wp2shell, la RCE pre-autenticazione che rimette in discussione il WordPress Core

Una vulnerabilità critica nel cuore di WordPress consente a un attaccante anonimo di eseguire codice da remoto su un’installazione standard, senza credenziali, senza plugin e senza interazione della vittima. La falla, battezzata wp2shell dai ricercatori di Searchlight Cyber (divisione Assetnote) che l’hanno scoperta, colpisce il core della piattaforma che, secondo la stessa società, sostiene oltre 500 milioni di siti nel mondo. WordPress ha rilasciato le correzioni il 17 luglio 2026 e ha attivato gli aggiornamenti forzati; una scala di esposizione di questa portata impone una verifica immediata a chiunque gestisca un sito pubblico, dalla PA alle testate ai siti aziendali.

Nota di trasparenza sulla freschezza: la prima pubblicazione risale alla sera del 17 luglio 2026 (advisory Searchlight alle 19:10 UTC, release WordPress e GitHub Security Advisory in pari data), quindi appena fuori dalla finestra stretta delle sei ore ma nettamente all’interno delle ultime 24. È la storia dominante del ciclo e il rischio è in evoluzione: nelle prime ore del 18 luglio è comparso un primo proof-of-concept pubblico (vedi sotto), motivo in più per selezionarla segnalando in chiaro i timestamp.

Cosa è, tecnicamente

wp2shell non è un singolo bug ma una catena. Il remote code execution pre-autenticazione è tracciato come CVE-2026-63030
e nasce da una route confusion sull’endpoint /wp-json/batch/v1
delle REST API: la logica che smista le richieste batch può essere indotta a raggiungere percorsi non previsti. A valle si innesta una SQL injection, CVE-2026-60137
, nel parametro author__not_in
di WP_Query
, la classe che costruisce quasi ogni query verso il database. La combinazione dei due difetti porta dall’accesso anonimo all’esecuzione di codice.

Attenzione al disallineamento nei riferimenti: diversi tracker etichettano l’intera catena come la sola CVE-2026-63030
, che è però l’identificativo della sola route confusion. I due Security Advisory ufficiali mappano con precisione difetti e scopritori: la route confusion nella batch API (
CVE-2026-63030
, GHSA-ff9f-jf42-662q
, gravità Critical) è stata trovata da Adam Kues di Assetnote e Searchlight Cyber; la SQL injection nel parametro author__not_in
di WP_Query
(
CVE-2026-60137
, GHSA-fpp7-x2x2-2mjf
, gravità Moderate) è stata segnalata in team da TF1T, dtro e haongo. Non esiste un terzo difetto: la RCE nasce dalla combinazione dei due e la seconda metà della catena non è opera di Searchlight, ma del secondo gruppo. Chi mappa l’esposizione tenga conto di entrambi gli identificativi.

Un elemento operativo utile arriva da Cloudflare, citata nell’analisi di Rapid7: il percorso vulnerabile risulta raggiungibile quando non è attiva una persistent object cache, condizione che riguarda molte installazioni predefinite ma non tutte.

Versioni colpite e correzioni

Il GitHub Security Advisory GHSA-ff9f-jf42-662q
circoscrive la RCE CVE-2026-63030
alle versioni 6.9.0
–
6.9.4
e 7.0.0
–
7.0.1
; le release precedenti alla 6.9
non sono esposte alla route confusion. La SQL injection CVE-2026-60137
risale invece al ramo 6.8
e copre 6.8.0
–
6.8.5
, 6.9.0
–
6.9.4
e 7.0.0
–
7.0.1
. Le correzioni sono in WordPress 7.0.2, nella backport 6.9.5
, nella 6.8.6
e nella 7.1 Beta 2
. Qui sta la ragione per cui il ramo 6.8
riceve solo una patch parziale: la 6.8.6
chiude la sola SQL injection, classificata Moderate, mentre la catena RCE Critical non lo tocca, non essendo presente su quel ramo la route confusion. WordPress.org ha forzato l’aggiornamento automatico sulle installazioni interessate; resta da verificare manualmente ogni sito esposto, perché hosting con auto-update disabilitato o deploy sotto controllo di versione possono restare scoperti.

Sul punteggio conviene essere precisi: l’advisory GitHub classifica la gravità come Critical sul piano qualitativo, mentre il CVSS numerico finora assegnato è 7.5, come segnala Rapid7. La divergenza tra etichetta e punteggio riflette metriche e contesti diversi; per la prioritizzazione pesa più la superficie (esecuzione di codice senza autenticazione su una piattaforma ubiqua) del numero isolato.

Sfruttamento e mitigazioni

La sera del 17 luglio, alla pubblicazione degli advisory, non circolava alcun proof-of-concept pubblico: Searchlight aveva volutamente omesso i dettagli tecnici per dare tempo alle patch, rilasciando solo un servizio di verifica dell’esposizione. La finestra si è però chiusa in poche ore. Nelle prime ore del 18 luglio è comparso su GitHub un PoC (repository Icex0/wp2shell-poc
), affiancato da uno strumento di detection che sfrutta la SQL injection di tipo time-based. La sfumatura conta, per non esagerare in senso opposto: non risulta ancora sfruttamento confermato in-the-wild, e il PoC pubblico dimostra l’injection e la lettura del database, inclusi gli hash delle password degli amministratori, ma non l’esecuzione di codice completa. Il salto finale dalla SQL injection alla RCE, che richiede di craccare un hash recuperato e caricare un plugin, non è stato pubblicato da Searchlight. Rapid7 aveva previsto un PoC in tempi brevi e i tempi brevi si sono rivelati poche ore: conferma di quanto la finestra tra disclosure e weaponizzazione si stia comprimendo, come già discusso a proposito della crisi della patch management su queste pagine.

La contromisura efficace è l’aggiornamento. Come misura d’emergenza temporanea, e solo in attesa della patch, Searchlight indica il blocco dell’accesso anonimo alla batch API, filtrando a livello di WAF /wp-json/batch/v1
e ?rest_route=/batch/v1
oppure installando un plugin che chiuda le REST API agli utenti non autenticati. Entrambe le opzioni hanno un costo: possono rompere integrazioni e funzionalità legittime che usano quell’endpoint, ragione per cui Rapid7 sconsiglia i workaround e raccomanda di correggere direttamente. Chi è dietro un WAF gestito ha una copertura parziale già disponibile: Cloudflare ha distribuito regole in concomitanza con la disclosure e Wordfence ha rilasciato una regola firewall il 17 luglio. La dinamica di sfruttamento di massa di una piattaforma diffusissima ricorda, per portata, la campagna ToolShell su SharePoint, con la differenza che qui il bersaglio è il web pubblico nella sua parte più capillare.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/wordpress-core-wp2shell-rce/




OkoBot: il framework modulare che carpisce le seed phrase da dentro Ledger Live e Trezor Suite

Il team GReAT di Kaspersky ha documentato nel report di Securelist OkoBot, un framework malevolo composto da oltre venti moduli che colpisce gli utenti di criptovaluta su Windows. La catena di attacco è stata ridisegnata a fine aprile 2025; la telemetria sulle vittime copre il periodo aprile 2025-giugno 2026 e GReAT ne ha identificato gli attacchi a gennaio 2026. La campagna è attiva da oltre un anno ed è tuttora in corso, con centinaia di vittime in più di venticinque Paesi, concentrate in Brasile, Vietnam, Canada, Messico e Turchia. Secondo Dmitry Galov (GReAT), citato nel comunicato di Kaspersky, i vettori osservati indicano gli sviluppatori tra i bersagli primari: un dettaglio che sposta la vicenda dal solo furto di criptovaluta al rischio d’ingresso in ambienti aziendali.

Vettori d’ingresso: repository GitHub fasulli e ClickFix

Il primo canale è la tecnica ClickFix, che induce la vittima a incollare ed eseguire comandi apparentemente innocui. Il secondo è più raffinato: un repository GitHub esistito da fine marzo 2025 a giugno dello stesso anno, composto dal solo README.md
con una finta guida d’installazione in stile ufficiale, indicizzato in cima ai risultati dei motori per la query SSMS
. Il pacchetto che prometteva SQL Server Management Studio consegnava in realtà una versione dell’editor audio Audacity con un impianto malevolo incorporato in una libreria. Non è avvelenamento della catena di fornitura, perché non risultano compromessi né un pacchetto legittimo né l’account di un manutentore: è abuso di piattaforma e SEO poisoning. Il perno, tuttavia, è lo stesso già osservato nelle campagne di pacchetti open source avvelenati contro gli sviluppatori, la fiducia implicita negli strumenti di lavoro quotidiani. Cambia il vettore, resta la superficie.

La catena e la persistenza RDP

Lo script TookPS
installa SSH sulla macchina della vittima, apre una connessione verso il server SSH controllato dagli attaccanti e inoltra la porta del demone SSH locale. Dopo un ritardo, è un bot SSH automatizzato, operante lato attaccante, a collegarsi alla porta inoltrata per consegnare i payload: il bot non risiede sull’host colpito. È questo bot a costruire la persistenza più interessante per un pubblico enterprise. Apre le porte del firewall per il traffico RDP in ingresso, crea un utente nel gruppo “Remote Desktop Users”, sostituisce la termsrv.dll
legittima con una versione modificata per consentire sessioni RDP concorrenti e crea un’attività pianificata chiamata Apple Sync
che mantiene ogni ora un tunnel SSH inverso sulla porta RDP locale.

Da qui parte l’anello che porta ai plugin. Il bot recupera i moduli via SFTP e li esegue tramite HDUtil
, un launcher protetto con VMProtect, usando il comando target
; l’argomento opzionale nouac
di quel comando esegue il bypass dell’UAC tramite RPC di Windows e un msconfig.exe
auto-elevato, tecnica descritta da Google Project Zero nel 2019. L’ultima consegna è Volume2
, un’utility open source collegata a una protobuf.dll
malevola: la libreria appare legittima ma espone una funzione ProtobufGetVer2
che decritta e avvia l’implant vero, cioè il dispatcher di plugin. Il payload è cifrato con AES-GCM e chiave statica a 256 bit, ma con il tag di autenticazione omesso, quindi senza verifica d’integrità. Il meccanismo è quello del DLL hijacking, utile come indicatore per la detection; tra i verdetti con cui Kaspersky rileva il framework figura infatti anche Trojan.Win32.Dllhijack.*
.

L’arsenale modulare e il dispatcher

Il dispatcher interroga il server di comando ogni venti secondi; i ricercatori hanno individuato cinque plugin: un wrapper per CMD, uno per PowerShell, un enumeratore d’ambiente, un dropper e un process injector. È il process injector a mettere in campo i quattro implant veri e propri, iniettandoli in processi legittimi: ext_daemon
, SeedHunter
, MC Keylogger
e OkoSpyware
. Il primo si aggancia ai processi dei browser basati su Chromium, non solo Chrome: per Microsoft Edge, ad esempio, viene agganciata la msedge.dll
. Installa estensioni malevole concedendo tutti i permessi richiesti; nell’attacco analizzato l’estensione installata era Rilide
. L’occultamento passa dalle stesse funzioni interne del browser agganciate dal loader: le estensioni malevole finiscono in un array dedicato e, quando quelle funzioni vengono invocate con tali estensioni come parametro, non fanno nulla e restituiscono un valore costante, sopprimendo le notifiche ed escludendole dall’elenco visibile, mentre le altre estensioni continuano a comportarsi normalmente. In fase d’installazione le estensioni vengono inoltre scompattate nella directory non predefinita Local Extension Settings
, con il manifest modificato al volo per iniettare un oggetto custom_args
contenente l’identificativo della macchina infetta (
hwid
) e il browser.

Il MC Keylogger
registra tasti e appunti (testo, immagini e percorsi dei file copiati), traccia i dispositivi USB collegati e cattura uno screenshot ogni cinque minuti. OkoSpyware
confronta le finestre attive con un elenco di oltre cento nomi di eseguibili, tra cui wallet come Exodus e Litecoin QT e gestori di password come KeePassXC e 1Password, e intercetta anche i titoli delle finestre dei browser tramite espressioni regolari (ad esempio le pagine delle estensioni MetaMask o Tonkeeper), avviando la registrazione video con FFmpeg e il logging dei tasti. L’esfiltrazione chiude il ciclo ed è anche anti-forense: uno script TookPS
lanciato da un’attività pianificata riceve dal C2 uno script PowerShell dedicato, invia all’endpoint ir-post.php
tutti i file prodotti da MC Keylogger
e OkoSpyware
, poi li cancella dal sistema e svuota il file di cronologia ConsoleHost_history.txt
.

L’inganno su Ledger e Trezor

Il modulo SeedHunter
si inietta nei processi di Trezor Suite, Ledger Wallet e Ledger Live agganciando le funzioni interne del framework Electron delle applicazioni: la finestra fraudolenta nasce quindi dentro l’app legittima. Il modulo interroga il C2 moonsand[.]store
e riceve un flag Wait
: se è true
, avvia scansioni periodiche dei dispositivi USB filtrate per VID e PID e attende che venga collegato un Ledger o un Trezor per mostrare la pagina di phishing; se è false
, la pagina compare subito. Il punto controintuitivo è proprio questo: il dispositivo hardware non viene compromesso, viene aggirato il software companion, ed è l’utente a consegnare la seed phrase digitandola nella schermata falsa. Chi cede quella sequenza perde il controllo dei fondi, perché la frase di recupero vale più della password e non è revocabile.

Un framework mantenuto, attribuzione prudente

L’evoluzione documentata da Kaspersky è la prova che il framework è manutenuto attivamente. Già a marzo 2026 il componente Volume2
viene installato direttamente da TookPS
, la vecchia catena HDUtil
verso extl
verso Rilide
risulta abbandonata e sostituita integralmente dal plugin ext_daemon
(funzionalmente identico a extl.exe
, solo meno offuscato e privo di VMProtect), mentre TeviRAT
è stato rimosso perché le sue funzioni sono coperte dal nuovo dispatcher; sempre da marzo 2026 la protobuf.dll
è stata rinominata version.dll
. Sull’attribuzione Kaspersky è netta: non collega la campagna ad alcun attore noto. Segnala però indizi circostanziali che rimandano ad attori di lingua russa, tecnica peraltro diffusa in quell’ambiente: i server della prima fase restituiscono una risposta vuota agli indirizzi IP di Russia e CSI, il codice sorgente delle pagine di phishing di SeedHunter
contiene commenti in russo e l’infostealer Rilide
circola su forum di cybercrime di lingua russa ad accesso su invito. Un’avvertenza sugli indicatori: il post pubblico ne espone solo un sottoinsieme, mentre la lista completa e gli script di decrittazione sono riservati ai clienti del servizio Kaspersky Threat Intelligence Reporting.

Sul piano difensivo gli artefatti non mancano: file come %PROGRAMDATA%hwid.dat
(l’identificativo di macchina che ogni componente verifica all’avvio, terminando se assente o non valido, il che ostacola anche l’analisi fuori dall’host bersaglio), %PROGRAMDATA%HDVideoHDUtil.exe
e %USERPROFILE%.sshgo.bat
, account non autorizzati nel gruppo “Remote Desktop Users”, traffico SSH in uscita da endpoint utente, la sostituzione di termsrv.dll
e l’attività pianificata Apple Sync
, fino allo svuotamento di ConsoleHost_history.txt
come segnale post-esfiltrazione. Il messaggio operativo resta duplice: trattare le workstation degli sviluppatori come asset ad alto rischio e ricordare agli utenti che nessun software legittimo chiede di digitare la seed phrase del wallet hardware su schermo.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/okobot-seed-phrase-ledger-trezor/




Two Scattered Spider Hackers Sentenced to Jail in UK

Two members of the Scattered Spider cybercrime group have been sentenced to jail in the United Kingdom, the country’s National Crime Agency (NCA) announced on Thursday.

Thalha Jubair, 20, and Owen Flowers, 18, were charged over their role in a 2024 cyberattack targeting Transport for London (TfL), which caused significant disruptions and generated costs of £29 million ($39 million).

Jubair and Flowers were arrested in September 2025. They initially pleaded not guilty but changed their pleas to guilty when their trial started in June.

On Thursday, they were each sentenced to five years and six months in prison following what officials described as “the largest cybercrime prosecution ever brought before the UK courts”. 

Despite several arrests last year, hackers operating under the Scattered Spider name continued to take credit for cyberattacks through the first months of 2026, although no new attacks have been announced in recent months.

Following the sentencing of Jubair and Flowers, the NCA noted, “Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity. Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group’s ability to continue conducting cybercriminal operations.”

Advertisement. Scroll to continue reading.

In the meantime, authorities continue prosecuting other suspected members of the group. An alleged member, 19-year-old Peter Stokes, a dual US-Estonian national, was recently extradited to the US to face charges. 

Tyler Buchanan, a British national believed to be part of the cybercrime gang, pleaded guilty in a US court in April. 

Related: Third US Security Expert Sentenced to Prison for Helping Ransomware Gang

Related: Romanian Hacker Sentenced to Prison in US for Selling Access to State Network

Related: Third DraftKings Hacker Sentenced to 18 Months in Prison

https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk/




Albiriox, il RAT bancario che si finge UniCredit su Telegram

Una finta promozione, la promessa di 100 dollari e un bot Telegram: è la trappola con cui, in una campagna a tema italiano documentata dalla società italiana D3Lab, viene distribuito Albiriox, un banking trojan Android costruito per la frode on-device. Il marchio abusato è quello di UniCredit, ma conviene chiarirlo subito per non generare equivoci: la banca e i suoi clienti sono le vittime dell’operazione, non la fonte di una compromissione. La catena descritta non coinvolge alcun sistema dell’istituto; ad essere sfruttata è la sua identità, usata come esca.

La catena di infezione

Secondo l’analisi di D3Lab, l’allarme è partito da un servizio di brand monitoring che ha intercettato un dominio appena registrato, unicredit-tme[.]shop
, creato l’8 luglio 2026. La pagina promette una ricompensa e invita a scaricare un’app, ma invece di rimandare a uno store ufficiale porta a un bot Telegram (
@UniCreditit_bot
) che guida la vittima nell’installazione. L’incentivo è esplicito: 100 dollari per chi installa l’applicazione e altri 50 per chi invita un amico, un meccanismo referral che trasforma il raggiro in un moltiplicatore di diffusione.

La campagna non risulta appoggiarsi a Google Play né ad altri store ufficiali: l’utente viene convinto a installare l’APK manualmente, presumibilmente dopo aver abilitato le sorgenti sconosciute. Il dettaglio tecnico più rilevante è che il file scaricato è un dropper autocontenuto: il payload di secondo stadio non viene prelevato dalla rete a runtime, ma è già incorporato nell’APK, spezzato in più asset con estensioni fuorvianti, ricomposto in locale, decifrato in AES-CBC e decompresso con GZIP. Così la catena di consegna deve solo convincere la vittima a installare il primo file: il resto avviene sul dispositivo, senza un secondo download che potrebbe fallire o essere intercettato dai controlli di rete.

Che cosa fa Albiriox una volta a bordo

Il secondo stadio si registra come servizio di Accessibility e da lì controlla il telefono. Le capacità osservate sono quelle di un banking trojan moderno: overlay per catturare credenziali (con schermate configurabili per PIN, pattern, coppie utente/password), intercettazione degli SMS e degli OTP, controllo remoto in stile VNC con manipolazione dello schermo, fino alla modalità black screen che nasconde all’utente ciò che l’operatore sta facendo.

L’operatore non si limita a rubare le password: agisce direttamente dentro le sessioni bancarie legittime, aggirando i passaggi di autenticazione. La comunicazione con il server avviene su un protocollo TCP grezzo con messaggi JSON, verso 179[.]43[.]159[.]210
sulle porte 5555
e 5552
; nel codice compare persino un marcatore di campagna con il paese bersaglio scritto in cirillico, Италия
, indizio dell’ecosistema in cui il builder è stato configurato.

L’attribuzione ad Albiriox, spiega D3Lab, poggia sul confronto manuale con un campione noto, sulle somiglianze di protocollo e sul materiale Telegram del progetto: il sample italiano appare una build personalizzata e offuscata. Vale la cautela d’obbligo sui nomi: si tratta di una build riconducibile alla famiglia, le cui funzionalità D3Lab allinea alla versione 1.5 annunciata dagli sviluppatori a gennaio 2026.

Perché conta per il mercato italiano

Albiriox non nasce oggi. La ricerca di Cleafy, che per prima ne ha descritto la famiglia, lo inquadra come offerta Malware-as-a-Service commercializzata su forum di lingua russa, con una fase beta a settembre 2025 e la commercializzazione dall’ottobre successivo, a canoni mensili nell’ordine delle centinaia di dollari; la lista hardcoded dei bersagli superava le 400 applicazioni bancarie, di pagamento e crypto, come riportato dalla stampa specializzata. La novità della campagna italiana non è quindi il malware in sé, ma la sua localizzazione: un pacchetto pronto all’uso viene calato su un marchio bancario nazionale e distribuito con un funnel social semplice ed economico.

Il segnale non è isolato: nella sintesi settimanale del 4-10 luglio il CERT-AGID ha rilevato campagne italiane a tema banking veicolate via SMS con link al download di APK malevoli, tra cui Albiriox insieme a RedWing e RedHook. Vettori diversi, stessa famiglia: nella stessa settimana Albiriox arriva agli utenti italiani per almeno due strade distinte.

Per il settore finanziario italiano contano soprattutto due elementi. La superficie di attacco resta il fattore umano unito al sideloading, mentre il brand monitoring si conferma un segnale di early warning: un dominio appena registrato che imita una banca è spesso il primo anello di una catena malevola, non solo phishing. Il mobile banking trojan a tema Italia è del resto un filone già noto al mercato, come mostra il caso del trojan Xenomorph.

La difesa passa per il presidio dei domini simili al proprio marchio, il blocco dei bot Telegram usati come vettore, la comunicazione ai clienti che nessuna banca distribuisce APK fuori dagli store, e il monitoraggio dei dispositivi che installano app con permessi di Accessibility e connessioni TCP verso porte anomale. Sul versante utente, la logica è la stessa che vale contro ogni account takeover: diffidare di premi che chiedono un’installazione, e trattare ogni APK ricevuto via messaggistica come ostile.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/albiriox-rat-bancario-italia/




County Government Reportedly Paid $1 Million to Cyber Extortion Group

A government entity in the US reportedly paid a $1 million ransom to the Kairos cyber extortion group to prevent the public dissemination of information stolen in a May 2025 intrusion, Ransom-ISAC reports.

A leaked negotiation transcript shows that the extortion group demanded $3 million in cryptocurrency from the victim organization, but eventually settled for $1 million.

Kairos claimed to have stolen over 2 terabytes of data, or approximately 1.6 million files, after accessing the victim’s environment in a brute-force attack.

During the three-week negotiation, the victim increased its offer from $100,000 to $430,000, but eventually accepted a hard deadline and the $1 million ransom, which was paid in Bitcoin on June 13.

The attackers pressured the victim with public exposure, while maintaining control of deadlines and proof-of-access artifacts.

“The affected entity’s responses are consistent with an organization buying time while legal, leadership, financial, and communications decisions were coordinated,” Ransom-ISAC notes.

Advertisement. Scroll to continue reading.

The anti-ransomware organization notes that the incident was an extortion attack and did not involve file-encrypting ransomware. The attackers’ proof-of-deletion appears selective, not comprehensive, but the listings they provided are consistent with a real file-server scrape.

According to Ransom-ISAC, the provided proof of deletion could have been generated by erasing a copy of the data, and no mechanism to independently verify the deletion was provided.

Ransom-ISAC did not name the affected organization, but the negotiation transcript identifies it as “a small county with very limited resources.”

The affected government body reportedly appears to be Union County, Ohio. In September, the county notified (PDF) 45,487 individuals that their personal information was stolen in a ransomware attack in May 2025.

The affected information included names, dates of birth, driver’s license/state ID numbers, passport numbers, Social Security numbers, financial account details, fingerprint information, medical information, and payment card details.

SecurityWeek has emailed Union County for a statement on the matter and will update this article if the county responds.

Related: Aflac Japan Data Breach Impacts 4.38 Million

Related: Nissan Employee Data Breached in Oracle PeopleSoft Hack

Related: Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack

Related: More Klue Breach Victims Identified as Hackers Get Hacked

https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/




Armored Likho APT Targeting Government, Electric Power Entities

A recently discovered advanced persistent threat (APT) actor has been targeting government and electric power organizations in multiple countries, Kaspersky reports.

Dubbed Armored Likho, the APT engages both in financially motivated attacks against individuals and in cyber-espionage operations against organizations in Russia, Brazil, and Kazakhstan.

The threat actor’s arsenal includes modular remote access trojans (RATs) and information stealers, including the Python-based BusySnake Stealer, and tools like Go2Tunnel for remote access and network tunneling.

“This diverse malware stack enables the threat actor to maintain stealthy control of compromised hosts, exfiltrate credentials and other sensitive information, and dynamically deploy downloadable modules tailored to the victim’s profile and the tasks at hand,” Kaspersky notes.

Armored Likho mainly relies on spear-phishing for initial access. Archives attached to its emails contain executables or LNK files that, once opened, display decoys while malware is being installed in the background.

A loader injected in memory via such an executable was seen fetching archives from GitHub repositories that contain early development builds and test samples of the malware. The LNK files display a fake document while a Python 3.12 interpreter and an archive are fetched in the background.

Advertisement. Scroll to continue reading.

Among other components, the archives contain a Python-based infostealer that Kaspersky tracks as BusySnake Stealer. The malware packs multiple evasion techniques and dynamically decrypts bytecode when a function is called, encrypting it immediately after, and runs in the background without a console window.

The stealer relies on multiple handlers for various functions, such as clipboard theft, file enumeration, 64-character hexadecimal key extraction, document exfiltration, screenshot capture, screenshot archiving, persistence checks, and command execution.

Based on commands received from the command-and-control (C&C) server, the malware can capture screenshots, exfiltrate logged keystroke data, decrypt stored passwords from Chromium-based and Firefox browsers, extract cookies from browsers, scrape the machine for OTP keys, find cryptocurrency wallets, harvest Telegram sessions and credentials, establish a reverse SSH tunnel, and restart RustDesk to capture users’ credentials.

Before BusySnake Stealer, Armored Likho relied on Go2Tunnel to establish a reverse SSH tunnel, but has implemented the functionality into the infostealer, which can now provide the attackers with persistent remote access and interactive control over the victim’s system.

Armored Likho’s operations appear to overlap with Eagle Werewolf activity. Previously, the hacking group was seen using the AquilaRAT RAT, which shares a similar structure and persistence mechanism with BusySnake Stealer.

Related: Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

Related: New ‘Mistic’ RAT Opens Door to Several Ransomware Families

Related: Hackers Target Global Stock Exchange in Espionage Operation

Related: Sophisticated Deep#Door Backdoor Enables Espionage, Disruption

https://www.securityweek.com/armored-likho-apt-targeting-government-electric-power-entities/




Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

Threat actors are using prompt injection attacks embedded in malicious websites and manipulated search results to trick AI agents into making payments or trusting fraudulent cryptocurrency platforms.

Zscaler says it identified two campaigns relying on indirect prompt injection, including a payment scam hiding behind API documentation, and a typosquatting operation promoting a crypto platform that impersonates DeBank.

As part of the first campaign, the threat actor has been using SEO poisoning to target AI agents searching for the Python library requests-secure-v2.

“The fraudulent website includes keyword-heavy HTML tied to the fake Python module to poison search results for package installation and dependency troubleshooting queries,” Zscaler explains.

Within the website, the attackers hid indirect prompts instructing the visiting agents to make a payment as part of the routine process of acquiring an API key. The payment was encoded in schema markup to increase the chances that the agents would follow the instructions.

A hidden <div> tag instructing AI agents to resolve an error by making the payment was also discovered on the website, as well as code to initialize a cryptocurrency transfer to a hardcoded wallet.

Advertisement. Scroll to continue reading.

“The website not only attempts to target AI agents, but also human developers. When the website is rendered by a desktop browser, the same payment options via credit card or cryptocurrency are displayed to the user,” Zscaler explains.

The threat actor behind the campaign is using 10 GitHub repositories linking to multiple similar websites containing indirect prompt injections.

As part of the second campaign, a threat actor is promoting a fraudulent website typosquatting the decentralized finance portfolio tracker DeBank. The indirect prompts used in this campaign tell the AI agents that the impersonating website is the legitimate DeBank domain.

“The fraudulent website is optimized to rank for DeBank-related searches by stuffing the title and meta tags with keywords such as DeBank Login, DeFi Dashboard, and Crypto Tracker. It also includes Open Graph and X (formerly Twitter) metadata to make the link appear like an official DeBank service,” Zscaler notes.

To test the campaigns’ impact, the cybersecurity firm built an autonomous AI agent with web-browsing and payment-execution capabilities.

Of the 26 LLMs that were evaluated, four (Llama 3.3 70B Instruct, Llama 3.2 90B Vision Instruct, Gemini 3 Flash, and Gemini 2.5 Pro) were successfully manipulated into making a payment. Still, only two (Claude Sonnet 4.5 and GPT-5.4) miscategorized the fraudulent website as the trusted DeBank platform.

“As AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse,” Zscaler notes.

Related: Agentic AI Used to Conduct Ransomware Attack via Langflow

Related: Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

Related: How to Conduct a Successful Audit of AI-Driven Software Development

Related: ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/




In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting

SecurityWeek’s cybersecurity news weekly roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.

Here are this week’s highlights:

Anonymous-linked hacker Aubrey Cottle jailed over Texas GOP cyberattack

Aubrey Cottle, a Canadian hacker associated with the hacktivist group Anonymous, has been sentenced to 18 months in prison for his involvement in a cyberattack on the Texas Republican Party’s website in September 2021. Cottle, 39, of Oshawa, Ontario, pleaded guilty to defacing the website, exfiltrating data from a Texas GOP server, and publishing the data online.

14 million impacted by KDDI data breach

Advertisement. Scroll to continue reading.

Japanese telecoms provider KDDI has disclosed (PDF) a data breach likely impacting the email addresses and passwords of 14,22 million people. The incident affected five ISP operators, including BIGLOBE, Chubu Telecommunications C., JCOM Co., NIFTY Corporation, and STNet. 

Push Security targeted in poisoned tenant attack

Three years after detailing the poisoned tenant attack, Push Security was targeted using the technique via OpenAI’s organization invitation feature. Multiple employees received an OpenAI invitation to join Push Security Inc. After they would join the tenant, the attacker could spy on their activities or target them with further social engineering. 

Rust-based PamStealer targeting macOS

Jamf has detailed PamStealer, an information stealer targeting macOS that validates the harvested credentials via Pluggable Authentication Modules (PAM) before using them. The malware is distributed as a compiled AppleScript file impersonating the open source clipboard manager Maccy.

Russian hackers behind the 2025 Jaguar Land Rover hack

The cyberattack that severely disrupted Jaguar Land Rover’s operations in September 2025 was mounted by Russian hackers, The New York Times says. Microsoft reportedly notified the car manufacturer about the hacking group, with Mandiant, Palo Alto Networks, and US and UK law enforcement agencies also involved in the investigation. 

Pegasus spyware targeted a European Parliament member investigating it

Former member of the European Parliament Stelios Kouloglou was hacked with NSO Group’s Pegasus spyware while he was investigating Pegasus abuse cases, as part of the PEGA committee, Citizen Lab discovered. The targeting has not been attributed to a specific government, and there is no evidence that the Greek Government was involved. 

Researcher drops dozens of zero-days in open source projects

A researcher known as Bikini has published proof-of-concept (PoC) code targeting dozens of zero-day vulnerabilities in multiple open source projects, including FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC. Nine of the security defects have been assigned a CVE identifier. The issues, the researcher says, were surfaced via LLM fuzzing. 

Pro-Russia influence operations are shifting

Four years into Russia’s invasion of Ukraine, pro-Russia influence operations are shifting from their single focus on Ukraine to pre-war objectives, Google says. Covert pro-Russia influence operations are targeting the US, European Union members, NATO, Russia’s neighbors, the Middle East and Africa, and internal entities. They focus on global events, elections, the war in Ukraine, and emerging geopolitical developments and events, and are increasingly relying on generative AI. 

Venezuelans sentenced in the US over ATM jackpotting

Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, have been sentenced to 78 months in prison in the US for their involvement in ATM jackpotting activities. As part of a sophisticated criminal group, they built and deployed a variant of the Ploutus malware on ATMs across the US and used it to withdraw money without authorization. They were also ordered to jointly pay $1.5 million in restitution. 96 other defendants have been charged over their roles in the operation. 

Cisco and Synology patches

Cisco has released fixes for seven ClamAV vulnerabilities impacting Secure Endpoint Connector for Windows, Linux, and macOS, and Secure Endpoint Private Cloud, and for one flaw in Catalyst Center. Synology resolved three security defects in MailPlus Server, including two critical bugs that could allow attackers to read or write arbitrary files and cause DoS conditions.

Join the AI Risk Summit | Ritz-Carlton, Half Moon Bay

https://www.securityweek.com/in-other-news-canadian-hacker-jailed-open-source-zero-days-two-sentenced-for-atm-jackpotting/




Medtronic Data Breach Impacts 3.8 Million People

Medical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach.

The incident occurred in April 2026, when the infamous extortion group ShinyHunters accessed the company’s corporate IT systems.

Medtronic confirmed the attack in late April, noting that its products and manufacturing and distribution operations were not affected.

ShinyHunters had added the company to its Tor-based leak site on April 17, claiming the theft of over 9 million records of personal information, and terabytes of corporate data.

The group has since removed Medtronic from the website, which suggests that the company might have paid a ransom to recover the stolen information.

This week, the medical technology titan started sending written notification letters to the affected individuals, confirming that the hackers stole patients’ personal and medical information, including names, contact details, dates of birth, Social Security numbers, and health-related details.

Advertisement. Scroll to continue reading.

“We have no evidence that any of that information was posted publicly or exposed on the internet,” reads a copy of the company’s notification letter (PDF) submitted to the California Attorney General’s Office.

Medtronic told the Indiana Attorney General’s Office that 3,834,294 individuals were affected by the incident.

The company is providing them with 24 months of free credit monitoring, dark web monitoring, and identity theft restoration services.

“Medtronic has implemented additional safeguards and continues to work with third-party cybersecurity experts to identify opportunities to further strengthen the security of its systems. Medtronic has also worked with law enforcement and is notifying relevant regulatory authorities,” the company said.

Related: Aflac Japan Data Breach Impacts 4.38 Million

Related: Nissan Employee Data Breached in Oracle PeopleSoft Hack

Related: More Klue Breach Victims Identified as Hackers Get Hacked

Related: Xsolis Data Breach Affects 1.4 Million Individuals

https://www.securityweek.com/medtronic-data-breach-impacts-3-8-million-people/




Alleged Scattered Spider Hacker Extradited to US

A dual US-Estonian citizen was extradited to the US to face charges for his alleged involvement in the activities of the infamous hacking group Scattered Spider.

The individual, Peter Stokes, 19, also known as ‘Bouquet’, was arrested in Finland in April while boarding a flight to Japan. He was indicted with counts of conspiracy, computer intrusion, and fraud.

In May 2025, together with other co-conspirators, Stokes allegedly hacked a luxury jewelry retailer’s computer system, stole data from it, and demanded an $8 million ransom in cryptocurrency from the victim.

While the retailer managed to evict the hackers from its network and no ransom was paid, the attack led to business disruption, which, together with the investigation and mitigation actions, caused at least $2 million in losses.

Also tracked as 0ktapus, Muddled Libra, Octo Tempest, Starfraud, Scatter Swine, and UNC3944, Scattered Spider is believed to have hacked at least 100 organizations and to have received over $100 million in ransom payments from its victims.

The group is known for its widespread 2025 Salesforce hacking campaign and for the 0ktapus campaign, which hit over 130 organizations in 2022.

Advertisement. Scroll to continue reading.

Over the past several years, authorities charged, arrested, and sentenced multiple alleged members of the hacking group. In April this year, UK national Tyler Robert Buchanan pleaded guilty in the US for his role in the Scattered Spider operations.

In September last year, after making the headlines for high-profile attacks against the retail, insurance, and aviation industries, Scattered Spider announced its retirement.

Related: Third DraftKings Hacker Sentenced to 18 Months in Prison

Related: Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

Related: Canadian Man Arrested for Operating Kimwolf Botnet

Related: Karakurt Ransomware Negotiator Sentenced to Prison

https://www.securityweek.com/alleged-scattered-spider-hacker-extradited-to-us/