{"id":1607,"date":"2026-07-16T17:37:51","date_gmt":"2026-07-16T17:37:51","guid":{"rendered":"https:\/\/cybercolombia.co\/index.php\/2026\/07\/16\/game-cheat-spyware-24-hour-ransomware-chrome-sync-stalking-12-more-stories-cyberdefensa-mx\/"},"modified":"2026-07-16T17:37:51","modified_gmt":"2026-07-16T17:37:51","slug":"game-cheat-spyware-24-hour-ransomware-chrome-sync-stalking-12-more-stories-cyberdefensa-mx","status":"publish","type":"post","link":"https:\/\/cybercolombia.co\/index.php\/2026\/07\/16\/game-cheat-spyware-24-hour-ransomware-chrome-sync-stalking-12-more-stories-cyberdefensa-mx\/","title":{"rendered":"Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories \u2013 CYBERDEFENSA.MX"},"content":{"rendered":"<div id=\"articlebody\">\n<p>A lot of this week\u2019s trouble starts with something that looks close enough.<\/p>\n<p>A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.<\/p>\n<p>Old bugs are back, weak defaults are earning their keep, and some attack paths are so plain they barely feel like research. Here\u2019s the mess.<\/p>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Game cheats drop spyware<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers 11 malicious NuGet packages published as .NET command-line tools that present themselves as game utilities, bots, and \u00abpanels,\u00bb each of which act as a first-stage downloader responsible for fetching and executing a second-stage Python payload named \u00abpepesoft.exe\u00bb from GitHub Releases and Hugging Face paths under the username \u00abpepegit666,\u00bb along with a dormant BitTorrent fallback mechanism built into it. \u00abThe recovered payloads use downloader-supplied AWS-style key material to retrieve remote configuration, authenticate to Google Sheets, bind activations to hardware, and honor a remote HWID\/UUID ban-list,\u00bb Socket <a href=\"https:\/\/socket.dev\/blog\/11-malicious-nuget-tools-pose-as-game-cheats\" target=\"_blank\">said<\/a>. \u00abIn the three direct-bytecode payloads, the larger game-automation application also exposes Telegram bot commands that can send screenshots back to the configured chat.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake installers deploy RATs<\/span><\/p>\n<p class=\"td-desc\">\n      UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary, has been observed conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. The activity delivers a Python-based remote access tool (RAT) dubbed Starland RAT and a command-and-control (C2) memory implant known as WLDR agent using trojanized installer lures for software like developer tooling, IT administration utilities, enterprise collaboration platforms, and consumer gaming applications (e.g., MobaXterm, WebEx, Zoom, DBeaver, and FaceIT). \u00abThe WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads,\u00bb Cisco Talos <a href=\"https:\/\/blog.talosintelligence.com\/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign\/\" target=\"_blank\">said<\/a>. Alternatively, UAT-11795 has been linked to the deployment of CastleStealer and Remcos RAT. The malware is designed to target victims\u2019 credentials and cryptocurrency wallet assets, harvest Active Directory information, and establish a persistent connection to the victims\u2019 machines from the C2 server, likely with an aim to deliver and execute further payloads. The majority of the infections are in the U.S., with fewer potential impacts recorded in Germany, Romania, and Venezuela. The attack chain makes use of ClickFix lures to distribute HTA scripts, which then download and run trojanized installers to deliver Starland RAT, which then uses \u00abcurl.exe\u00bb to execute a PowerShell stager for decrypting and running WLDR agent. In recent weeks, ClickFix has also served as a conduit for TELEPUZ, a modular malware, and <a href=\"https:\/\/www.group-ib.com\/blog\/clicklock-stealer-macos-malware\/\" target=\"_blank\">ClickLock Stealer<\/a>, a macOS-focused information and cryptocurrency wallet stealer targeting users in Europe, North America, and MEA. \u00abClickLock Stealer targets data from 8 browsers, 31 crypto wallet browser extensions, 7 password manager extensions, 8 desktop wallet applications, extracts blockchain addresses across 6 chains, macOS Keychain, shell history, and FTP credentials,\u00bb Group-IB said.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Network encrypted within hours<\/span><\/p>\n<p class=\"td-desc\">\n      An IT services company in South Asia was targeted by a previously undocumented ransomware family called Spirals in June 2026. \u00abThe Rust-based payload is either a new ransomware threat or one purpose-built for this attack,\u00bb Broadcom\u2019s Symantec and Carbon Black Threat Hunter Team <a href=\"https:\/\/www.security.com\/threat-intelligence\/ransomware-spirals-extortion\" target=\"_blank\">said<\/a>. \u00abLess than 24 hours after the initial breach, the ransomware payload was being pushed to machines on the network.\u00bb The attacker is said to have obtained initial access by compromising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established persistent access, conducted reconnaissance, uninstalled endpoint security software, dumped the Security Account Manager (SAM) hive, and set up covert remote access prior to deploying the payload across the network using PsExec. The ransom note seeks to apply pressure by threatening to publish stolen data after six days if a ransom is not paid and directs victims to a Tor portal for negotiations. The actor behind the attack remains unknown.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Actively exploited flaws<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/15\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">added<\/a> CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite, and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4346\" target=\"_blank\">CVE-2023-4346<\/a>, an overly restrictive account lockout mechanism vulnerability in KNX Association KNX Protocol Connection Authorization Option 1, to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring federal agencies to apply the fixes by July 18 and 29, 2026, respectively. Reports about active exploitation of CVE-2026-46817 emerged late last month. It\u2019s currently not known how the KNX Protocol flaw is being abused and by whom.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">New rules for vulnerability reports<\/span><\/p>\n<p class=\"td-desc\">\n      CISA, in partnership with the National Security Agency (NSA), Japan Computer Emergency Response Team Coordination Center (JPCERT\/CC), Netherlands\u2019 National Cyber Security Centre (NCSC-NL), and United Kingdom\u2019s National Cyber Security Centre (NCSC-UK), has published <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-and-partners-publish-guidance-help-software-manufacturers-and-online-service-providers-work\" target=\"_blank\">joint guidance<\/a> to \u00abhelps software manufacturers and online service providers collaborate effectively with security researchers who identify weaknesses in software, networks, and hardware in a structured, transparent framework.\u00bb The agency said a \u00abwell-defined coordinated vulnerability disclosure (CVD) program enables software manufacturers and online service providers to better assess potential risk, improve their vulnerability management processes, and make informed decisions that improve product security for their customers.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">700-person scam network dismantled<\/span><\/p>\n<p class=\"td-desc\">\n      Authorities from the Netherlands have arrested a 46-year-old man with Israeli and Polish citizenship, who is alleged to be behind an international criminal organization with more than 700 employees who were employed at about 20 fraudulent call centers. These individuals posed as financial advisors to conduct investment fraud. \u00abBy maintaining regular contact, sometimes over a period of months, these scammers build a bond of trust with their victims,\u00bb the Dutch police <a href=\"https:\/\/www.politie.nl\/nieuws\/2026\/juli\/15\/02-criminele-organisatie-met-700-medewerkers-verdachten-beleggingsfraude-gearresteerd.html\" target=\"_blank\">said<\/a>. \u00abThe initial deposit is always a relatively small amount that yields an immediate profit. The online platform where victims can view their investments is indistinguishable from the real thing, yet in reality, no actual investments are being made. Scammers use a friendly approach and cunning tactics to manipulate victims into depositing ever-larger sums. The money \u2013 often cryptocurrency \u2013 that victims believe they are investing ends up in the scammers\u2019 pockets.\u00bb The operation has also led to the arrest of four \u00abfinancial advisors.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">\u20ac140M fraud network disrupted<\/span><\/p>\n<p class=\"td-desc\">\n      Spanish National Police have disrupted a cybercrime network accused of stealing and laundering about \u20ac140 million through fake investment platforms, CEO fraud, invoice fraud, and adversary-in-the-middle attacks across Europe. Four people have been apprehended in connection with the operation: two in Portugal, one in Spain, and one in Panama. \u00abThe suspects established and managed a network of over 800 bank accounts to receive substantial sums of illicit money swindled from numerous victims; these funds were immediately dispersed and concealed across another network of accounts, creating a chain of transactions that safeguarded the criminal proceeds and allowed the vast amounts of defrauded money to be hidden and laundered through \u2018money mule\u2019 accounts in third countries,\u00bb police <a href=\"https:\/\/policia.es\/_es\/comunicacion_prensa_detalle.php?ID=16947\" target=\"_blank\">said<\/a>. \u00abTo create the complex web of accounts used for money laundering, the group utilized an extensive network of money mules \u2013 European citizens who had arrived in Spain from other countries \u2013 to set up companies and subsequently open bank accounts across Spanish territory.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Windows bind links evade EDR<\/span><\/p>\n<p class=\"td-desc\">\n      Bitdefender Labs has demonstrated three attack techniques in which Windows\u2019 bind links can be misused to evade endpoint detection and response (EDR) products. \u00abWindows includes a file-system virtualization feature that can redirect one local path to another without modifying the original file or leaving a persistent filesystem artifact,\u00bb Bitdefender\u2019s Martin Zugec <a href=\"https:\/\/businessinsights.bitdefender.com\/bind-link-abuses-windows-feature-edr-evasion-technique\" target=\"_blank\">said<\/a>. \u00abIt is implemented by bindflt.sys, the Bind Filter minifilter driver, and used legitimately by Store apps, Windows Sandbox, and Windows containers.\u00bb The techniques can be leveraged by an attacker running as a local administrator to bypass EDR sensors and built-in Windows defenses such as AMSI and AppLocker. The techniques include: File-Binding, Process-Binding, and Silo-Binding, each of which shadow a trusted file or DLL path, a trusted executable path, and a user-defined Windows silo. Microsoft has assessed the findings as low severity because it requires administrator access.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRGal4SRCJVsoYC5P8dnP1TTuBA3-Pu4LFyI_mTudvIuJRToG6TzseFb-FcrOzaTYum1HyeE5-9aD6Yb6Fuj0x6MQg-lUtnpx1E9ooixrC51F_drRHQzH155SAGyGo4WJDU_59wW609-7O8-5-AcWr_Gp2h-vpC7zl8eu0xIgP0hvwx0q2mmajbZV5iN4t\/s1700-e365\/bit.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRGal4SRCJVsoYC5P8dnP1TTuBA3-Pu4LFyI_mTudvIuJRToG6TzseFb-FcrOzaTYum1HyeE5-9aD6Yb6Fuj0x6MQg-lUtnpx1E9ooixrC51F_drRHQzH155SAGyGo4WJDU_59wW609-7O8-5-AcWr_Gp2h-vpC7zl8eu0xIgP0hvwx0q2mmajbZV5iN4t\/s1700-e365\/bit.png\" alt=\"\" border=\"0\" data-original-height=\"684\" data-original-width=\"1266\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">290 fake repos spread infostealer<\/span><\/p>\n<p class=\"td-desc\">\n      A financially-motivated threat actor has set up more than 290 fake GitHub repositories impersonating trusted software and security tooling vendors, including Arctic Wolf, to distribute a Windows infostealer that shares the same codebase as BoryptGrab. The 292 impersonated repositories span security tooling, fintech and personal finance, cryptocurrency wallets and exchanges, developer and productivity tools, secure email providers, macOS utilities, and gaming software. \u00abThe payload is a pure smash-and-grab in-memory infostealer, with a 41-entry cryptocurrency wallet path table and 19+ targeted browser names for broad, financially driven credential collection,\u00bb Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/fake-github-repositories-deliver-boryptgrab-lineage-infostealer\/\" target=\"_blank\">said<\/a>. \u00abStolen data is packaged into a ZIP archive and exfiltrated to a C2 with an IP residing in Russia, on a hosting provider repeatedly associated with malware operations.\u00bb The malware does not set up persistence on the host and is instead designed to collect as much data as possible in a single execution. The brandjacking campaign is said to be the work of a Russian-speaking operator.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">$62M cybercrime indictment<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Justice Department has <a href=\"https:\/\/www.justice.gov\/opa\/pr\/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more\" target=\"_blank\">unsealed<\/a> a December 2024 indictment charging three Russian nationals and two related bulletproof hosting companies for their roles in cybercrimes against U.S. victims, causing tens of millions of dollars in losses. The charges are against Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin, Yulia Vladimirovna Pankova, Media Land LLC, and ML.Cloud LLC. In tandem, the U.S. Department of State\u2019s Rewards for Justice (RFJ) program has <a href=\"https:\/\/rewardsforjustice.net\/rewards\/media-land\/\" target=\"_blank\">announced<\/a> its offering a reward of up to $10 million and possible relocation for actionable information on foreign government-linked associates of Pankova, Volosovik, and Zatolokin, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud. The defendants and the companies were sanctioned by the U.S., the U.K., and Australia in November 2025. Earlier this week, the Council of the European Union also levied sanctions against Media Land, ML.Cloud, and Volosovik, as part of the first joint cyber sanctions package issued against Russia in collaboration with the U.K.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Chrome Sync becomes spyware<\/span><\/p>\n<p class=\"td-desc\">\n      A legitimate Chrome sync technique meant for user convenience is being misused by stalkers to gain broad access to a device owner\u2019s private information. \u00abChrome\u2019s sync feature exists to make life easier,\u00bb Certo <a href=\"https:\/\/www.certosoftware.com\/insights\/cyberstalkers-exploiting-chrome-sync-to-spy\/\" target=\"_blank\">said<\/a>. \u00abSign in with a Google account, and Chrome will keep your bookmarks, open tabs, browsing history, autofill data, and saved passwords in step across every device you use \u2014 your phone, tablet, laptop, whatever you\u2019re signed into.\u00bb However, this can be turned into a surveillance tool in a simple step. All a digital intruder has to do is gain brief physical access to a victim\u2019s phone, open the Chrome app and add a Google account under their control, and ensure sync is switched on for that account. \u00abThe victim carries on using their phone as normal,\u00bb Certo explained. \u00abFrom this point, their browsing activity is copied to the attacker\u2019s Google account in the background. The attacker opens the same Google account on their own device and reviews the victim\u2019s browsing history whenever they choose, from anywhere with an internet connection.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">eCards deliver remote access<\/span><\/p>\n<p class=\"td-desc\">\n      A sustained phishing campaign dubbed SeasonalInvite has been observed deploying and abusing commercial Remote Monitoring and Management (RMM) tools since at least January 2026 by making use of social engineering themes tied to the seasonal calendar in attacks targeting both Windows and macOS users. The attacks involve the abuse of ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&amp;O Syspectr. The bogus pages are likely distributed via phishing emails and poisoned search results. Forescout said it identified 959 eCard-themed domains and a traffic distribution system (TDS) using 2,658 gate pages to route victims to phishing pages while blocking automated security scanners. \u00abThe phishing pages are generated by a kit and contain indicators of likely AI-generated code, suggesting the threat actor used a large language model (LLM) to assemble delivery pages and rapidly retool the campaign,\u00bb it <a href=\"https:\/\/www.forescout.com\/blog\/seasonalinvite-new-phishing-campaign-abuses-ecards-and-rmm\/\" target=\"_blank\">noted<\/a>.\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi537WoXAFjoR3Su5quFqFd7pbyWGZxYb4g4W-NAdtIsgTehc9Mxc3ZN7GyCsaiY-7fTDNdBEvWU2XdISz0_TKkUt69sxqJugsr5Wk2XVhyphenhyphen52HqryyS5AZ_7l8blek3v1WCCn-kQpMlgtjWIpvwjLA2PHbvgiQhvY-UYDWcnzIZzkv_kKZhY5pxedA5Vz9N\/s1700-e365\/Season.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi537WoXAFjoR3Su5quFqFd7pbyWGZxYb4g4W-NAdtIsgTehc9Mxc3ZN7GyCsaiY-7fTDNdBEvWU2XdISz0_TKkUt69sxqJugsr5Wk2XVhyphenhyphen52HqryyS5AZ_7l8blek3v1WCCn-kQpMlgtjWIpvwjLA2PHbvgiQhvY-UYDWcnzIZzkv_kKZhY5pxedA5Vz9N\/s1700-e365\/Season.jpg\" alt=\"\" border=\"0\" data-original-height=\"481\" data-original-width=\"865\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">OAuth codes bypass MFA defenses<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have identified a new AI-powered device code phishing toolkit called Jalisco, along with a credential harvester codenamed OmegaLord that captures phone numbers alongside passwords to intercept multi-factor authentication (MFA) codes. \u00abJalisco is a device code phishing toolkit that provisions fresh OAuth codes in real time, defeating the time-based controls defenders rely on and pairing naturally with AI-powered kits like \u2018EvilTokens,&#8217;\u00bb ReliaQuest <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge\/\" target=\"_blank\">said<\/a>. \u00abOmegaLord, by contrast, is a JavaScript-based credential harvester that impersonates a PDF reader and collects phone numbers alongside credentials\u2014a deliberate step toward intercepting or hijacking MFA.\u00bb The development comes amid a surge in device code phishing attacks in 2026 that employ purpose-built tools to run such campaigns at scale. \u00abOnce inside a compromised Microsoft 365 account, attackers establish persistence by pairing multiple attacker-controlled devices to the victim\u2019s Entra ID tenant, then move quickly to exfiltrate sensitive data from software-as-a-service (SaaS) platforms for extortion,\u00bb the company added. In some cases, threat actors have been observed enrolling more than five devices to a single compromised account in an attempt to extend the window for exfiltration.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">3,900 threat servers mapped<\/span><\/p>\n<p class=\"td-desc\">\n      A new analysis from Hunt.io has uncovered more than 3,900 threat activities enabling servers across 302 Eastern European infrastructure providers within the past 3 months. \u00abKeitaro leads Eastern European threat activity enablement with 1,277 unique threat activity enabling IPs, followed by Tactical RMM (232) and Acunetix (173),\u00bb the threat intelligence company <a href=\"https:\/\/hunt.io\/blog\/eastern-europe-malicious-infrastructure-report\" target=\"_blank\">said<\/a>. \u00abCloud Atlas APT infrastructure was observed across multiple Eastern European providers, confirming the group\u2019s continued reliance on Eastern European hosting. Proton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group, with threat activity enabling infrastructure directly traceable to this Russian provider.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">One infection, two revenue streams<\/span><\/p>\n<p class=\"td-desc\">\n      A financially motivated campaign has been observed delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. The campaign was detected in April 2026. \u00abAttackers lure victims via malvertising to pages for downloading files that impersonate cracked versions of copyright-protected software,\u00bb Palo Alto Networks Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/vidar-stealer-xmrig-miner-campaign-analysis\/\" target=\"_blank\">said<\/a>. \u00abUpon execution, the loader drops and runs both Vidar stealer and XMRig. Vidar stealer targets information like browser credentials, cookies, and crypto wallets. XMRig mines Monero cryptocurrency.\u00bb The loader binaries use the Factory-v3 framework, which refers to a malware-as-a-service (MaaS0 builder used for different families of stealer malware. \u00abThe tag X3D MINER appears in Telegram operator notifications sent for every new victim infection,\u00bb Unit 42 added. \u00abThe operator behind this campaign runs a dual-monetization scheme. Criminals sell credentials and session cookies stolen by Vidar stealer on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles.\u00bb\n    <\/p>\n<\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhq7_5U-0dZGe3UfOc2MM4zWqV7rh1-x03x4-YE7Q0W7bmE03H08DCF5sZVEJuXZNorrMeW6vdr-ZSNDklLLVyqTOvfCVG-jXfCslkI3v_maEs_ziOepU_Nend-0GSMR8QLCVFo6Fro51ga8aAkjHjBir5nGPg7WKOpyqV76anrvelPGW7RZFzdBhsscuhx\/s1700-e365\/unit.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhq7_5U-0dZGe3UfOc2MM4zWqV7rh1-x03x4-YE7Q0W7bmE03H08DCF5sZVEJuXZNorrMeW6vdr-ZSNDklLLVyqTOvfCVG-jXfCslkI3v_maEs_ziOepU_Nend-0GSMR8QLCVFo6Fro51ga8aAkjHjBir5nGPg7WKOpyqV76anrvelPGW7RZFzdBhsscuhx\/s1700-e365\/unit.png\" alt=\"\" border=\"0\" data-original-height=\"1166\" data-original-width=\"1472\"\/><\/a><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>The lesson is not \u201ctrust nothing.\u201d It is to stop granting trust in bulk. Check the repo, the installer, the account, the exposed service. Small shortcuts keep turning into full attack paths.<\/p>\n<p>And when a bug looks old, awkward, or too simple to matter, assume someone has already found a use for it. Patch the boring stuff. Tighten the defaults. Watch the handoffs.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A lot of this week\u2019s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak defaults are earning their keep, and some [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1608,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,5],"tags":[3836,3835,17,24,3834,508,1586,3838,23,3837],"class_list":["post-1607","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","category-trending","tag-24hour","tag-cheat","tag-chrome","tag-cyberdefensa-mx","tag-game","tag-ransomware","tag-spyware","tag-stalking","tag-stories","tag-sync"],"_links":{"self":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/comments?post=1607"}],"version-history":[{"count":0,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1607\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media\/1608"}],"wp:attachment":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media?parent=1607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/categories?post=1607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/tags?post=1607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}