows Management Instrumentation</a>, scheduled tasks in both user and SYSTEM contexts, Windows services, and PowerShell remoting. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEYPfRIlfuUr-zl2lPK1g8Qbkjyxplmx22BV-qO1SfqMyV3o3rzIaAY_TKCa4MADLg_yPhleEQq0Wg8JXjFELiiVkenh5AA3OUevQFwbMhFSB0Ji_TS910x9kMV4YU3GjGwMU3T93j6n0ppW5yVvdAWH9762iIUH1rto__l_Pg1sZaa4J56HKNRE6Sofc/s16000/The%20Gentlemen%20ransomware%E2%80%99s%20file%20encryption%20mechanism%20(Source%20-%20Microsoft).webp" alt="The Gentlemen ransomware’s file encryption mechanism (Source - Microsoft)" /><figcaption class="wp-element-caption">The Gentlemen ransomware’s file encryption mechanism (Source &#8211; Microsoft)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The malware attempts 21 separate remote execution operations per target host. This redundancy is central to its strategy because even if most methods are blocked, a single successful execution on one new host is enough to restart the entire propagation cycle.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Defenders can reduce exposure by enabling controlled folder access, turning on cloud-delivered antivirus protection, and blocking process creations originating from PsExec and WMI commands through attack surface reduction rules. </p>



<p class="wp-block-paragraph">Running endpoint detection and response tools in block mode is also strongly recommended, as is configuring automatic attack disruption to contain active threats before they spread further across the environment.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>SHA-256</td><td><code>22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67</code></td><td>The Gentlemen ransomware encryptor binary&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>File Name</td><td><code>README-GENTLEMEN.txt</code></td><td>Ransom note dropped in each encrypted directory&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>File Extension</td><td><code>.umc16h</code></td><td>Extension appended to all encrypted files&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>File Name</td><td><code>gentlemen.bmp</code></td><td>Desktop wallpaper bitmap dropped to %TEMP% after encryption&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Scheduled Task Name</td><td><code>gentlemen_system</code></td><td>SYSTEM-privileged scheduled task created for elevated encryption&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Scheduled Task Name</td><td><code>UpdateSystem</code></td><td>Persistence scheduled task running payload as SYSTEM at startup&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Scheduled Task Name</td><td><code>UpdateUser</code></td><td>Persistence scheduled task running payload as current user at startup&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Registry Key Value</td><td><code>GupdateS</code>&nbsp;(HKLM)</td><td>System-wide autorun registry persistence key&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Registry Key Value</td><td><code>GupdateU</code>&nbsp;(HKCU)</td><td>User-scoped autorun registry persistence key&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>File Path</td><td><code>C:\Temp\psexec.exe</code></td><td>PsExec binary dropped for lateral movement&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>File Name</td><td><code>wipefile.tmp</code></td><td>Temporary file used for free disk space wiping&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Environment Variable</td><td><code>LOCKER_BACKGROUND=1</code></td><td>Internal flag indicating SYSTEM-context background encryption execution&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr><tr><td>Hardcoded Password</td><td><code>9VoAvR7G</code></td><td>Build-specific operator authentication password embedded in analyzed sample&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/df5cadfe-ebc6-487a-a745-283dbcc8876d/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.pdf?AWSAccessKeyId=ASIA2F3EMEYESR4GMYSA&amp;Signature=U17jOo7HR1LmuipwFaMAY9wWu7I%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDvV3EREtTvb5Cs0EPcuzJ1JpbQTwHiup5Cv2OtH%2ByyxgIhAKZ2WhOXy0s%2FAFpT8We2yIX5zic61oltub7Cs%2BRf7PsvKvwECMf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwYmKNT4DimcGLDIj0q0AQ1PmWxtxBnAHd0%2Bd9lQ63ql10Y2Jd21Som%2BE8evX%2FO1XTaBegB33tN%2BYh%2Fn6WjacxWX%2F08lGnkYaT7uQs2GaDRq0Dujy%2FEYmZv%2Bhp%2B0EVF%2FOxXYfLU0DdGas%2BYR7VtiKjavyuVcKb%2BhqEFCb9idw1GoelYJZW2OBhcSXt7T9dEQshcr2bDwIgFm9XAlUtdh90fqDuk2BAk5weE6xWwfxrunPx8jVKCyDbL%2B%2BcttGg717NU22fihUfXUX6SpJu304J9aE8MGmn%2BUACK2yapZ7AqAWopLuk7jVSgComUBpwXrevuTk42EsUHZOPy4N3aPIf4SXGuXaWQ%2Ff41bOiwmFolMHxHun%2BkXDTP8DgIPmd3%2FZ29TYH7FVhoZfjBjGUWiverd1C533uK%2ByiEZHOsN23MhBoG7maKCvHmi%2BHsu1zG2lhtPelqQZDqSisIRxlNPbSpZK2O58pkr1eWuNHfcK0I0orADJyO5wRTvYTWZ2Vvy6jEcRwAxRwAu00qsG4V7mX8Nyq5svlXDgj%2FuJX92w%2BdvQl86fRiSVwpzbtP3stDW7etv0PFtBuoq5j84fQWNsjbg9uLxuRBBrtTSb8uLtUwSgZHFC6crlYdARSLW8bqSCFh7FF5MU1Sti2P7sMKB8sI8Oxf9KvWJCV7mx5wV7EyF6ZNvoEWb3Wh9KzqfRObDaFIezYDM327%2FTWLRcD5DpInbTsrZ2ICjwl0dC5Qh8EtTyNWeNRio9azOwNWXz1b0EZe9NfN4cI9LPGjXnRVaQY7cEpEV7%2FLQlpbSgvYg8LWMK%2FA5tAGOpcBF4153OT3FMFQJ42nI3VCXUsmI%2BJaB4TSHflSXXFQNLJTG6zaHZvLKBewdqi4tsZc4QVzEH5fuahQBSjUqLkzFySBQlTQFTiFWIRrToU2Xc3l2EQcbcdpMayrIi9YCCC%2Bz0V4BI5jpJWfyA3sb8spQ0Q9eiL8XFkNxnUBoHXhq6ue6N7c3gq3xoxMenuojEtx7xCX2%2B7SrQ%3D%3D&amp;Expires=1780066392"></a></td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/ransomware-uses-system-scheduled-task/">Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/Ransomware-Uses-SYSTEM-Scheduled-Task-to-Encrypt-Local-Drives-With-Elevated-Privileges.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151380</post-id>	</item>
		<item>
		<title>JINX-0164 Threat Actor Using LinkedIn Social Engineering to Deploy Custom macOS Malware</title>
		<link>https://cybersecuritynews.com/jinx-0164-threat-actor-using-linkedin-social-engineering/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 29 May 2026 15:45:11 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151379</guid>

					<description><![CDATA[<p>A new threat actor tracked as JINX-0164 has been running calculated attacks against cryptocurrency organizations, using LinkedIn profiles to lure developers into downloading custom macOS malware. Active since at least mid-2025, the group has combined social engineering, credential theft, and supply chain sabotage into a seamless operation that puts the entire software development pipeline at [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/jinx-0164-threat-actor-using-linkedin-social-engineering/">JINX-0164 Threat Actor Using LinkedIn Social Engineering to Deploy Custom macOS Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new threat actor tracked as JINX-0164 has been running calculated attacks against cryptocurrency organizations, using LinkedIn profiles to lure developers into downloading custom macOS malware. </p>



<p class="wp-block-paragraph">Active since at least mid-2025, the group has combined social engineering, credential theft, and supply chain sabotage into a seamless operation that puts the entire software development pipeline at risk.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attacks begin with a convincingly crafted LinkedIn profile reaching out to targets under the guise of a business opportunity or a job offer. </p>



<p class="wp-block-paragraph">Once trust is established, victims receive a meeting invitation linked to a fake conferencing platform page designed to look like Microsoft Teams or similar services. </p>



<p class="wp-block-paragraph">Clicking the link triggers the download of a macOS-specific remote access tool that silently begins stealing sensitive data from the moment it runs.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Researchers at Wiz.io identified and named the threat cluster JINX-0164 after investigating multiple intrusions targeting cryptocurrency companies. </p>



<p class="wp-block-paragraph"><a href="https://www.wiz.io/blog/threat-actors-target-crypto-orgs" id="https://www.wiz.io/blog/threat-actors-target-crypto-orgs" target="_blank" rel="noreferrer noopener nofollow">Wiz CIRT and Wiz Research said in a report</a> shared with Cyber Security News that this actor is financially motivated and has been deploying two distinct malware families, AUDIOFIX and MINIRAT, with a clear focus on macOS devices.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">AUDIOFIX is a compiled Python-based infostealer and <a href="https://cybersecuritynews.com/deepdoor-stealer-harvests-browser-passwords/" id="148905" target="_blank" rel="noreferrer noopener">backdoor that harvests browser credentials</a>, cryptocurrency wallet extensions, SSH keys, cloud API tokens, and even clipboard data in real time. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV-b9wu5sHoMu2D5pCpLcp4tezKbUsDasRYz-MKq7KO1tKLx9WNjAkU5DovQBCO8cCL8t7foULQqTg02QpwVpTlrzeyxeMXY4vWXh_c_twBVFVcxWhczGgNTsaHEjQrNG_tm5PS3gqvMkmXxUOb20w0K19cFCqTVL49SfcRLpa30QmDsZZ36JcLAkJ2ng/s16000/Attack%20Chain%20(Source%20-%20Wiz.io).webp" alt="Attack Chain (Source - Wiz.io)" /><figcaption class="wp-element-caption">Attack Chain (Source &#8211; Wiz.io)</figcaption></figure>
</div>


<p class="wp-block-paragraph">It communicates with its command-and-control server over encrypted HTTPS, using AES-256-CBC encryption, and can quietly switch to randomized polling intervals to avoid detection. </p>



<p class="wp-block-paragraph">The malware also targets active sessions on communication platforms like Discord, Slack, and Telegram, giving attackers a wide view into a victim&#8217;s digital life.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The threat actor masked their network activity by routing connections through commercial VPN services, making attribution harder. </p>



<p class="wp-block-paragraph">To further cover their tracks, they tampered with Git commit metadata to impersonate legitimate developers and pushed malicious code directly into internal repositories, turning the organization&#8217;s own development infrastructure into a delivery mechanism for further infections.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-jinx-0164-threat-actor-using-linkedin-social-engineering" class="wp-block-heading"><strong>JINX-0164 Threat Actor Using LinkedIn Social Engineering</strong></h2>



<p class="wp-block-paragraph">The attack chain unfolded over a two-week period in one documented case, moving from a LinkedIn message to full infrastructure compromise. </p>



<p class="wp-block-paragraph">Once a developer clicked the fake meeting link, AUDIOFIX was downloaded via a bash dropper script hosted on a fake driver update domain. </p>



<p class="wp-block-paragraph">The payload disguised itself as a system audio component named coreaudiod and was saved as ChromeUpdater, launched through launchctl to establish persistence.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">After gaining a foothold, the malware harvested credentials from macOS Keychain, browsers, and cloud configuration files, including AWS, GCP, and Azure keys, as well as Cloudflare API tokens. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/new-github-device-code-phishing-attacks/" id="110957" target="_blank" rel="noreferrer noopener">GitHub tokens were then used to exfiltrate secrets</a> from CI/CD pipelines using an open-source tool called nord-stream. The attacker pushed infected code into shared repositories, which then spread AUDIOFIX to every developer who pulled and built from those branches.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-supply-chain-attack-via-trojanized-npm-package" class="wp-block-heading"><strong>Supply Chain Attack via Trojanized npm Package</strong></h2>



<p class="wp-block-paragraph">On April 7, 2026, JINX-0164 escalated by targeting the broader software supply chain. The group quietly modified version 4.9.1 of the npm package @velora-dex/sdk, a widely used cryptocurrency SDK, appending code that would download and execute a shell script whenever the package was imported by any project.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891"></a></p>



<p class="wp-block-paragraph">That shell script delivered MINIRAT, a lightweight Go-based backdoor that registers infected machines with the same command-and-control infrastructure used by AUDIOFIX. </p>



<p class="wp-block-paragraph">Although MINIRAT does not perform the same broad automated data theft, it provides operators with persistent remote access and the ability to execute commands and move files. </p>



<p class="wp-block-paragraph">Only npm credentials were compromised in this incident, as the source code on GitHub remained unmodified.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Organizations are advised to deploy an Endpoint Detection and Response solution and enable audit logging across all cloud platforms and version control systems by default. </p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/security-teams-shrink-as-automation-rises/" id="https://cybersecuritynews.com/security-teams-shrink-as-automation-rises/" target="_blank" rel="noreferrer noopener">Security teams should watch for unverified commits in GitHub</a>, unexpected VPN usage from providers like ExpressVPN, Astrill VPN, and Mullvad VPN, and any anomalous workflow activity in CI/CD pipelines. </p>



<p class="wp-block-paragraph">Enabling GitHub Vigilant Mode can help surface developer impersonation attempts through unsigned or mismatched commits. Teams should also monitor for the use of nord-stream and flag any new code package publications originating from unfamiliar IP addresses.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7281aa19-23fa-45b1-bc69-1ad96c4c5929/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYESITK66PH&amp;Signature=VXXPNJSQgjukph8T7xAdO9ePK1U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCMtuLLjrtNlHgW2HRWT5egpxr9KQFIvmtx9%2B1yTqqAiwIhAIe20gjhsAazQBHWCUXkyXv0%2BiLHW6zg7D9tTVpbDdJCKvwECMj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgyJUg9DqYUADWzmvekq0AQQaMwtzlVIk%2F8ve7w8rMp5qeHibQh%2FW6Prx0o2L07e7dt8ISysH1j6wRFYKAmTIeBP%2B1tL4HVP7gkuCgZ2LbkyOLxD4CTGIixi%2Brx558U6iMlRB420R5U7XEjY1RvzbteFqgHgxbclfeSrHHlYfWaQVrTK3cWL174OkoLdDnTY2zug4Mc5ivRnSPUzLua84zMR7387ieD49MSrHQRgID6g3PyEWe5Okj9WrJrSaiG0v1xo73txp9kgyhgsZ0BtIkej64grkXfJzcaDIyPD%2Baq%2BchNCDvsg4BVkOl%2FmSGOa6dCAyuYp3vmWxxEkJvlOs%2By9qf2votpN%2F%2FtcX69ETuLziK2BMF2LNzWFmYIDSsWK7JzRAMDKQXWStP7BzQGK4c4EVJIIenjVropPwKlarSOYhhcKQmkoVJkDgq9X1kuj4caPwStoGIC%2BVwG2l4i8oaGYiI9WJiBw4Rp%2B%2BrblkWo6HZjJ3cXqnzxJZoKGWHOO8bnGmGizvb9Qd6meMo6DYVdwM%2BnAIv20j6NPiZlKkop98SJvteFshbKf0QqElxOtafETTEmocCjpmpex8xI96pQJW5D9aodBFPV2XBhj6a8vvbM1y6SPEob6445wOH78xtkN3J68VNeSzUS%2Br7Od1%2F9iX148ty1FvSmUl7QmL3JPHTBDCHi%2BSDFkWeoLwEZVeKyyl3%2B46kqoocrLJavLIKKWS%2Bqrbf5UItcTM1OhnBix6tnEjwCxW%2B6qmsiCOG1yVnWlAGgBV%2FQLbtUKVc5K8FXPTVEffvgJI0f32YlBdrWsMMjH5tAGOpcB0jDB3P7c3siRt%2Bse%2FKhMBuSl8q1A7hzSogcWtV5MQD7B%2FuwSLsCjx0uwNXhyKflEPWeSo3Hu%2BblXGxWlMLsSejyfb%2FR4OM2W%2FhLbkvKJom7eNsPzMdY3UFSOaX3s7Wgr6VKM0tK07ZyNM9bPpjBRixyNJvVXA9TZPypHXOL%2Bm4%2FvcNjMzleZGBFMcxCbWFOGWsaGLi8T5w%3D%3D&amp;Expires=1780065891" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>SHA-256</td><td><code>0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270</code></td><td>MINIRAT ARM64</td></tr><tr><td>SHA-256</td><td><code>0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba10875f5</code></td><td>MINIRAT x86_64</td></tr><tr><td>SHA-256</td><td><code>a35d2b67fa478a7174e308b43ce30bf69b3bc6f44fa76197fdf95fc2fbc1cf7d</code></td><td>MINIRAT ARM64 (variant)</td></tr><tr><td>SHA-256</td><td><code>65cba741fe30fa4799fb9002ea8de6d96042a59159dd7c3419c766af24c7a8b4</code></td><td>AUDIOFIX HTTPS/ARM64</td></tr><tr><td>SHA-256</td><td><code>0b1a36a31b952341a534fe24890f1ed2921ee259773cff46e4f6273b8c4d5e3a</code></td><td>AUDIOFIX HTTPS/x86_64</td></tr><tr><td>SHA-256</td><td><code>e8ee6f5145c9d503c5130bfc6585567f6e19d409158c3c0ca0b259f1875b1a2f</code></td><td>AUDIOFIX Dropbox/ARM64</td></tr><tr><td>SHA-256</td><td><code>3e3901519c2305fbe9d5483b7234c25c6d2b562512916481d96f26b849c7d4e1</code></td><td>AUDIOFIX Dropbox/x86_64</td></tr><tr><td>SHA-256</td><td><code>9c2ce925133a3bf5a924063bbef8df49918d5b7258695c1894cd18c75970157a</code></td><td>Dropper – Fake audio fix (apple.driver-store.com)</td></tr><tr><td>SHA-256</td><td><code>402625ec79e3573a80b6de9b33fc1e503e3c7803603cd958ddd515fb0e4a3c91</code></td><td>Dropper – Fake audio fix (apple.driver-update.io)</td></tr><tr><td>SHA-256</td><td><code>b6cab0b3aa8e56e2427f486c74588d598ae58bb0cbc0eda6939fe171cb4f2d89</code></td><td>Dropper – Fake audio fix (driver-updater.net)</td></tr><tr><td>SHA-256</td><td><code>d4e863f9818bfb2f1dd932df6441dff204e6142c3bdb55b298cb08dc7b6a9f12</code></td><td>Dropper – Fake Chrome update (apple.driver-store.com)</td></tr><tr><td>SHA-256</td><td><code>c6ef82d2864dfd26f117a1ef5602679153423f2742970a7949cec72722f0a0b3</code></td><td>Dropper – Supply chain (89.36.224.5)</td></tr><tr><td>SHA-256</td><td><code>2a10ffe0367bb1b26ba2c3bc600892c21074725c0b8c9dc9161e6ceb339f4d5c</code></td><td>Dropper – Supply chain (89.36.224.5, variant)</td></tr><tr><td>Domain</td><td><code>datahub[.]ink</code></td><td>Primary C2 domain (resolves to 208.115.220.17 / 185.175.59.85)</td></tr><tr><td>Domain</td><td><code>cloud-sync[.]online</code></td><td>Backup C2 domain</td></tr><tr><td>Domain</td><td><code>byte-io[.]us</code></td><td>Backup C2 domain</td></tr><tr><td>Domain</td><td><code>apple[.]driver-store[.]com</code></td><td>Payload delivery domain</td></tr><tr><td>Domain</td><td><code>apple[.]driver-update[.]io</code></td><td>Payload delivery domain</td></tr><tr><td>Domain</td><td><code>driver-updater[.]net</code></td><td>Payload delivery domain</td></tr><tr><td>Domain</td><td><code>driver-hub[.]net</code></td><td>Payload delivery domain</td></tr><tr><td>Domain</td><td><code>drvstore[.]com</code></td><td>Payload delivery domain</td></tr><tr><td>Domain</td><td><code>bitget-meeting[.]com</code></td><td>Meeting spoofing domain</td></tr><tr><td>Domain</td><td><code>teamicrosoft[.]com</code></td><td>Meeting spoofing domain (Teams impersonation)</td></tr><tr><td>Domain</td><td><code>teams[.]cam</code></td><td>Meeting spoofing domain</td></tr><tr><td>Domain</td><td><code>live[.]us[.]org</code></td><td>Meeting spoofing domain</td></tr><tr><td>Domain</td><td><code>us03-slack[.]online</code></td><td>Meeting spoofing domain (Slack impersonation)</td></tr><tr><td>Domain</td><td><code>live[.]ong</code></td><td>Meeting spoofing domain</td></tr><tr><td>IP Address</td><td><code>89[.]36[.]224[.]5</code></td><td>Payload delivery server</td></tr><tr><td>IP Address</td><td><code>185[.]100[.]85[.]250</code></td><td>Meeting spoofing infrastructure</td></tr><tr><td>IP Address</td><td><code>84[.]32[.]83[.]250</code></td><td>Meeting spoofing / payload delivery infrastructure</td></tr><tr><td>IP Address</td><td><code>153[.]92[.]126[.]84</code></td><td>Meeting spoofing infrastructure</td></tr><tr><td>IP Address</td><td><code>45[.]45[.]217[.]242</code></td><td>Meeting spoofing infrastructure</td></tr><tr><td>IP Address</td><td><code>163[.]172[.]53[.]20</code></td><td>Meeting spoofing / payload delivery infrastructure</td></tr><tr><td>IP Address</td><td><code>208[.]115[.]220[.]17</code></td><td>C2 server (datahub.ink)</td></tr><tr><td>IP Address</td><td><code>185[.]175[.]59[.]85</code></td><td>C2 server (datahub.ink)</td></tr><tr><td>File Path</td><td><code>~/Library/LaunchAgents/com.microsoft.teams.coreaudiod.plist</code></td><td>Persistence mechanism (Python RAT)</td></tr><tr><td>File Path</td><td><code>~/Library/LaunchAgents/io.aircall.workspace.helper.plist</code></td><td>Persistence mechanism (Python RAT)</td></tr><tr><td>File Path</td><td><code>~/Library/LaunchAgents/com.apple.Terminal.profiler.plist</code></td><td>Persistence mechanism (MINIRAT)</td></tr><tr><td>File Path</td><td><code>~/.zsh_cache</code></td><td>XOR-encoded stolen macOS password</td></tr><tr><td>File Path</td><td><code>/helper.log</code></td><td>Malware activity log</td></tr><tr><td>File Path</td><td><code>/tokens.txt</code></td><td>Exfiltrated Discord tokens</td></tr><tr><td>File Path</td><td><code>/clip</code></td><td>Clipboard capture log</td></tr><tr><td>File Name</td><td><code>ChromeUpdater</code></td><td>AUDIOFIX payload saved under this name</td></tr><tr><td>File Name</td><td><code>coreaudiod</code></td><td>Payload masquerading as system audio driver</td></tr><tr><td>npm Package</td><td><code>@velora-dex/sdk v4.9.1</code></td><td>Trojanized npm package used in supply chain attack</td></tr><tr><td>AES Key</td><td><code>v59l2uwlow9s1ebuscgfg9k9r4voxkbs</code></td><td>Shared AES key found in both AUDIOFIX and MINIRAT samples</td></tr><tr><td>Git Committer</td><td><code>nord-stream / nord-stream@localhost.com</code></td><td>Developer impersonation indicators in malicious commits</td></tr><tr><td>Branch Name</td><td><code>dev_remote_ea5Eu/test/v1</code></td><td>Branch used by nord-stream during secret exfiltration</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/jinx-0164-threat-actor-using-linkedin-social-engineering/">JINX-0164 Threat Actor Using LinkedIn Social Engineering to Deploy Custom macOS Malware</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/05/JINX-0164-Threat-Actor-Using-LinkedIn-Social-Engineering-to-Deploy-Custom-macOS-Malware.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151379</post-id>	</item>
	</channel>
</rss>
