El ataque a la cadena de suministro de Packagist infecta 8 paquetes utilizando malware de Linux alojado en GitHub – CYBERDEFENSA.MX

Una nueva campaña de ataque «coordinada» a la cadena de suministro ha afectado a ocho paquetes en empaquetador incluido código malicioso diseñado para ejecutar un binario de Linux recuperado de una URL de versiones de GitHub.

«Aunque los paquetes afectados eran todos paquetes de Composer, el código malicioso no se agregó a compositor.json», Socket dicho. «En cambio, se insertó en package.json, dirigido a proyectos que incluyen herramientas de compilación de JavaScript junto con código PHP».

Esta «ubicación entre ecosistemas» hace que la actividad se destaque porque los desarrolladores y equipos de seguridad que escanean las dependencias de PHP solo pueden centrarse en los metadatos relacionados con Composer, mientras omiten los ganchos del ciclo de vida de package.json que están incluidos en el paquete. Desde entonces, las versiones maliciosas se han eliminado de Packagist.

Ciberseguridad

Un análisis de los paquetes ha descubierto que sus repositorios ascendentes han sido modificados para incluir un script posterior a la instalación que intenta descargar un binario de Linux desde una URL de versiones de GitHub («github[.]com/parikhpreyash4/systemd-network-helper-aa5c751f»), guárdelo en la carpeta «/tmp/.sshd», cambie sus permisos usando «chmod» para otorgar permisos de ejecución a todos los usuarios y ejecútelo en segundo plano.

Los nombres de los paquetes y la versión afectada asociada se enumeran a continuación:

  • moritz-sauer-13/silverstripe-cms-theme (dev-master)
  • crosiersource/crosierlib-base (dev-master)
  • devdojo/wave (dev-principal)
  • devdojo/génesis (dev-main)
  • katanaui/katana (dev-principal)
  • elitedevsquad/sidecar-laravel (3.x-dev)
  • r2luna/cerebro (dev-principal)
  • baskarcm/tzi-chat-ui (dev-principal)

La investigación de Socket encontró referencias a la misma carga útil en 777 archivos en GitHub, lo que sugiere que podría ser parte de una campaña más amplia. en al menos dos instanciasse agregó a un flujo de trabajo de GitHub. Sin embargo, actualmente no se sabe cuántos de estos coinciden con distintos compromisos, bifurcaciones, artefactos de paquetes duplicados o referencias almacenadas en caché.

«Esto sugiere que el atacante no confiaba en un único mecanismo de ejecución. En los artefactos del paquete, la carga útil se activaba a través de scripts postinstalación package.json», dijo la firma de seguridad de aplicaciones. «En los archivos de flujo de trabajo, estaba posicionado para ejecutarse durante los trabajos de GitHub Actions».

Ciberseguridad

Es más, la naturaleza exacta de la carga útil descargada de GitHub no está clara, ya que cuenta GitHub asociado con el alojamiento del repositorio ya no está disponible. La elección del nombre «gvfsd-network» para el malware es interesante, ya que se refiere a un demonio del sistema de archivos virtual GNOME (GVfs). responsable para administrar y explorar recursos compartidos de red.

«Incluso sin el binario de segunda etapa, el instalador malicioso es suficiente para justificar el bloqueo», dijo Socket. «Proporciona ejecución remota de código durante la instalación o creación de flujos de trabajo e intenta ocultar su actividad desactivando la verificación TLS, suprimiendo errores y ejecutando un binario descargado en segundo plano».

El ataque Megalodon GitHub apunta a 5561 repositorios con flujos de trabajo CI/CD maliciosos – CYBERDEFENSA.MX

Investigadores de ciberseguridad han revelado detalles de una nueva campaña automatizada llamada megalodón eso ha impulsado 5.718 confirmaciones maliciosas a 5.561 repositorios de GitHub en un período de seis horas.

«Utilizando cuentas desechables e identidades de autor falsificadas (build-bot, auto-ci, ci-bot, pipeline-bot), el atacante inyectó flujos de trabajo de GitHub Actions que contienen cargas útiles bash codificadas en base64 que filtran secretos de CI, credenciales de nube, claves SSH, tokens OIDC y secretos de código fuente a un servidor C2 en 216.126.225[.]129:8443», SeguridadSegura dicho en un informe.

La lista completa de datos recopilados por el malware se encuentra a continuación:

  • Variables de entorno CI, /proc/*/environ y entorno PID 1
  • Credenciales de servicios web de Amazon (AWS)
  • Tokens de acceso a Google Cloud
  • Credenciales de rol de instancia obtenidas consultando los puntos finales de AWS IMDSv2, metadatos de Google Cloud y Microsoft Azure Instance Metadata Service (IMDS)
  • Claves privadas SSH
  • Configuraciones de Docker y Kubernetes
  • Fichas de bóveda
  • Credenciales de terraforma
  • Historia del caparazón
  • Claves API, cadenas de conexión de bases de datos, JWT, claves privadas PEM y tokens de nube que coinciden con más de 30 patrones secretos de expresiones regulares.
  • URL y token de solicitud de token OIDC de GitHub Actions
  • GITHUB_TOKEN, tokens GitLab CI/CD y tokens Bitbucket
  • Archivos .env, credenciales.json, service-account.json y otros archivos de configuración

Uno de los paquetes afectados es @tiledesk/tiledesk-server, que incluye una carga útil bash codificada en Base64 dentro de un archivo de flujo de trabajo de GitHub Actions. En total, se enviaron 5.718 confirmaciones a 5.561 repositorios distintos el 18 de mayo de 2026, entre las 11:36 a. m. y las 5:48 p. m. UTC.

Ciberseguridad

«El atacante rotó entre cuatro nombres de autores (build-bot, auto-ci, ci-bot, pipeline-bot) y siete mensajes de confirmación, todos imitando el mantenimiento rutinario de CI», dijo SafeDep. «El atacante utilizó cuentas de GitHub desechables con nombres de usuario aleatorios de 8 caracteres (por ejemplo, rkb8el9r, bhlru9nr, lo6wt4t6), configuró git config para falsificar la identidad del autor y utilizó PAT comprometidas o claves de implementación».

Se han observado dos variantes de carga útil como parte de la campaña a gran escala: SysDiag, una variante masiva que agrega un nuevo flujo de trabajo que se activa en cada solicitud push y pull, y Optimize-Build, una variante específica que se activa solo en envío_flujo de trabajoun activador de GitHub Actions que permite a los usuarios ejecutar manualmente un flujo de trabajo bajo demanda. En el caso de Tiledesk, el enfoque dirigido se utiliza para dirigirse a los ejecutores de CI/CD, y no cuando está instalado el paquete npm.

«La compensación es alcance: encendido: empuje garantizaría la ejecución en cada compromiso para dominar, alcanzando más objetivos sin intervención», agregó SafeDep. «Workflow_dispatch sacrifica eso por la seguridad operativa. Con más de 5700 repositorios comprometidos, incluso una pequeña fracción que produzca un GITHUB_TOKEN utilizable le da al atacante suficientes objetivos para la activación bajo demanda».

El resultado es que una vez que el propietario de un repositorio fusiona la confirmación, el malware se ejecuta dentro de sus canales de CI/CD y se propaga aún más, lo que permite el robo de credenciales y secretos a escala.

«Hemos entrado en una nueva era de ataques a la cadena de suministro, y el compromiso de TeamPCP con GitHub fue solo el comienzo», Moshe Siman Tov Bustan de OX Security. dicho. «Lo que viene a continuación es una ola interminable, un tsunami de ciberataques a desarrolladores de todo el mundo».

El desarrollo se produce cuando TeamPCP ha utilizado como arma la cadena de suministro de software interconectada para corromper cientos de herramientas de código abierto, abriéndose camino a través de varios ecosistemas y extorsionando a las víctimas para obtener ganancias en algunos casos. GitHub, propiedad de Microsoft, se ha convertido en la última incorporación a la larga lista de víctimas del grupo, que también incluye a TanStack, Grafana Labs, OpenAI y Mistral AI.

Los ataques de TeamPCP han impulsado una explotación cíclica de proyectos populares de código abierto, donde un compromiso alimenta al siguiente, permitiendo que el malware se propague como la pólvora en forma de gusano. El grupo también parece estar motivado financieramente y ha establecido asociaciones con BreachForums y otros grupos de extorsión como LAPSUS$ y VECT.

Es más, el grupo también parece tener motivaciones geopolíticas, como lo demuestra el despliegue de malware limpiador al detectar máquinas ubicadas en Irán e Israel.

Las consecuencias de la ola de ataques del TeamPCP y la Mini gusano Shai-Hulud tiene incitado npm para invalidar tokens de acceso granular con acceso de escritura que omite la autenticación de dos factores (2FA). NPM también insta a los usuarios a cambiar a Publicación confiable para reducir la dependencia de dichos tokens.

«Al quemar cada token bypass-2FA en la plataforma, npm corta las credenciales que el gusano ya ha recopilado», afirma la empresa de seguridad de aplicaciones Socket. dicho. «Los mantenedores emiten otros nuevos. El gusano, todavía activo en la naturaleza, vuelve a recolectarlos. El reinicio da un respiro. No cierra el agujero subyacente».

Los grupos de actividades como Megalodon y TeamPCP implican comprometer paquetes legítimos para distribuir malware. Por el contrario, una cuenta desechable llamada «polimercadodev» publica nueve paquetes npm maliciosos que se hacen pasar por herramientas CLI comerciales de Polymarket en una ventana de 30 segundos para robar las claves privadas de Ethereum/Polygon de las víctimas a través de un gancho posterior a la instalación.

Ciberseguridad

Al momento de escribir este artículo, todavía están disponibles para descargar desde npm. Los nombres de los paquetes están a continuación:

  • polimercado-trading-cli
  • terminal-polimercado
  • comercio-polimercado
  • polimercado-auto-comercio
  • comercio de copias de polimercado
  • robot-polimercado
  • código-claude-polimercado
  • agente-ai-polimercado
  • comerciante-polimercado

«Durante la instalación, un script posterior a la instalación muestra un mensaje de incorporación de billetera falsa que solicita al usuario que pegue su clave privada, afirmando que ‘permanece cifrada’», SafeDep dicho. «El script PUBLICA la clave sin formato en texto plano a un trabajador de Cloudflare en hxxps://polymarketbot.polymarketdev.workers[.]dev/v1/billetera/claves.»

«El atacante creó una CLI comercial funcional en torno a una operación de robo de credenciales. La ingeniería social lleva el ataque: el mensaje posterior a la instalación parece una incorporación de billetera estándar, el enmascaramiento imita la entrada segura y el repositorio de GitHub proporciona credibilidad falsa»

Repositorios internos de GitHub violados a través de la extensión maliciosa de código VS de la consola Nx – CYBERDEFENSA.MX

GitHub confirmó oficialmente el miércoles que la violación de sus repositorios internos fue el resultado de un compromiso del dispositivo de un empleado que involucraba una versión envenenada de la extensión Microsoft Visual Studio Code (VS Code) de la consola Nx.

El desarrollo se produce cuando el equipo de Nx reveló que la extensión, nrwl.angular-console, fue violada después de que uno de los sistemas de sus desarrolladores fuera pirateado a raíz del reciente ataque a la cadena de suministro de TanStack, que también afectó a OpenAI, Mistral AI y Grafana Labs.

«No tenemos evidencia de impacto en la información de los clientes almacenada fuera de los repositorios internos de GitHub, como las propias empresas, organizaciones y repositorios de nuestros clientes», Alexis Wales, director de seguridad de la información de GitHub, dicho en un comunicado.

«Algunos de los repositorios internos de GitHub contienen información de los clientes, por ejemplo, extractos de interacciones de soporte. Si se descubre algún impacto, notificaremos a los clientes a través de los canales de notificación y respuesta a incidentes establecidos».

Ciberseguridad

Se dice que el ataque permitió al actor de la amenaza, un grupo cibercriminal conocido como TeamPCP, filtrar alrededor de 3.800 repositorios. GitHub dijo que tomó medidas para contener el incidente y rotó secretos críticos, y agregó que continúa monitoreando la situación para detectar actividades de seguimiento.

En una publicación en X, Jeff Cross, cofundador de Narwhal Technologies, la empresa detrás de nx.dev, dicho«este incidente resalta que es necesario que haya cambios más profundos y fundamentales en la forma en que nosotros y otros mantenedores debemos pensar acerca de proteger las herramientas de desarrollo y la distribución de código abierto».

«También estamos iniciando conversaciones con otros mantenedores de código abierto de alto perfil sobre cómo podemos trabajar juntos en algunos de los problemas estructurales más profundos en torno a la seguridad de la cadena de suministro de software. Muchas de las suposiciones bajo las cuales el ecosistema ha operado durante años ya no se cumplen».

En los últimos meses, TeamPCP ha ganado rápidamente notoriedad por sus ataques a la cadena de suministro de software a gran escala, específicamente persiguiendo proyectos de código abierto ampliamente utilizados y herramientas de seguridad adyacentes en las que confían los desarrolladores.

Lo que es notable aquí es que la versión troyanizada de la extensión VS Code estuvo activa en Visual Studio Marketplace solo durante dieciocho minutos (entre las 12:30 p. m. y las 12:48 p. m. UTC del 18 de mayo de 2026). Pero esta breve ventana fue suficiente para que los atacantes distribuyeran un ladrón de credenciales capaz de recopilar datos confidenciales de las bóvedas de 1Password, configuraciones de Anthropic Claude Code, npm, GitHub y Amazon Web Services (AWS).

«La extensión se veía y se comportaba como la Consola Nx normal, pero al iniciarse ejecutaba silenciosamente un único comando de shell que descargaba y ejecutaba un paquete oculto desde una confirmación plantada en el repositorio oficial de GitHub nrwl/nx», dijo Nir Zadok, investigador de seguridad de OX. dicho. «El comando fue disfrazado como una tarea rutinaria de configuración del MCP para no levantar sospechas».

Ciberseguridad

La naturaleza interconectada del software moderno ha permitido a TeamPCP desatar un ciclo autosostenible de nuevos compromisos. El patrón que resalta este aspecto es tan engañosamente simple como nefasto: irrumpir en una herramienta confiable, robar credenciales de los sistemas de desarrolladores que puedan instalarla y usar esas credenciales para irrumpir en la siguiente herramienta legítima.

«Todos los mercados de extensiones populares vienen con la actualización automática activada de forma predeterminada. VS Code, Cursor, toda la línea», dijo el investigador de seguridad de Aikido Raphael Silva. dicho. «El razonamiento tiene sentido de forma aislada, porque la mayoría de los desarrolladores nunca actualizan nada manualmente, por lo que dejarlo fuera significa una larga cola de editores ejecutando código vulnerable y obsoleto».

«La compensación deja de tener sentido una vez que se tiene en cuenta a los editores hostiles/comprometidos. La actualización automática le da a un atacante que controla una versión un canal de envío directo a cada máquina que ejecuta esa extensión. Los mercados no imponen ninguna puerta de revisión o período de espera entre el momento en que se publica una actualización y el momento en que los clientes la instalan».

GitHub dice que los repositorios internos fueron tomados en un ataque de extensión de VS Code envenenado

GitHub dijo el martes por la noche que los repositorios internos fueron exfiltrados después de que el dispositivo de un empleado se viera comprometido a través de una extensión envenenada de Visual Studio Code, un incidente que subraya los crecientes riesgos que enfrentan las plataformas de desarrollo de software y los ecosistemas construidos alrededor de herramientas de desarrollo de terceros.

La empresa propiedad de Microsoft dijo en publicaciones en X que detectó y contuvo el compromiso, eliminó la versión de la extensión maliciosa, aisló el punto final afectado y comenzó una investigación de respuesta al incidente. La evaluación actual de la empresa es que la actividad involucró únicamente repositorios internos de GitHub.

GitHub también dijo que una afirmación de TeamPCP, un grupo de hackers detrás de ataques dirigidos a paquetes de desarrollo de software, de que 3.800 repositorios se vieron afectados era «direccionalmente consistente» con su investigación hasta el momento. Dijo que los secretos críticos se rotaron el martes, dando prioridad primero a las credenciales de mayor impacto. La compañía dijo que continuó analizando registros, validando la rotación secreta y monitoreando la actividad de seguimiento.

La empresa no ha nombrado públicamente la extensión involucrada ni ha atribuido la actividad a un grupo en particular. Según se informa, TeamPCP anunció la venta del material en un foro sobre delitos cibernéticos y amenazó con publicarlo si no aparecía ningún comprador.

El episodio también sigue una serie de ataques a la cadena de suministro que involucran a npm, PyPI, Docker y otros ecosistemas de desarrolladores. En esos incidentes, los atacantes a menudo se han dirigido a los mantenedores, paquetes o credenciales en lugar de atacar directamente a los usuarios finales. Los múltiples ataques muestran cuán frágiles se han vuelto los entornos de desarrollo a medida que los actores de amenazas los atacan cada vez más. Una única cuenta, paquete, extensión o proceso de compilación de desarrollador comprometido puede crear acceso a muchos sistemas posteriores.

GitHub ha dicho que no tiene evidencia de que los datos de los clientes almacenados fuera de los repositorios afectados se hayan visto afectados.

Los desarrolladores utilizan ampliamente las extensiones de Visual Studio Code para agregar funciones al editor de código de Microsoft, incluida la compatibilidad con lenguajes de programación, herramientas de prueba, servicios en la nube y asistentes de inteligencia artificial. Debido a que estas extensiones a menudo operan dentro de entornos de desarrollo, una extensión maliciosa o comprometida puede ubicarse cerca del código fuente, las credenciales y los sistemas de compilación.

«Lo que la gente subestima acerca de las extensiones de VS Code es que tienen acceso completo a todo lo que hay en la máquina del desarrollador», dijo a CyberScoop Charlie Eriksen, investigador de seguridad de Aikido Security. «EDR no cubre esta capa en absoluto. Lo que falta para la mayoría de las organizaciones es cualquier tipo de visibilidad de lo que realmente se ejecuta en las máquinas de desarrollo y la capacidad de controlarlo».

Extensiones troyanizadas han aparecido en VS Code Marketplace antes. Los investigadores de seguridad han identificado extensiones maliciosas que se hacen pasar por herramientas de desarrollo legítimas, incluidos paquetes utilizados para robar credenciales, extraer criptomonedas o exfiltrar datos. Algunos han acumulado un gran número de instalaciones antes de su eliminación, lo que refleja la dificultad de controlar los ecosistemas de complementos abiertos a escala.

Para GitHub, la infracción se produce en medio de un escrutinio más amplio de la seguridad de la infraestructura de los desarrolladores. La plataforma se encuentra en el centro de la producción de software para empresas, gobiernos, mantenedores de código abierto y desarrolladores independientes. Sus sistemas internos y su código son de evidente interés para los atacantes porque los servicios de GitHub admiten alojamiento de código, distribución de paquetes, automatización y flujos de trabajo de identidad en gran parte de la industria del software.

GitHub dijo que publicaría un informe más completo cuando finalice la investigación.

Greg Otto

Escrito por Greg Otto

Greg Otto es el editor en jefe de CyberScoop y supervisa todo el contenido editorial del sitio web. Greg ha dirigido una cobertura de ciberseguridad que ha ganado varios premios, incluidos los de la Sociedad de Periodistas Profesionales y la Sociedad Estadounidense de Editores de Publicaciones Empresariales. Antes de unirse a Scoop News Group, Greg trabajó para Washington Business Journal, US News & World Report y WTOP Radio. Tiene una licenciatura en periodismo televisivo de la Universidad de Temple.

La infracción de Grafana GitHub expone el código fuente a través del ataque TanStack npm – CYBERDEFENSA.MX

Grafana Labs, el 19 de mayo de 2026, dijo que una investigación sobre su reciente violación no encontró evidencia de que los sistemas de producción u operaciones del cliente estuvieran comprometidos.

Dijo que el alcance del incidente se limita al entorno GitHub de Grafana Labs, que incluye código fuente público y privado junto con repositorios internos de GitHub.

«Después de la evaluación inicial, descubrimos que, además del código fuente, el contenido descargado incluía repositorios de GitHub que algunos equipos de Grafana Labs utilizan para colaborar y almacenar información operativa interna y otros detalles sobre nuestro negocio», dicho.

«Esto incluye nombres de contactos comerciales y direcciones de correo electrónico que se intercambiarían en un contexto de relación profesional, no información extraída o procesada mediante el uso de sistemas de producción o la plataforma Grafana Cloud».

Ciberseguridad

El fabricante de software de visualización de código abierto también señaló que la violación se originó en el ataque a la cadena de suministro de npm de TanStack orquestado por TeamPCP, que también afectó a OpenAI y Mistral AI, y que detectó la actividad el 11 de mayo de 2026.

«Realizamos análisis y rotamos rápidamente una cantidad significativa de tokens de flujo de trabajo de GitHub, pero un token perdido llevó a los atacantes a obtener acceso a nuestros repositorios de GitHub», dijo. «Una revisión posterior confirmó que un flujo de trabajo específico de GitHub que originalmente consideramos que no estaba afectado, de hecho, se había visto comprometido».

La compañía dijo que posteriormente recibió una demanda de extorsión por parte de un actor de amenazas anónimo el 16 de mayo, pero optó por no pagar el rescate porque no hay garantía de que los datos robados realmente se eliminen y podrían actuar como catalizador para futuras campañas.

Desde entonces, Grafana ha tomado medidas para rotar tokens de automatización, implementar un monitoreo mejorado, auditar todas las confirmaciones en busca de signos de actividad maliciosa y reforzar su postura general de seguridad en GitHub.

Vale la pena mencionar aquí que un equipo de extorsión de datos llamado CoinbaseCartel incluyó a Grafana Labs en su sitio web oscuro el 15 de mayo de 2026. The Hacker News se comunicó con Grafana para solicitar comentarios y actualizaremos la historia si recibimos una respuesta.

El desarrollo se produce cuando GitHub dijo que está investigando el acceso no autorizado a sus repositorios internos después de que el notorio actor de amenazas conocido como TeamPCP pusiera a la venta el código fuente de la plataforma y las organizaciones internas en un foro de cibercrimen.

Etiquetas de acción populares de GitHub redirigidas al impostor que se compromete a robar credenciales de CI/CD – CYBERDEFENSA.MX

En otro ataque más a la cadena de suministro de software, los actores de amenazas han comprometido el popular flujo de trabajo de GitHub Actions. acciones-cool/problemas-ayudantepara ejecutar código malicioso que recopila credenciales confidenciales y las exfiltra a un servidor controlado por un atacante.

«Todas las etiquetas existentes en el repositorio se han movido para señalar una confirmación impostor que no aparece en el historial de confirmación normal de la acción», dijo el investigador de StepSecurity, Varun Sharma. dicho. «Esa confirmación contiene código malicioso que extrae credenciales de los canales de CI/CD que ejecutan la acción».

Un compromiso de impostor se refiere a una estrategia engañosa de ataque a la cadena de suministro de software en la que se inyecta código malicioso en un proyecto haciendo referencia a una confirmación o etiqueta que existe solo en una bifurcación controlada por el adversario, en lugar del repositorio confiable original. Como resultado, los atacantes pueden eludir las revisiones estándar de solicitudes de extracción (PR) y lograr la ejecución de código arbitrario.

Ciberseguridad

El compromiso del impostor, según la empresa de ciberseguridad, contiene código que, al ejecutarse dentro de un ejecutor de GitHub Actions, realiza una serie de acciones:

  • Descarga el tiempo de ejecución de Bun JavaScript al ejecutor.
  • Lee la memoria del proceso Runner.Worker para extraer las credenciales.
  • Realiza una llamada HTTPS saliente a un dominio controlado por un atacante («tm-kosche[.]com») para transmitir los datos robados.

StepSecurity dijo que 15 etiquetas asociadas con una segunda acción de GitHub, «actions-cool/maintain-one-comment», también se han visto comprometidas con la misma funcionalidad.

GitHub desde entonces acceso deshabilitado al repositorio debido a una «violación de los términos de servicio de GitHub». Actualmente no se sabe qué llevó a la filial propiedad de Microsoft a tomar esta decisión.

Curiosamente, el dominio de exfiltración «tm-kosche[.]com» se ha observado en la última ola de la campaña Mini Shai-Hulud dirigida a paquetes npm del ecosistema @antv, lo que indica que los dos grupos de actividad podrían estar relacionados.

«Debido a que ahora cada etiqueta se resuelve en confirmaciones maliciosas, cualquier flujo de trabajo que haga referencia a la acción por versión extrae el código malicioso en su próxima ejecución», dijo StepSecurity. «Solo los flujos de trabajo anclados a un SHA de compromiso completo en buen estado no se ven afectados».

La violación del token de Grafana GitHub provocó la descarga de la base de código y un intento de extorsión – CYBERDEFENSA.MX

Grafana ha revelado que una «parte no autorizada» obtuvo un token que les otorgaba la posibilidad de acceder al entorno GitHub de la empresa y descargar su código base.

«Nuestra investigación ha determinado que no se accedió a datos o información personal del cliente durante este incidente, y no hemos encontrado evidencia de impacto en los sistemas u operaciones del cliente», Grafana
dicho
en una serie de publicaciones sobre X.

La compañía también dijo que lanzó inmediatamente un análisis forense al descubrir la actividad y que identificó la fuente de la filtración, agregando que desde entonces las credenciales comprometidas han sido invalidadas y que se han implementado medidas de seguridad adicionales para proteger contra el acceso no autorizado.

Además, Grafana reveló que el atacante intentó chantajear y extorsionar a la empresa, exigiendo un pago para evitar que se publicara la base de datos robada.

Grafana dijo que optó por no pagar el rescate, citando a la Oficina Federal de Investigaciones (FBI) de Estados Unidos. La agencia advirtió anteriormente contra la negociación de rescates con los perpetradores, ya que no hay garantía de que hacerlo ayude a las empresas afectadas a recuperar sus datos.

Ciberseguridad

«También anima a los perpetradores a apuntar a más víctimas y ofrece un incentivo para que otros se involucren en este tipo de actividad ilegal», dijo el FBI.
estados
en su sitio web.

Grafana no reveló cuándo ocurrió el incidente ni desde cuándo el actor de amenazas tuvo acceso a su entorno, solo reveló que se enteró del ataque «recientemente». La infracción no se ha atribuido a ningún actor o grupo de amenazas conocido.

Sin embargo, informes de
Hackmanac
y
Ransomware.live
indican que un grupo de cibercrimen llamado CoinbaseCartel se ha atribuido la responsabilidad del incidente.

Según informes de
Martín pescador
y
Laboratorios Fortinet FortiGuard
CoinbaseCartel es un equipo de extorsión de datos que surgió en septiembre de 2025. Se considera una rama de los ecosistemas ShinyHunters, Scattered Spider y LAPSUS$.

Ciberseguridad

El grupo, que solo se centra en el robo de datos y la extorsión, a diferencia de los grupos tradicionales de ransomware, ha acumulado 170 víctimas en servicios de salud, tecnología, transporte, manufactura y negocios.

La compañía tampoco reveló qué código base descargó el atacante, pero Grafana ofrece varias soluciones como
Nube de Grafana
una plataforma de observabilidad alojada en la nube y totalmente administrada para aplicaciones e infraestructura. The Hacker News se comunicó con Grafana para hacer comentarios y actualizaremos la historia si recibimos una respuesta.

El desarrollo se produce días después de que la empresa estadounidense de tecnología educativa Instructure tomara la controvertida decisión de llegar a un acuerdo con el grupo de extorsión ShinyHunters después de que este último amenazara con filtrar terabytes de datos pertenecientes a miles de escuelas y universidades en todo Estados Unidos.

AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More – CYBERDEFENSA.MX

This week, the shadows moved faster than the patches.

While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems.

The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional.

Here’s the full weekly cybersecurity recap:

⚡ Threat of the Week

cPanel Flaw Comes Under Attack—A critical flaw in cPanel and WebHost Manager (WHM) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-41940, could result in an authentication bypass and allow remote attackers to gain elevated control of the control panel. In some cases, the attacks have led to a complete wipe of entire websites and backups. Other attacks have deployed Mirai botnet variants and a ransomware strain called Sorry.

🔔 Top News

  • Cybercrime Groups Use Vishing for Data Theft and Extortion—Two cybercrime groups tracked as Cordial Spider and Snarky Spider are carrying out «rapid, high-impact attacks» operating almost within the confines of SaaS environments, while leaving minimal traces of their actions. The groups employ voice calls, text messages, and emails, directing targeted employees to phishing pages masquerading as their employer’s legitimate single sign-on (SSO) page to capture credentials and provide attackers an entry point into systems, which they exploit for deeper access to victims’ SaaS environments. The attacks also use the initial access hooks to remove and set up multi-factor authentication devices under their control and delete emails that would otherwise alert organizations of potential malicious activity. According to CrowdStrike, «These actors use vishing to bypass MFA and move laterally across entire SaaS ecosystems with a single authenticated session, masking their tracks through residential proxy networks to blend in as legitimate home user traffic. This is part of a larger trend of English-speaking ransomware crews that share similar playbooks but are branching off into their own distinct groups.»
  • Copy Fail Linux Flaw Exploited—The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-31431, a vulnerability impacting various Linux distributions, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. It’s described as a logic bug in the Linux kernel’s authentication cryptographic template that allows an attacker to reliably trigger privilege escalation trivially by means of a 732-byte Python-based exploit. According to Theori and Xint, CVE-2026-31431 was the result of a series of unremarkable updates to the Linux kernel over the years, particularly one update from 2017 that was meant to speed up data encryption. As a result, all major Linux distributions from 2017 are impacted. What complicates matters is that Copy Fail works 100% of the time, unlike most local privilege escalation (LPE) bugs that tend to be probabilistic in nature. More worryingly, it leaves no traces on disk as exploitation occurs in memory and enables container escape from any pod in a Kubernetes cluster.
  • TeamPCP’s Supply Chain Attack Spree Continues—TeamPCP’s extensive supply chain campaign continued last week, as the cybercriminal group compromised several packages across the npm, PyPI, and Packagist ecosystems in a «Mini Shai Hulud» attack. TeamPCP has in recent months compromised the packages of several open source software projects, including Trivy, a security scanner maintained by Aqua Security, and KICS, a Checkmarx-developed tool for static code analysis. Amit Genkin, threat researcher at Upwind, said the latest string of attacks represents a shift, where they are not only more frequent but harder to detect because they weaponize legitimate CI/CD pipelines to push out poisoned versions under real identities, allowing the activity to blend in with normal development workflows. «Campaigns like Shai-Hulud take that further by using each compromised pipeline to spread to the next, turning credential theft into a scaling problem across environments,» Genkin said. «For teams, the immediate priority is to check for the affected version and rotate any credentials tied to pipelines that may have run it, especially GitHub and cloud tokens. Longer term, this is a signal to reduce how broadly pipeline credentials are scoped and to add visibility into what’s actually happening during installs and builds – because if you’re relying on traditional scanning or known indicators, this type of activity is easy to miss.»
  • New Python Backdoor Enables Comprehensive Data Theft—A newly identified stealthy Python-based backdoor framework dubbed DEEP#DOOR provides attackers with persistent remote command execution and surveillance capabilities on Windows computers. Once active, the backdoor enables shell command execution, file manipulation, system and network reconnaissance, and surveillance operations such as keylogging, clipboard monitoring, screenshot capture, microphone and webcam access, and credentials and SSH key harvesting. Additionally, the malware can shift from data gathering to disruption and system manipulation, as it can overwrite the Master Boot Record, force system crashes, exhaust system resources by spawning numerous processes, and disable Microsoft Defender services.
  • GitHub Flaw Leads to Remote Code Execution—Cybersecurity researchers from Wiz disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server (CVE-2026-3854, CVSS score: 8.7) that could allow an authenticated user to obtain remote code execution with a single «git push» command. The vulnerability was severe enough that Microsoft rolled out a patch within six days of responsible disclosure. On GitHub.com, it allowed remote code execution on shared storage nodes, and on GitHub Enterprise Server, it granted full server compromise, enabling unauthorized access to all hosted repositories and internal secrets. «Exploitation could expose the codebases of nearly all of the world’s biggest enterprises, making this one of the most severe SaaS vulnerabilities ever found,» a Wiz spokesperson told The Hacker News.
  • VECT 2.0 Ransomware’s Flawed Encryption Makes Data Recovery Impossible—VECT 2.0 ransomware has been found to wipe large files instead of merely encrypting them, making recovery impossible, even for the attackers. VECT 2.0 is a ransomware-as-a-service (RaaS) program that first appeared in December 2025. The group quickly grabbed headlines after it announced on BreachForums that it was partnering with TeamPCP, the threat group behind several supply chain attacks, such as Trivy, Checkmarx KICS, LiteLLM, and Telnyx, in March and April 2026. VECT also announced a partnership with BreachForums itself, promising that every registered forum user will become an affiliate and be granted use of the ransomware, negotiation platform, and leak site for operations. Beazley Security, in an analysis of the ransomware, said the VECT 2.0 RaaS panel covers the «full operational lifecycle an affiliate needs from payload generation through to payout.»

🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-41940 (cPanel and WebHost Manager), CVE-2026-31431 aka Copy Fail (Linux Kernel), CVE-2026-42208 (LiteLLM), CVE-2026-3854 (GitHub.com and GitHub Enterprise Server), CVE-2026-32202 (Microsoft Windows Shell), CVE-2026-26268 (Cursor), CVE-2026-35414 (OpenSSH), CVE-2026-6770 (Mozilla Firefox and Tor Browser), CVE-2026-42167 (ProFTPD), CVE-2026-24908, CVE-2026-23627, CVE-2026-24487 (OpenEMR), CVE-2026-6807 (GRASSMARLIN), CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, CVE-2026-7343 (Google Chrome), CVE-2026-7322, CVE-2026-7323, CVE-2026-7324 (Mozilla Firefox), CVE-2026-6100 (CPython), CVE-2026-0204 (SonicWall), CVE-2026-35414 (OpenSSH), CVE-2026-42511 (FreeBSD), CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687 (Exim), CVE-2026-5402, CVE-2026-5403, CVE-2026-5405, CVE-2026-5656 (Wireshark), CVE-2026-42520, CVE-2026-42523, CVE-2026-42524 (Jenkins), CVE-2026-3008 (Notepad++), and CVE-2025-41658, CVE-2025-41659, CVE-2025-41660 (CODESYS).

🎥 Cybersecurity Webinars

  • Learn to Spot Attack Paths Your AppSec Tools Completely Miss → Modern attackers chain tiny flaws across code, pipelines, and cloud into major breaches — while your AppSec tools stay blind. Join this free webinar with Wiz and The Hacker News to uncover the top real-world attack paths and learn exactly how to spot, map, and stop them fast. Practical insights to prioritize real risks and strengthen your entire software lifecycle.
  • How to Match AI Attack Speed with Autonomous Exposure Validation → Struggling with AI attacks moving faster than your team can respond? Join this free webinar from Picus Security & The Hacker News to discover Autonomous Exposure Validation – how to automatically find real risks, test attack paths, and fix them in minutes, not weeks. Practical, no-fluff insights to stay ahead without burnout. Grab your spot now.
  • Learn Latest AI Threats + Practical Ways to Kill Initial Access → Modern attackers are slipping past traditional defenses with AI-powered phishing, encrypted malware, and stealthy “Patient Zero” tactics. Want to stay ahead? Join this free webinar with Zscaler and The Hacker News to uncover the latest threat trends and practical Zero Trust strategies that actually stop initial compromise — before it becomes a full-blown breach. No fluff, just real insights to protect your organization.

📰 Around the Cyber World

  • OpenAI Debuts Advanced Account Security —OpenAI launched Advanced Account Security, a set of opt-in protections for ChatGPT users «designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available.» As part of the new program, the new controls strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. OpenAI has also partnered with Yubico to link two physical security keys, YubiKey C Nano and YubiKey C NFC, to ChatGPT accounts. That said, users can use any other FIDO-compliant security key, or use software-based passkeys for phishing-resistant authentication.
  • Over 8.8K Ransomware Attacks in 2025 —Fortinet said it recorded 7,831 confirmed ransomware victims globally in 2025, skyrocketing from approximately 1,600 identified victims in 2024. «Availability of crime service kits like WormGPT, FraudGPT, and BruteForceAI contributed to this 389% increase year-over-year (YoY),» Fortinet said. «The top three targeted sectors include manufacturing (1,284), business services (824), and retail (682). Geographic concentration includes the U.S. (3,381), Canada (374), and Germany (291).»
  • KidsProtect Android Surveillance Tool Marketed on the Web —A new Android surveillance tool called KidsProtect is being openly advertised on the clear web that gives an operator near-total secret control of a victim’s phone. «It can’t be removed without the attacker’s permission,» Certo said. «From a web-based dashboard, an operator can secretly record calls, stream live audio from the device’s microphone, track GPS location in real time, read SMS messages and notifications from apps including WhatsApp and Viber, log keystrokes, access contacts and photos, and remotely trigger the front and rear cameras.» Assessed to be the work of a Greek-speaking developer, it’s available on a subscription basis starting from $60, allowing anyone to buy it, rebrand it, and start selling it as their own.
  • New KYCShadow Android Malware Detected —An Android malware masquerading as a bank KYC verification application is being distributed via WhatsApp and primarily targeting users in India. «The application operates as a multi-stage dropper that installs a secondary payload and establishes persistent command-and-control (C2) communication,» CYFIRMA said. «It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data.»
  • Phishing Campaign Targets Pakistan Orgs —A highly targeted spear-phishing campaign targeting the Punjab Safe Cities Authority and PPIC3 in Pakistan has been found to use legitimate-sounding government infrastructure projects as lures to deliver malware. «The email carried two malicious attachments: a Word document with a VBA macro dropper and a PDF with a fake Adobe Reader lure, both delivering payloads from a BunnyCDN-hosted malicious infrastructure,» Joe Security said. «The attack chain establishes persistent remote access by abusing Microsoft’s legitimate VS Code tunnel service, with exfiltration notifications sent via a Discord webhook — a sophisticated technique designed to evade network-level detection.»
  • Calendly-Themed Phishing Attacks on the Rise —Multiple threat clusters are leveraging Calendly-themed phishing to fingerprint site visitors and steal credentials and other data. «Behind the shared Calendly branding sits a diverse set of phishing kits, including API-driven frameworks, real-time Socket.IO applications, fake CAPTCHA chains, and Telegram-based exfiltration,» urlscan said.
  • Fraud Campaigns GovTrapand FEMITBOT Exposed —Threat actors have been observed deploying sophisticated tactics, including fake government portals, SMS phishing, and lookalike domains, to drive financial fraud and credential harvesting as part of an effort called GovTrap. The government impersonation scam mimics official portals with high accuracy, with links to the fake sites distributed via SMS or email. The end goal is to trick users into entering their personal and financial information, or make non-existent payments that are transferred through money mule accounts. The collected payment card details are abused to facilitate fraudulent transactions. Another threat cluster has leveraged FEMITBOT, a malicious infrastructure that abuses Telegram Mini Apps to scale global fraud campaigns and Android malware delivery. «By leveraging Telegram’s native features, threat actors create highly convincing fake platforms across crypto, financial services, AI, and streaming sectors,» CTM360 said. «Built on a modular, template-driven architecture, FEMITBOT enables rapid deployment, brand impersonation, and campaign optimization using real-time tracking and analytics.»
  • New PowerShell Desktop Stealer Spotted —A Pastebin-hosted PowerShell script disguised as «Windows Telemetry Update» comes with capabilities to steal Telegram Desktop session data via Telegram bot API exfiltration. «The script collects host metadata, including username, hostname, and public IP via api.ipify[.]org, then checks for Telegram Desktop and Telegram Desktop Beta tdata directories,» Flare said. «If found, it terminates the Telegram process to release file locks, archives session material into ‘TEMP\diag.zip,’ and uploads the archive to the attacker-controlled operator chat via the Telegram Bot API sendDocument endpoint.»
  • Surge in Teams Phishing in 2026 —eSentire said it has observed an increase in Microsoft Teams-based phishing since early 2026, in which threat actors impersonate IT support and help desk personnel to trick users into granting remote access to their devices. «These phishing attacks have often been linked to email bombing, followed by threat actors reaching out to users under the guise of providing assistance to resolve an issue,» eSentire said. «The objective of the attack is to trick the user into granting remote access to their device, and once obtained, threat actors will attempt to exfiltrate data and execute additional payloads to establish persistence or deploy ransomware.»
  • New KarstoRAT Malware Enables Data Theft —First spotted in early 2026, KarstoRAT is capable of system reconnaissance, audio and webcam monitoring, screenshot capture, key logging, and token theft. It also enables threat actors to download and run additional payloads, which could point to it being used for post-compromise control on infected machines. «KarstoRAT uses a command-and-control (C2) server that has a diverse set of open ports and services, indicating that it has a multi-purpose infrastructure created for C2 communication and payload distribution,» LevelBlue said. «Threat actors use a fake Blox Fruits (a popular Roblox game) virtual marketplace as a lure to trick players into downloading malware that will install KarstoRAT into their machines.»
  • ClickUp Discloses Email Address Exposure —ClickUp said its client-side feature flag configuration exposed personally identifiable information. This included 893 customer email addresses that were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer’s API token. «The exposure was limited to 893 customer email addresses used in feature flag targeting rules to control which users see specific features during rollouts,» it said. «If your email address was among those included in a feature flag configuration, you have been directly contacted.» The incident did not expose any other data.
  • Finnish Authorities Arrest Alleged Scattered Spider Member —Finnish authorities arrested 19-year-old Peter Stokes (aka Bouquet), a dual U.S.-Estonian citizen, as he tried to board a flight to Japan. U.S. prosecutors have charged him as a key member of the notorious Scattered Spider hacking group, and he faces multiple counts of wire fraud, conspiracy, and computer intrusion.
  • New Attacks Linked to Versatile Werewolf —The threat actor known as Versatile Werewolf (aka HeartlessSoul) has been linked to campaigns targeting Russian state structures and aviation companies via phishing emails with malicious archive attachments and malvertising campaigns to deliver a JavaScript trojan. The end goal is to obtain confidential data, particularly geospatial information. Alternatively, the threat actor is known to distribute malicious code using the legitimate SourceForge platform through a project called GearUP. Versatile Werewolf is believed to be active since at least September 2025. Some of the attachments have exploded ZDI-CAN-25373 to trigger the infection chain. The malvertising campaign uses fake domains («battleflight[.]pro») to deliver bogus installers for aviation-related software to launch the same trojan. «The initial infection involves executing PowerShell commands or scripts designed to download a JavaScript loader from C2 servers,» Kaspersky said. «This loader, in turn, loads and executes the main JS-RAT and its modules in memory, among which we found tools for data collection and exfiltration, keyloggers, screen capture tools, UAC bypass tools, and other payloads.» The company noted that the domain «battleflight[.]pro» resolves to an IP address that also hosts fake domains linked to the GOFFEE APT. «Both groups actively use PowerShell payloads to deliver and execute malicious modules,» it added. «GOFFEE also targets the public sector, which suggests the possibility of joint or coordinated campaigns.»
  • Cisco Unveils Model Provenance Kit —Cisco unveiled a new open-source tool, named Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models. «Much like a DNA test reveals biological origins, the Model Provenance Kit examines both metadata and the actual learned parameters of a model (like a unique genome that comprises a model), to assess whether models share a common origin and identify signs of modification,» Cisco said. «This, combined with a constitution that defines provenance linkages, is an important step toward providing evidence-based assurance that the AI you deploy is what it says it is.»
  • Abuse of Hugging Face and ClawHub for Malware Delivery —Threat actors are abusing legitimate AI platforms like Hugging Face and ClawHub for malware delivery, once again demonstrating how trust in AI ecosystems are being exploited. Acronis said it identified more than 575 malicious skills across 13 developer accounts that target both Windows and macOS systems with trojans, cryptocurrency miners, and AMOS stealer, a macOS-focused infostealer. «On Hugging Face, attackers leverage repositories to host payloads and act as staging infrastructure within multistep infection chains, distributing malware disguised as legitimate applications,» Acronis said.
  • European Authorities Bust Cryptocurrency Fraud Ring —Albanian and Austrian authorities dismantled a cryptocurrency investment fraud ring that caused estimated losses of more than €50 million ($58.5 million) to victims worldwide. The operation, which took place over two years, resulted in the arrest of ten individuals, the search of multiple premises, and the seizure of 891,735 in cash, 443 computers, 238 mobile phones, six laptops, and multiple storage devices. «The criminal network, allegedly operating several call centres in Tirana, Albania, is believed to have caused significant financial damage, totalling at least €50 million,» Europol said. «The call centres were professionally set up and organized, resembling legitimate business structures featuring a clear division of roles and hierarchical management.» The criminal network is estimated to have involved up to 450 employees across various departments. The scheme involved luring victims to seemingly legitimate online investment platforms through deceptive advertisements on social media or web searches, and coaxing them into making investments under the promise of huge returns. Victims were then assigned retention agents, who masqueraded as investment advisors and used remote access software to gain full control of their devices. «The fraudsters feigned professional expertise and employed psychological pressure to persuade victims to make additional investments, falsely claiming they would be profitable,» Europol said. «In truth, the funds were never invested but were instead channelled into an intricate international money-laundering scheme, ultimately disappearing into the hands of the criminal organisation.» In some cases, the fraudsters reached out to the victims again and offered help with recovering their stolen funds, only to demand a €500 entry fee and defraud them a second time.
  • Flaws in EnOcean’s SmartServer —Two security flaws have been disclosed in EnOcean’s SmartServer IoT platform that affect version 4.60.009 and prior. According to Claroty: «CVE-2026-20761 allows remote attackers to send malicious, crafted LON IP-852 messages that result in arbitrary command execution on devices. CVE-2026-22885 allows remote attackers to send malicious, crafted IP-852 messages that bypass ASLR memory protections and leak memory.» Successful exploitation of the flaws results in attackers obtaining control over building management and building automation systems running affected versions of this platform and legacy i.LON devices. Patches have been released for both vulnerabilities.
  • Google Announces Android Credential Manager Update —Google has announced a new update to Android’s Credential Manager that allows apps to automatically verify a user’s personal Gmail address without requiring one-time passwords (OTPs) or email verification links. «Google now issues a cryptographically verified email credential directly to Android devices,» the company said. «For users, this completely removes the need to manually verify their email through external channels. For developers, the API securely delivers these verified user claims for any scenario, whether you are building an account creation flow, a recovery process, or a high-risk step-up authentication.»
  • Nearly 8.8K Secrets Leaked Online —According to Truffle Security, 8,792 verified, unique secrets have been leaked online through web-based development environments. The tokens were found across 22 million public projects hosted on Cloud Development Environments (CDEs) such as CodePen, CodeSandbox, JSFiddle, and StackBlitz.
  • Is There More to the Xygeni Compromise? —Multiple connections have been found between the compromise of the Xygeni vulnerability scanner on GitHub and a proxy botnet of hacked ASUS and TP-Link routers. Some of the TP-Link consumer routers have been compromised with Microsocks to unroll them to a residential proxy network. «These routers were also running a custom command-and-control beacon that was named ShadowLink,» Ctrl-Alt-Intel said. «When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply chain attack.»
  • Brazilian Anti-DDoS Firm Behind DDoS Attacks on ISPs —Huge Networks, a Brazilian tech company that specializes in protecting networks from distributed denial-of-service (DDoS) attacks, has been enabling a botnet responsible for massive DDoS attacks against other internet service providers (ISPs) in the country, according to KrebsOnSecurity. The company has since said the malicious activity resulted from an intrusion first detected in January 2026 and claimed it was likely the work of a competitor.
  • Canonical Target of Sustained DDoS Attack —Canonical disclosed its web infrastructure came under a «sustained, cross-border attack,» knocking Ubuntu servers offline for several hours. A pro-Iranian hacktivist group known as the Islamic Cyber Resistance in Iraq, aka 313 Team, claimed responsibility for the attack on Telegram. The websites have since become operational. Last month, the group also disrupted access to the decentralized social media platform Bluesky.
  • New Phishing Kit Bluekit Detailed —A new phishing kit named Bluekit is offering more than 40 templates targeting popular services and includes basic artificial intelligence (AI)-powered features for generating campaign drafts. Available templates can be used to target email accounts (Outlook, Hotmail, Gmail, Yahoo, ProtonMail), cloud and enterprise services (iCloud and Zoho), developer platforms (GitHub), and cryptocurrency services (Ledger). What makes the kit stand out is the presence of an AI Assistant panel that supports multiple models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, to help criminals draft phishing emails. It also has support for two-factor authentication, geolocation emulation, antibot cloaking, notifications, spoofing capabilities, voice cloning, and a mail sender. The development once again reinforces the broader trend of crimeware services integrating AI to streamline and scale their operations. Bluekit is the second kit to integrate AI features in as many months. In April 2026, Abnormal Security shed light on a cybercrime platform called ATHR that uses AI vishing agents, credential harvesting panels, and built-in phishing mailers to execute and scale telephone-oriented attack delivery (TOAD) attacks.
  • North Korea Calls U.S. Cyber Threat Claims a Fabrication — North Korea’s foreign ministry rejected U.S. accusations that the country poses a cyber threat, stating the U.S. was spreading false information about a non-existent cyber threat from North Korea for political purposes, per Reuters. The ministry said it «would actively take all necessary measures for defending the interests of the state and protecting the rights and interests of its citizens in cyberspace.»

🔧 Cybersecurity Tools

  • Model Provenance Kit → It is a free open-source Python tool from Cisco AI Defense that helps identify if a machine learning model is based on a known base model (like Llama, Mistral, GPT, etc.). It analyzes architecture, tokenizer, and weights to quickly compare two models or check against a database of ~150 popular base models.
  • AutoFyn → It is an open-source tool from SignalPilot Labs that runs Claude AI in self-improving loops to optimize measurable goals. Give it a GitHub repo, a clear task (like security hardening, bug fixing, or performance optimization), and a time budget — it works in sandboxed rounds, tracks progress with real evaluations, learns from failures, and delivers improved code via PRs.

Disclaimer: This is strictly for research and learning. It hasn’t been through a formal security audit, so don’t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law.

Conclusion

Stay sharp out there.

The pace of attacks is accelerating, and the margin for delay is shrinking. Patch what you can today, verify your supply chains, tighten SaaS access, and treat every “routine” login or pipeline run as potentially hostile. Small habits now will save major headaches later.

Until next Monday. Keep your defenses tight and your eyes open. The threats won’t wait — neither should we. See you in the next recap.

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades – CYBERDEFENSA.MX

Intro

A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers, and security analysts by impersonating administrative utilities they rely on for daily operations. By integrating Search Engine Order (SEO) poisoning, a dual-stage GitHub distribution architecture, and decentralized blockchain-based command-and-control (C2) resolving, Threat Actors have established a highly resilient delivery and persistence mechanism.

Creative Distribution via GitHub Facades

The campaign utilizes a multi-layered delivery chain designed to evade platform-level takedowns and maintain a high search engine ranking. The attack begins with SEO poisoning on various search engines, including Bing, Yahoo, DuckDuckGo, and Yandex. That ensures that malicious results for niche IT terms rank at the top of search results. Users are initially directed to a primary «facade» GitHub repository. These repositories are optimized for SEO but contain no malicious code – just a professional-looking README file.

To maintain operational flexibility, the README contains a link directing a victim to a second, hidden GitHub repository. It serves as the true distribution point for the malware. By separating the SEO-optimized «storefront» from the payload delivery account, the threat actors can rapidly rotate their distribution repositories if flagged, while the primary search-indexed facade remains active and untouched.

Strategic Tool Impersonation and Victim Profiling

The campaign is characterized by its focus on the administrative stack. By distributing malicious MSI installers disguised as tools like PsExec, AzCopy, Sysmon, LAPS, and Kusto Explorer, the adversary performs automated victim profiling. These utilities are almost exclusively used by personnel with elevated network and system permissions. A successful infection on an administrator’s workstation may provide the «keys to the kingdom, » which can facilitate lateral movement inside the enterprise environment.

Decentralized Command and Control via Ethereum

The most technically significant aspect of the campaign is its implementation of Blockchain-based Dead Drop Resolving (DDR). Once the malicious MSI is executed, the malware does not reach out to a hardcoded domain or IP address, which could be easily blocklisted. Instead, the malware repetitively initiates a query to a public Ethereum (ETH) RPC endpoint.

The malware is hardcoded with a specific Smart Contract address on the Ethereum blockchain. By querying this contract, malware dynamically retrieves the live C2 server address. This technique provides the adversary with extreme resilience:

  • Infrastructure agility: The attacker can rotate C2 servers globally simply by updating the value stored in the blockchain contract.
  • Robustness: As long as public Ethereum gateways are accessible, the malware can always find its «home,» making traditional domain takedown or blockage efforts ineffective.

Research analysis

This research provides a comprehensive technical analysis of the current campaign, based on long-term observation and active detonation within a controlled environment. Our research moves beyond initial delivery vectors to examine the sophisticated infrastructure and post-exploitation behaviors.

The following data points represent the core operational mechanics of the campaign, including:

  • Malware Distribution: breakdown of the dual-stage GitHub repository architecture and the SEO-poisoning usage to manipulate search engine results.
  • Administrative Tools Impersonation: adetailed look at the specific administrative utilities being impersonated to ensure the compromise of high-privilege IT personnel.
  • Malware Logic: malware analysis of the malicious MSI payloads, including their initial staging and persistent components.
  • Decentralized C2 Infrastructure: investigation into the malware’s use of Ethereum Smart Contracts and public RPC gateways to dynamically resolve live Command and Control (C2) addresses.

NOTE: During the finalization of the research, we identified a preliminary alert from KISA&KrCERT/CC regarding this threat actor’s campaign – LINK. While their initial report provided early visibility, our longitudinal investigation confirms the campaign remains highly active and has undergone significant technical maturation.

Our investigation further confirms that the malware is evolving, with several distinct variants and additional C2 infrastructure identified since the campaign’s inception. 

Find out the latest threat intelligence and adversary research insights on Atos Cyber Shield Blogs.

Malware Distribution

Visualisation below demonstrates the dual-stage distribution chain, where SEO-optimized facade repository redirects unsuspecting users to a secondary GitHub account hosting the malicious MSI. This modular architecture allows the threat actors to preserve their search engine rankings even if the individual payload delivery accounts are taken down.

The intrusion lifecycle begins with a search query via Bing (also Yahoo, DuckDuckGo, Yandex) for specialized IT administrative utilities. Through aggressive SEO poisoning, the threat actors ensure that the facade GitHub repository appears prominently among the top search results. In this instance, a user seeking Kusto Explorer – acritical tool for engineers and analysts querying Azure Data Explorer via KQL – is led toward a non-malicious storefront designed to build initial trust.

Bing search for “kusto explorer”
Bing search for “kusto explorer download”

The first repository the user opens is a storefront that impersonates the targeted administrative tool. This facade repo is intentionally clean of malware, acting only as a gateway to the second, malicious stage of the delivery process. Thanks to such a design, it maintains a high search engine ranking.
First GitHub repo – used only as a facade

First GitHub repo – used only as a facade
As we can see it’s the one that survives quite long time

By embedding a link in the README of a clean facade repository, Threat Actors effectively separate their search visibility from their malware distribution. This second repository hosts the actual malware, while the first remains untainted. This strategy allows for rapid recovery after a takedown, as the adversary only needs to update a single URL to restore their infection chain. This separation is key to the campaign’s longevity, as the initial landing page appears benign to both users and security tools.

Link to second GitHub repo that serves malware to the user
Historical Commits in facade GitHub: we can see changes of links to second GitHub repo

The redirection leads the user to a second GitHub repository where the malicious software is hosted. This secondary site acts as the final stage in the distribution chain, providing the direct download for the malware impersonating administrative tools.

Second GitHub used to host malware
Malware downloaded by user

The threat actor has successfully hijacked the search results for larger set of Windows administrative stack, placing malicious storefronts at the very top of Bing. This dominant search presence effectively masks the threat, as the facade repositories appear as the primary, verified download locations for essential IT tools. Such high visibility on the front page is the critical factor that could help campaign’s broader reach into corporate environments.

“ProcDump” Bing SEO poisoning and Threat Actors GitHub repo
“LAPS” Bing SEO poisoning and Threat Actors GitHub repo
“BgInfo” Bing SEO poisoning and Threat Actors GitHub repo
DuckDuckGo SEO poisoning and Threat Actors GitHub repo
Yandex SEO poisoning and Threat Actors GitHub repo
Yahoo SEO poisoning and Threat Actors GitHub repo

Between early December 2025 and April 1, 2026, the threat actor deployed 44 separate GitHub facades, each spoofing a different administrative or developer tool. This high-volume approach indicates a sustained effort to maximize search engine visibility and capture a diverse range of high-privilege victims.

Total 44 malicious GitHub repositories identified

Administrative Tools Impersonation

Category Impersonated tools
Sysinternals / Diagnostics Autoruns, ProcDump, RAMMap, TCPView, Process Monitor, Process Explorer, Disk2vhd, Sysmon, DebugView, WinDbg, BgInfo
AD / Credential / Admin Windows ADK, Windows LAPS, RSAT, IIS Crypto, Profwiz, PCmover, Transwiz, Delprof2
Remote Access Dameware, SecureCRT, SuperPuTTY, ScreenConnect Client, Bitvise SSH Client, TeraTerm
Data Transfer / Cloud AzCopy, FSLogix, PCmover, Transwiz
Security / Auth AppLocker, SafeNet Authentication Client, NSSM
Network / Debugging PRTG Network Monitor, HTTP Debugger
Utility / Business Apps KDiff3, Beyond Compare, BarTender, PaperPort
Misc Sysadmin Tools Autologon, Kusto Explorer, LEAP Desktop, VMware Tools

Identified Threat Actors campaign specifically targets the professional toolsets of enterprise administrators, systems engineers, and security practitioners. Unlike traditional malware campaigns that cast a wide net across general consumers, this activity is surgically focused on the «crown jewel» accounts of the enterprise. By leveraging Search Engine Optimization (SEO) poisoning, theadversary is distributing malicious MSI installers that mimic essential infrastructure management and diagnostic tools. The primary objective is the compromise of high-privilege credentials and the establishment of persistent backdoors within corporate environments, which can lead to large-scale breaches.

The current threat landscape is defined by the strategic impersonation of utilities foundational to modern IT operations, such as PsExec, AzCopy, Sysmon, and LAPS. The rationale for selecting these specific targets is rooted in an advanced victim profiling model. Because a standard user very rarely interacts with a debugger like WinDbg or a deployment kit like Windows ADK, the adversary ensures that every successful infection lands on a machine belonging to a user with elevated system or network permissions.

The psychological component of this campaign is also particularly aggressive. Many of these utilities are the tools defenders use to investigate malicious activity. This creates an «irony lure» where a security professional, attempting to diagnose a perceived issue using a tool like Process Explorer or TCPView, inadvertently introduces a threat. By delivering these via legitimate-looking MSI packages, the attackers bypass the initial suspicion often associated with raw scripts or standalone executables.

The consequences of an infection might be devastating. Given the administrative nature of the victims, this often transitions into a «keys to the kingdom» scenario.

Find out the latest threat intelligence and adversary research insights on Atos Cyber Shield Blogs.

Malware Logic

Atos TRC has analyzed a number of .msi installers from identified malicious repositories. Since the malware evolved over time this analysis focuses on its latest variant. All paths, file names, extensions, and keys shown are specific to one single sample as they are randomly generated for each.

This malware is a multi-stage, fileless-style Remote Access Trojan (RAT) written in  JavaScript, delivered as a malicious MSI installer impersonating various IT administration and enterprise sysadmin tools. It uses layered AES-256-CBC encryption to conceal its payload, a blockchain-based dead-drop resolver for resilient C2 communication, and an AsyncFunction constructor engine for arbitrary remote code execution. Node.js is downloaded at runtime from nodejs.org rather than bundled, keeping the package small (~4.7 MB) at the cost of requiring internet access during infection. Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.

Latest versions of installers consist of four files. When the MSI is executed, these files are extracted, and a CMD batch script is run via a Custom Action, initiating the chain that leads to RAT deployment:

MSI content screenshot

It is important to note that file extensions differed among the analyzed samples, but “.cmd” was always the initiating file. The table contains a few examples:

Stage # Extensions
Sample #1 Sample #2 Sample #3 Sample #4
0 – Dropper .cmd .cmd .cmd .cmd
1 – In-memory loader .bak .cfg .xml .tmp
2 – Loader/Persistence .xml .bak .bak .dat
3 – RAT .cfg .bin .xml .log

File names, decryption keys, secrets, directory names, and extensions presented below are extracted from the latest installer version.

STAGE 0 – DROPPER

File: VW80IqXy.cmd (2,377 bytes)

Stage 0 code screenshot

The malware’s entry point is a heavily obfuscated Windows batch script (VW80IqXy.cmd), launched at SYSTEM privilege by the MSI CustomAction immediately after file extraction. Its primary obfuscation mechanism splits all sensitive command names – including curl, tar, copy, start, and cmd – across multiple SET variable assignments that are silently concatenated at runtime, ensuring no recognizable keywords appear in the raw file and defeating simple string-based static analysis. To ensure execution in a hidden window regardless of how the MSI launched it, the script immediately re-launches itself as a minimized background process and exits, with the re-launched copy performing all actual work. That copy proceeds to create a build-specific staging directory under %LOCALAPPDATA%\, download the Node.js runtime from its official distribution endpoint to a temporary archive via curl, extract it into a build-specific runtime subdirectory within the staging directory, and delete the zip archive to minimize forensic artifacts on disk. With the environment prepared, the script hands off execution to Stage 1 by invoking the bundled node.exe against the first-stage payload file and terminates, carrying no persistence mechanism of its own and playing no further role in the infection chain.

Stage 0 simplified graph (link to detailed)

STAGE 1 – In-memory loader

File: ZOVTSc3WW9wotbj.bak (472 bytes)

Stage 1 code screenshot

A minimal Node.js script. Unobfuscated and fully readable. It is never saved onto the disk. Its main goal is to read the file containing the second-stage payload (in this example, “tQqoxkAJFhqWtg5.xml”), decrypt it using a hardcoded key and initialization vector (IV), and execute it in memory via “module._compile()”

AES-256-CBC credentials from example:

  • Key : F4J/454U+W0+8y7L+L9MxSY15rB0KoSeQkPauifCTiQ=
  • IV  : RXvUsgFBwDx9HuOhpkoiqQ==
Simplified Stage 1 graph (link to detailed)

STAGE 2 – Loader/Persistence

File: tQqoxkAJFhqWtg5.xml (2,096 bytes encrypted)

Stage 2 code screenshot
Stage 2 decrypted code screenshot

Decrypted and executed in-memory by Stage 1. It is an intermediary stage that decrypts the content of obfuscated stage 3 payload (0cZeeDPZMsxWtaK.cfg), writes this content into a new file (4S3HKjraAP.cfg) and then executes it via node.exe wrapped by “conhost.exe –headless”, which disguises the process in Task Manager as a standard console host. Additionally, it creates persistence via the registry Run key.

AES-256-CBC credentials from example:

  • Key : m+wOc81aCEKfGEOpZsEr8WAN4O8mJnEoalp3LwZau0A=
  • IV  : cOoXZ1ImLZ/V90MLhCpVJw==

Registry persistence from example:

  • Key  : HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • Name : <6-byte random hex, regenerated on every fresh install>
  • Data : conhost.exe –headless 1FgUre\node.exe 4S3HKjraAP.cfg
Simplified Stage 2 graph (link to detailed)

STAGE 3 – RAT

File: 0cZeeDPZMsxWtaK.cfg (encrypted) / 4S3HKjraAP.cfg (plaintext, ~9.8 KB)

Stage 3 code screenshot
Stage 3 decrypted code screenshot

Stage 3 is the malware’s main payload – a JavaScript file that runs silently in the background on every system boot. It is written to disk under a randomly generated filename with a non-descriptive extension, making pattern-based file detection unreliable across different malware distributions. It runs inside conhost.exe, a legitimate Windows process, so it does not stand out in Task Manager. All strings inside the file – including server addresses and API names – are encrypted, making static analysis difficult.

When executed, the RAT first assigns to the infected machine a persistent identity. It reads a unique bot ID from a hidden file on disk or generates a fresh one if the file does not yet exist and stores it for use in all future communication. It also computes a working directory path derived from the machine’s username and computer name, making that path unique on every victim system.

RAT’s next task is to find out where its command-and-control server is. Rather than hardcoding a server address directly, which could be blocked by defenders, the attacker stores the address inside an Ethereum smart contract on the blockchain. RAT queries nine public Ethereum API services in parallel and picks the answer that the majority return – this makes the lookup reliable even if some services are temporarily down. Because the address lives on the blockchain, it cannot be taken down by blocking a domain or an IP address; the attacker can update it at any time by sending a single transaction. Independent of everything else, a background timer re-runs this blockchain lookup every five minutes, so if the attacker publishes a new server address, the RAT switches to it automatically on its next contact attempt without needing to restart.

Once the C2 address is known, the RAT enters a continuous polling loop, repeatedly beaconing to the server to check for new commands. Each request is constructed to resemble an ordinary browser fetch for a static web asset — the URL path contains random hex segments, a randomly chosen common file extension (.png, .jpg, .gif, .css, .ico, or .webp), and a randomly selected query parameter name. While every beacon looks different to a network observer, each one also silently carries the bot’s unique ID and a campaign identifier baked into the build, allowing the attacker’s server to recognize and track each victim individually. RAT also sends its own source code to the server and receives back a freshly obfuscated replacement, which it writes over itself on disk, effectively re-encrypting itself once every execution, whether it was from “.msi” or a persistent Run registry key. Commands from the attacker arrive as JavaScript code and are executed directly inside the running Node.js process, giving the attacker full access to the file system, the ability to run any OS command, and the ability to exfiltrate data – all without ever dropping a traditional executable to disk.»

Every action that the malware makes, like startup, blockchain resolution, re-obfuscation, every poll request, task receipt, task execution, errors, URL updates are being written to %APPDATA%\\svchost.log, keeping a complete operational trace of everything the RAT does.

For all samples analyzed, the same 9 endpoints were queried to obtain the C2 address from the contract. 

The earlier versions of this malware had a lower number of stages used from the moment of execution until the C2 communications and followed the same file extension pattern: .msi -> .cmd -> .js -> obfuscated file with no clear extension. Additionally, the oldest sample Atos Researcher was able to find had fallback C2 IP hardcoded inside the RAT logic to use when the smart contract was unresponsive. This C2 IP was the same as the first value set for the smart contract from this oldest sample (hxxp[://]135[.]125[.]255[.]55).

Simplified Stage 3 graph (link to detailed)

Decentralized C2 Infrastructure

The campaign implements a decentralized C2 model that does not rely on fixed domains or attacker-controlled servers. Instead, the malware retrieves its C2 address from the Ethereum blockchain. Each sample contains the address of a specific Ethereum smart contract, which is queried periodically via multiple public Ethereum RPC services. In this context, a smart contract is a small piece of program logic stored on the blockchain that can hold data and return it on request in a consistent and verifiable way. This design enables centralized C2 changes without modifying or redeploying the malware, increasing resilience against takedown and blocklisting efforts.

For the purpose of this explanation, we used one of the contracts used by attackers (0xc12c8d8f9706244eca0acf04e880f10ff4e52522) and the wallet that funded it (0x37ef6e88425613564b2cf8adc496acff4b6481a9).

The smart contract used for C2 resolution is implemented as an on‑chain coordination mechanism and shows clear signs of operational use during its lifetime. Its blockchain record exposes a defined contract address, a fixed creation timestamp, and a sequence of transactions submitted over time. The observed activity indicates that the contract instance is actively used as part of a broader and persistent C2 resolution architecture, even though individual smart contracts may be replaced or rotated as the campaign evolves. 

Etherscan contract overview page

The contract can be directly associated with the Ethereum wallet that deployed it. Review of the wallet’s activity shows repeated interactions with the same contract during its operational period, demonstrating that control over C2 resolution is exercised through blockchain transactions. This confirms that changes to C2 distribution are performed independently of the malware already deployed on compromised systems.

Etherscan wallet page

Analysis of the contract’s transaction history reveals multiple state-changing calls used to update values stored on-chain. Each of these updates corresponds to a change in the C2 address retrieved by the malware during its regular resolution cycle. As a result, infected systems automatically redirect to the new backend infrastructure without requiring any additional payload delivery or local configuration changes.

Etherscan contract transaction list highlighting repeated state‑changing calls (Set String)

At the transaction level, a single state-changing operation is sufficient to redirect all active infections. Detailed inspection shows that one blockchain write operation, submitted from the operator’s wallet, modifies the contract state and is immediately reflected in subsequent C2 resolution attempts by the malware. This replaces traditional infrastructure management steps -such as domain registration, DNS updates, or server redeployment -with a single on-chain transaction.

Detailed Etherscan view of a single state‑changing transaction, including timestamp, sender, and input data

By anchoring C2 resolution to blockchain state and resolving it through widely available public Ethereum services, the campaign moves a critical dependency of its control infrastructure onto a decentralized network designed for high availability. This substantially limits the effectiveness of conventional disruption techniques based on domain seizure, IP blocking, or server takedown, and contributes to the operation’s overall resilience and longevity.

Full list of found malicious domains as well as wallets and contracts to distribute them is available for download and review at the TRC GitHub repository.

Conclusions

As of the day of writing this article, the Administrative Utility Spoofing campaign remains a highly active and technically resilient threat to enterprise environments. Our research confirms that this is not merely an opportunistic malware cluster, but a more sophisticated operation designed for specific victim profiling. By impersonating the specialized utilities required for infrastructure management, the adversary has “automated” the discovery of high-privilege IT personnel, increasing the probability that successful infections provide immediate pathways for lateral movement into the corporate environment.

The campaign’s operational longevity is rooted in two strategic factors: the dual-stage GitHub distribution architecture and the integration of decentralized blockchain-based C2 resolution. The use of SEO-optimized «facade» repositories allows the threat actors to maintain front-page visibility on search engines while isolating their malicious payloads on secondary accounts that can be rapidly rotated. Furthermore, the EtherHiding module’s reliance on Ethereum smart contracts creates an infrastructure that is particularly difficult to dismantle.

Malware analysis of the MSI payload distributed across this campaign identifies it as an EtherRAT, a modular Node.js backdoor distinguished by its high-resilience «EtherHiding» C2 module. The Sysdig Threat Research Team has previously linked this malware to the North Korean state-sponsored actor – Lazarus Group. They noticed significant overlaps in the tooling utilized during operations conducted with the usage of EtherRAT and the “Contagious Interview” campaign.

Furthermore, in March 2026, eSentire’s Threat Response Unit (TRU) investigated an open-directory web server attributed to Iranian state-sponsored group MuddyWater (APT34). During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic. Their analysis documented extensive code commonalities between EtherRAT and the Tsundere malware.

Active Atos TRC monitoring confirms that this operation is not yet another high-velocity stealer campaign. While commodity malware often prioritizes immediate data exfiltration, these actors demonstrate a focus on operational patience and stealth. Following the initial breach, we have documented a transition to methodical hands-on-keyboard activities characterized by a deliberate approach to environmental discovery.

The adversary avoids aggressive, high-volume scanning that might trigger behavioural alerts, opting instead for quiet discovery to map the network’s high-privilege architecture. This measured pace indicates that the primary objective is sustained persistence and strategic access rather than a simple opportunistic extraction. By carefully profiling the environment before escalating their activity, the threat actors significantly increase their chances of remaining undetected within enterprise networks.

In alignment with our commitment to proactive defense, the Atos Threat Research Center has initiated formal takedown actions against the identified malicious scheme in order to neutralize distribution channels and disrupt the campaign’s operational resilience.

Recommendation

To mitigate the risks associated with the Administrative Utility Spoofing campaign, organizations should implement the following defensive measures:

  • Restrict Decentralized Infrastructure Access: block access to the public Ethereum (ETH) RPC endpoints used by EtherRAT, attached in the Appendixes’ section. These gateways are the primary heartbeat for the decentralized C2 resolution mechanism.
  • Retrospective Communication Review: review of historical logs to identify any outbound communications with the listed RPC ETH endpoints and identified historical C2 domains identified in this research.
  • Tool Provenance & Administrative Awareness: increase awareness among IT personnel regarding using verified internal software centers or direct, authenticated vendor portals for all administrative tools. It is important to educate administrators on the potential risks of sourcing critical utilities from search engine results.
  • Behavioural Threat Hunting: following behavioural patterns should be reviewed in the given for organization telemetry:
  • repeated, high-frequency beacons (every 500ms) to suspicious external domains
  • periodic outbound requests (every 30000ms or 5 minutes) to public ETH RPC endpoints
  • suspicious process tree: node.exe processes executing shell commands, which may indicate the secondary stages of the EtherRAT payload
  • usage of conhost.exe with the –headless argument, a common artifact of the malware’s attempts to maintain a silent background presence.

Appendixes

A complete list of Indicators of Compromise (IoCs), mapped TTPs, and detailed malware relationship graphs for this campaign are available for download and review at the TRC GitHub repository.

Find out the latest threat intelligence and adversary research insights on Atos Cyber Shield Blogs.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Los investigadores descubren un fallo crítico en GitHub CVE-2026-3854 RCE que se puede explotar mediante un solo Git Push – CYBERDEFENSA.MX

Investigadores de ciberseguridad han revelado detalles de una vulnerabilidad de seguridad crítica que afecta a GitHub.com y GitHub Enterprise Server y que podría permitir a un usuario autenticado obtener la ejecución remota de código con un solo comando «git push».

El defecto, rastreado como CVE-2026-3854 (Puntuación CVSS: 8,7), es un caso de inyección de comandos que podría permitir a un atacante con acceso push a un repositorio lograr la ejecución remota de código en la instancia.

«Durante una operación de git push, los valores de las opciones de inserción proporcionados por el usuario no se desinfectaron adecuadamente antes de incluirlos en los encabezados de servicio internos», según un Aviso de GitHub por la vulnerabilidad. «Debido a que el formato del encabezado interno utiliza un carácter delimitador que también podría aparecer en la entrada del usuario, un atacante podría inyectar campos de metadatos adicionales a través de valores de opciones de inserción diseñados».

A la empresa de seguridad en la nube Wiz, propiedad de Google, se le atribuye el mérito de descubrir e informar el problema el 4 de marzo de 2026, y GitHub validó e implementó una solución en GitHub.com en dos horas.

La vulnerabilidad también se solucionó en las versiones 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0 o posteriores de GitHub Enterprise Server. No hay evidencia de que el problema haya sido explotado alguna vez en un contexto malicioso.

Ciberseguridad

Según GitHub, el problema afecta a GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Cloud con residencia de datos, GitHub Enterprise Cloud con usuarios administrados empresariales y GitHub Enterprise Server.

En esencia, el problema surge del hecho de que los usuarios opciones de inserción de git no se desinfectan adecuadamente antes de que los valores se incorporaran al encabezado interno X-Stat. Debido a que el formato de metadatos internos se basa en un punto y coma como carácter delimitador que también podría aparecer en la entrada del usuario, un mal actor podría aprovechar este descuido para inyectar comandos arbitrarios y ejecutarlos.

«Al encadenar varios valores inyectados, los investigadores demostraron que un atacante podría anular el entorno en el que se procesó el envío, evitar las protecciones de espacio aislado que normalmente limitan la ejecución del enlace y, en última instancia, ejecutar comandos arbitrarios en el servidor», dijo el director de seguridad de la información de GitHub, Alexis Wales. dicho.

Wiz, en un anuncio coordinado, señaló que el problema es «notablemente fácil» de explotar y agregó que permite la ejecución remota de código en nodos de almacenamiento compartido. Alrededor del 88% de los casos son actualmente vulnerables al problema en el momento de su divulgación pública. La cadena de ejecución remota de código encadena tres inyecciones:

  • Inyectar una no producción rieles_env valor para omitir la zona de pruebas
  • Inyectar dir_ganchos_personalizados para controlar para redirigir el directorio de gancho
  • Inyectar repo_pre_receive_hooks con una entrada de gancho diseñada que activa el recorrido de la ruta para ejecutar comandos arbitrarios como usuario de git

«Con la ejecución de código sin espacio aislado como usuario de git, teníamos control total sobre la instancia de GHES, incluido el acceso de lectura/escritura al sistema de archivos y la visibilidad de la configuración del servicio interno», dijo el investigador de seguridad de Wiz, Sagi Tzadik. dicho.

Ciberseguridad

En cuanto a GitHub.com, un indicador de modo empresarial, que está configurado en «verdadero» para GitHub Enterprise Server, tiene por defecto «falso», lo que deja inactiva la ruta de los enlaces personalizados. Pero dado que este indicador también se pasa en el encabezado X-Stat, es igualmente inyectable usando el mismo mecanismo, lo que resulta en la ejecución de código también en GitHub.com.

Para empeorar las cosas, dada la arquitectura multiinquilino de GitHub y su infraestructura backend compartida, la compañía señaló que obtener la ejecución de código en GitHub.com permitía la exposición entre inquilinos, lo que permitía efectivamente a un atacante leer millones de repositorios en el nodo de almacenamiento compartido, independientemente de la organización o el usuario.

A la luz de la gravedad de CVE-2026-3854, se recomienda a los usuarios que apliquen la actualización inmediatamente para una protección óptima.

«Un solo comando git push fue suficiente para explotar una falla en el protocolo interno de GitHub y lograr la ejecución del código en la infraestructura backend», dijo Wiz. «Cuando varios servicios escritos en diferentes idiomas pasan datos a través de un protocolo interno compartido, las suposiciones que cada servicio hace sobre esos datos se convierten en una superficie de ataque crítica».

«Alentamos a los equipos que crean arquitecturas multiservicio a auditar cómo fluye la entrada controlada por el usuario a través de protocolos internos, especialmente cuando la configuración crítica para la seguridad se deriva de formatos de datos compartidos».