Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Attacks. Show all posts

Polish Dental Software Firm Hit by Cyberattack

 

Polish dental software provider FELG Software has confirmed a cybersecurity incident affecting its FELG Dent cloud-based practice management platform. The company became aware of the attack on September 28, 2026, and publicly acknowledged it on October 1. A threat actor using the alias Horus reportedly contacted Polish cybersecurity news outlets, claiming to have accessed sensitive information stored in the system. FELG Software also confirmed receiving a ransom demand in exchange for preventing the disclosure of the allegedly stolen data. More than 16,000 dentists reportedly use the company’s tools, meaning one vendor breach could affect patients from numerous independent practices. 

The attackers claim to have obtained records linked to approximately 2.4 million patients and more than 700,000 medical professionals. The allegedly exposed information includes names, addresses, telephone numbers, national identification numbers known as PESEL, company details, medical records, electronic prescriptions, electronic sick-leave certificates and insurance-verification information. The group also claims to have accessed around 1.2 million prescriptions, visit documentation and diagnostic images. However, these figures have not been independently verified, and the company disputes the attackers’ assessment of the incident’s scale. 

FELG Software has reportedly said that the stolen information represents about 10 percent of its overall database, rather than the complete dataset claimed by Horus. Reports also indicate that the attackers threatened to publish or sell the information after the company refused to pay the ransom. One reported explanation for the intrusion involves an IDOR vulnerability, or Insecure Direct Object Reference flaw. Such weaknesses can allow unauthorized users to manipulate references in requests and retrieve records belonging to other accounts when access controls are not properly enforced. 

The incident is significant because FELG Dent operates as a shared platform for many healthcare organizations. A weakness in the central service can therefore create risks across multiple dental practices at the same time. The breach is also reportedly the third attack in three months targeting Polish healthcare software providers, following incidents involving MyDr in August and Medyc, operated by Qbusoft, in September. These repeated attacks highlight the risks created when sensitive medical information is concentrated in cloud systems without strong tenant isolation, monitoring and access controls. 

The exact scope of the FELG Dent breach remains under investigation. Dental practices using the service may need to review logs, identify affected patients and assess their legal notification responsibilities under applicable data-protection rules. Healthcare providers should also reset potentially compromised credentials, monitor suspicious activity and communicate carefully with patients without relying solely on unverified attacker claims. The case demonstrates why software vendors handling medical data require regular security testing, strict authorization controls, vulnerability disclosure processes and tested incident-response plans. Until forensic investigations are complete, the number of affected records and the precise information accessed should be treated as provisional.

China Nexus Cyber Espionage Attacks Government Organizations


A China-nexus cyber-espionage campaign is targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called Antino. Researchers at Cisco Talos are tracking the threat activity as UAT-11587.

Campaign details 

The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. By July 2026, Talos had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints.

The campaign's lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests,” Talos said.

The most notable feature of Antino is its use of legitimate Microsoft 365 services as command-and-control (C2) infrastructure. Instead of relying on a traditional attacker-controlled server, the malware communicates through Microsoft Outlook and OneDrive using Microsoft Graph.

About Antino

Antino is a Rust-compiled Windows backdoor capable of gathering information about infected systems, executing commands through Windows shell and PowerShell, transferring files, loading shellcode directly into memory and maintaining persistence.

About the infection 

The infection generally begins with a carefully prepared spear-phishing email. Attackers used government, diplomatic, maritime, legislative and foreign-policy themes designed to appear relevant to their intended victims.

Attack tactic

In some cases, the attackers recreated Gmail’s attachment-preview interface inside the email. When victims interacted with the fake attachment, they were directed to attacker-controlled infrastructure.

The attack then proceeds through multiple stages involving HTA or WSF files, JavaScript and a .NET-based downloader before ultimately installing Antino. The malware has also been deployed through DLL sideloading, using a legitimate Microsoft-signed executable to load the malicious DLL. 

Once installed, Antino uses Microsoft Graph to communicate with Microsoft 365. Outlook is used for receiving commands, while OneDrive handles heartbeat communications and file transfers. This allows malicious traffic to terminate at legitimate Microsoft infrastructure, potentially making conventional network-based detection more difficult.

Impact on systems

A successful Antino infection can provide attackers with persistent access to a Windows system, allowing them to conduct reconnaissance, execute commands, run PowerShell, access files and transfer data.

The targeting of government agencies, diplomatic organizations, universities, think tanks and policy groups suggests that the campaign is focused primarily on intelligence gathering and espionage rather than ordinary financial cybercrime.

Cisco Talos assessed UAT-11587 as China-nexus with high confidence, citing technical, language, infrastructure and targeting indicators. However, researchers noted that attribution to a specific Chinese group remains more complicated. 

AI Turns Into Both Threat and Shield in Supply-Chain Cyberattacks

 

Artificial intelligence is emerging as both a growing cybersecurity risk and a critical defence tool for supply-chain companies. As warehouses, factories and logistics networks adopt connected sensors, GPS tracking, tablets and automated equipment, every new digital connection can potentially give attackers another route into operational systems. 

Recent incidents underline the scale of the threat. Uber Freight disclosed unauthorized access to part of its systems and data in mid-August, while Ceva Logistics reported a breach affecting multiple companies and exposing customer information. Coca-Cola dairy brand Fairlife was also struck by ransomware, temporarily suspending its US operations. Such attacks can halt production, delay deliveries and cause time-sensitive products to spoil. 

The consequences can extend well beyond the directly targeted business. When Jaguar Land Rover suffered a cyberattack last fall, its production remained halted for six weeks, disrupting suppliers and reportedly contributing to the failure of some smaller companies. Software supply-chain attacks create an additional danger because compromised code can spread malware across many organisations using the same tools or automated systems. 

AI-powered security systems can help companies identify unusual activity, scan code for vulnerabilities and flag deviations from normal system behaviour. When a potential weakness is detected, organisations can deploy patches quickly before attackers exploit it. However, technology alone is not enough. Employees across offices, plants and warehouses need training to recognize phishing attempts, protect privileged access and use strong password-management practices. 

The challenge is becoming more difficult as criminals use AI to create convincing phishing emails, deepfake voice calls and fake videos that remove traditional warning signs such as poor grammar. Businesses are therefore reassessing supplier contracts, cybersecurity audits and third-party risk management. With more diversified supplier networks sharing inventory, operational and customer data, firms must ensure partners maintain comparable security standards and maintain incident-response plans. In an era when attackers can use AI to find weaknesses rapidly, using AI for defence is becoming essential.

Mayor Confirms Ransomware Incident Disrupted Mississippi City Systems


The city of Vicksburg, Mississippi, has taken its computer systems offline after a ransomware attack disrupted several city functions. Mayor Willis Thompson confirmed the incident and announced a temporary shutdown while officials investigate the incident and restore the affected systems. Due to this incident, residents will be unable to use online utility payment services and will experience delays making payments in person due to the incident. 

Even with the disruption, emergency response, police, fire, and utility services remain operational. In addition, residents of Vicksburg will not be subjected to late payments or termination of utility services while the systems remain offline, according to the city. As part of the recovery effort, Vicksburg has enlisted outside cybersecurity experts and is working with the FBI, Department of Homeland Security, and state officials. 

As part of the investigation, officials are examining whether personal or confidential information belonging to customers, contractors, vendors, employees or business partners has been accessed. As of this writing, officials do not know whether any information has been accessed or taken without authorization. Also, it has not been disclosed who the attackers are or whether a ransom demand has been placed. 

Although the investigation and system recovery are ongoing, technical details about the incident will remain withheld while questions remain regarding its exact nature and scope. Reporting has not been able to establish whether the incident involved the encryption of city systems typically associated with ransomware or whether the term was being used in connection with a ransom demand. 

There was no publicly asserted responsibility at the time of reporting, and the city did not disclose whether a ransom was demanded, or whether any communication with the attackers occurred. In addition, officials have withheld technical information that could impact the ongoing investigation. 

Investigations are aimed at investigating whether the incident exposed personal or confidential information of current and former customers, contractors, vendors, employees and affiliated business partners, as well as other parties involved. 

If a compromise is confirmed, officials have informed affected individuals that appropriate information and resources will be provided. However, a final determination has not been reached regarding whether such information was accessed or acquired without authorization.

The city is currently partnering with external cybersecurity specialists and other partners in order to secure the restoration of affected services, alongside the investigation. Some routine government operations, particularly utility payment processing, have already been affected by the shutdown, even though vital emergency and utility services have been provided. 

There are approximately 10,000 utility accounts that are serviced by the city's water and gas office, which means that the disruption may affect a significant proportion of the local community. Other ransomware attacks have also been reported in Mississippi following the Vicksburg incident. As part of its recovery process, the University of Mississippi Medical Center consulted with the FBI following a ransomware incident that caused parts of its systems to be unavailable for several weeks. 

In previous years, Mississippi saw ransomware affect an electric utility and a county government, highlighting that a number of public-sector and critical service organizations have experienced similar disruptions. However, Vicksburg is unsure whether the shutdown will last for a prolonged period of time. 

Investigations are currently underway to determine how the intrusion occurred, which systems were affected, and whether any sensitive information has been compromised. Further details will be provided once verified findings have been identified.

Federal Agencies Disrupt Ransomware Gang Involving A 16-Year Old Member


An international law enforcement operation known as "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, resulting in three arrests and identifying a 16-year-old as the group's alleged administrator.

Combined efforts in finding suspects

Europol and Eurojust, as well as cybersecurity companies Bitdefender and Group-IB, all contributed to the investigation.
"The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," according to Europol.
"Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds,” Europe stated.

About the investigation 

The inquiry started last year and assisted officials in finding suspects like negotiator, administrator, and associate of the cybercrime gang.
As per Europol, the suspected main operator and administrator of KillSec is 16 years old. 
Officials have also discovered members suspected of being an affiliate and a negotiator.
KillSec, also known as Kill Security or k1llsec, has reportedly been active since around 2024 and operated as a ransomware-as-a-service (RaaS) group. 

About the attack 

Investigators say the attackers gained access to organizations by exploiting software vulnerabilities and poorly secured access points, including systems associated with cloud storage.
After gaining access, the attackers allegedly stole sensitive corporate information and transferred it to infrastructure controlled by the group. They then used a dark-web leak site to pressure victims into paying ransom. Victims were threatened with the public release of stolen information if they refused to pay.

The impact 

Investigators have linked KillSec to approximately 1,000 suspected attacks worldwide, with around 500 currently identified as successful. Authorities stressed that these figures could change as they continue examining seized computers, servers and other evidence. At least 70 suspected attacks involved organizations in Germany, including 18 connected to Hamburg. 
Investigators also found that KillSec members allegedly used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.
By taking control of KillSec’s leak site and servers, authorities have prevented the group from continuing to use that infrastructure to publish stolen information. However, the seizure cannot necessarily remove copies of information that may already have been obtained by criminals or downloaded by others.
The investigation may also identify additional victims, attacks and individuals involved in the operation.
Authorities are now analyzing the seized evidence and tracing alleged criminal proceeds, including cryptocurrency.

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns

 

Microsoft has warned of a new wave of phishing campaigns that abuse the legitimate MSP360 Remote Monitoring and Management (RMM) software to establish persistent remote access on victim devices. Once this foothold is secured, attackers deploy a second RMM tool, ConnectWise ScreenConnect, creating a redundant channel for control and further malicious activity. This dual-RMM technique enables threat actors to blend into normal IT operations while carrying out credential theft and data exfiltration with reduced risk of detection. 

The attack chain, observed by Microsoft in July 2026, begins with phishing emails disguised as meeting invites, PDF-related lures, or fake software update prompts. These messages distribute a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames such as “ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe” or “PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe.” When executed, the installer drops multiple DLLs, triggers a User Account Control (UAC) elevation to gain privileged context, and establishes persistence by registering Windows services and autorun Registry entries. It also modifies Windows Firewall rules to allow inbound UDP traffic to MSP360 on port 48678, ensuring uninterrupted remote access.

With MSP360 in place, attackers leverage its PowerShell execution capabilities to stealthily install ScreenConnect on the compromised endpoint. This second RMM client provides a backup remote-access path and is used to transfer additional payloads, run post-compromise tools, and perform information collection and credential-access operations. Microsoft notes that ScreenConnect’s native RunFile functionality is abused to execute these payloads, further camouflaging malicious activity within legitimate administrative workflows. The combination of two trusted RMM platforms gives attackers flexibility and resilience, allowing them to maintain control even if one channel is disrupted. 

In a parallel set of incidents during the same period, Microsoft observed attackers substituting MSP360 with Faronics Deploy Agent before installing ScreenConnect, indicating a broader pattern of RMM abuse. While no specific threat group has been attributed to these campaigns, the consistent use of multiple RMM tools suggests a coordinated effort to maximize persistence and minimize detection. By relying on signed, legitimate software, attackers reduce the likelihood of triggering endpoint security alerts, making these intrusions particularly challenging to identify without behavioral monitoring.

Organizations are advised to enforce strict application allowlisting, monitor for unusual RMM installations, and scrutinize processes that invoke UAC elevation or modify firewall rules. Security teams should also track anomalous PowerShell activity and unexpected service registrations linked to RMM agents. As remote administration tools become increasingly weaponized, a defense-in-depth strategy combining endpoint detection, network segmentation, and user awareness training is critical to mitigating dual-RMM phishing threats.

Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks


ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake artificial intelligence assistants. A campaign identified by Huntress in which attacker-controlled Custom GPTs were impersonating legitimate ChatGPT offers and directing victims to ClickFix scams has been identified. 

A total of 40 incidents associated with the same Google Sites infrastructure were linked to the campaign, and two of these cases have been confirmed to originate from malicious Custom GPTs. OpenAI reported a GPT that had been identified and removed on September 25, however two days later researchers identified another GPT that had been connected to the same campaign. 

The attack is initiated by a Custom GPT that appears to be a genuine ChatGPT service. It has been reported that some victims have reached the malicious GPT by searching for ChatGPT on Google and clicking a sponsored result. While the page itself remained hosted on the legitimate ChatGPT domain, the GPT was titled Plus 5.6, giving the appearance that it was an official model. 

A false message claiming that the primary domain was restricted to a limited number of users was displayed when the GPT was opened. After that, the website directed users to a fake backup website hosted on Google Sites, where a false Cloudflare CAPTCHA was displayed and a technique known as ClickFix was utilized to entice the victim into manually executing a command. 

PowerShell is launched by the command to retrieve an obfuscated script, which is temporarily saved before executing. After a silent download of a malicious MSI package named ISOSimple.msi, the script silently installs it. During the subsequent attack chain, the installer appears to be a legitimate Canon-signed application that is used to install an “Advanced Printer Configuration Reader”. 

Even when security software detected part of the payload, the infection was designed to remain active. One incident involved Microsoft Defender quarantining ISOSimple.msi as Trojan:Script/Wacatac.H!ml, because it had already set up a Run key and a scheduled task called “Canon Configuration Reader.” These keys and tasks allowed the malware to continue running on the computer. 

DLL sideloading is the next stage. With the MSI, the legitimate Canon COTFileReadApp.exe is installed, which has a valid digital signature, making the malicious package appear less suspicious. Attackers inserted a modified logging library alongside the executable, causing the legitimate Canon application to load malicious code through Windows' DLL search process as a result. 

The sideloaded code then extracts the next payload from a .wav file included in the installer Even though the file contains authentic audio data at the beginning and a valid WAV header, there are later sections that contain encrypted data that is decoded in memory. 

To avoid simple file-based detection, the loader retrieves an encrypted archive containing the malware and its persistence components and eventually eliminates straightforward file-based detection. There are 315 folders and 806 files contained within the archive, known as monitor.raw, which has a custom encrypted file structure. It contains a persistence script that continuously checks the registry for the malware's run entry and scheduled task, and recreates them if they are removed. 

In both instances, the infection can be re-executed by launching the Canon executable under the name "Canon Configuration Reader" by launching the Canon executable. An advanced Remote Access Trojan is attached to the final payload, which can provide access to the computer's desktop and screen, capture input from the camera, microphone, and audio system, and search for files on the computer. 

Additionally, the program collects information regarding security software installed, Windows configuration, network adapters, open ports, software installed and hardware installed. Command-and-control communication is carried out through DNS-over-HTTPS via services such as Cloudflare, Google, and Quad9, allowing its network traffic to blend in with legitimate encrypted web traffic.

In addition to downloading and executing additional EXE, DLL, MSI, PowerShell, and script-based payloads, attackers can extend activity beyond the initial compromise by downloading additional payloads. After removing the first Custom GPT from the campaign, Hunters discovered a second version. In addition to keeping the underlying RAT unchanged, the attackers replaced the Canon-based execution chain with a modified DLL and signed Stardock executables. 

In addition, the loader was moved from the WAV file into a Microsoft NuGet package, demonstrating that the delivery components can be changed without replacing the core malware. A second variant included additional measures to make detection more difficult, including freshly obfuscated download scripts and the removal of Windows Mark-of-the-Web tags before the MSI was executed. 

Nonetheless, the main behavior remained the same: MSI installation resulted from PowerShell activity, malicious code was loaded from a legitimate signed application, and persistent registry and scheduled task access was maintained. 

Therefore, security researchers advise that detection should be focused on behavior connecting these stages rather than relying solely on specific filenames or trusted software brands. It is possible to detect this type of attack by suspicious PowerShell activity followed by Msiexec, signed applications running from unusual locations, unexpected DLL loading, and newly created Run keys and scheduled tasks.

Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks

 

Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible threat intelligence of a potential imminent cyberattack. The recommendation, communicated directly to enterprise and government clients, was described as a precautionary measure rather than a response to any confirmed compromise of systems. According to reports, the company received specific warnings from federal law enforcement agencies indicating that a threat actor may attempt to target Kiteworks installations over the weekend. 

The shutdown window was carefully scheduled to accommodate customers across multiple time zones, spanning from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, organizations were instructed to take their Kiteworks systems offline between 4:00 a.m. and 10:00 a.m. on Saturday, September 26, while customers in New York faced a window from 10:00 p.m. Friday to 4:00 a.m. Saturday. Company representatives reportedly advised clients to shut down servers before the scheduled window began and emphasized that systems should be taken offline even if they were not directly accessible from the Internet, reflecting the seriousness of the potential threat. 

Kiteworks explicitly stated that it was not aware of any actual compromise of its systems and characterized the advisory as preventative in nature. The company confirmed that all known vulnerabilities affecting its platform had already been addressed in the current software release, version 9.5.1, and continued to recommend that customers run the latest version available. Despite this assurance, customer support representatives reportedly indicated to technology journalists that the shutdown recommendation was specifically intended to protect against potential zero-day attacks, though neither the official company statement nor the customer notification explicitly confirmed the discovery or exploitation of such a vulnerability. 

The potential targeting of Kiteworks platforms carries significant implications given the nature of the software and its typical user base. The company develops secure file-transfer and communications products that are widely used by government organizations, financial institutions, and large enterprises to handle sensitive documents and data. Secure file-sharing platforms represent high-value targets for cybercriminals who specialize in data-theft extortion attacks, as they commonly store confidential information that organizations would be desperate to protect from public exposure or unauthorized access. 

While the specific threat actor behind the potential attacks remains unidentified, the cybersecurity community has noted historical patterns that raise particular concerns. The Clop extortion gang has established a long history of targeting enterprise file-transfer platforms in sophisticated data-theft campaigns, including previous attacks against Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer systems. The U.S. Department of State currently offers a ten million dollar reward for information that could link this cybercrime gang's operations to foreign government sponsorship, underscoring the geopolitical dimensions that often accompany major enterprise security incidents of this nature.

OAuth Phishing Attacks Bypass Passwords by Turning User Consent Into a Security Threat

 

Cybercriminals are targeting something more difficult to protect with traditional password advice: the user consent. New phishing techniques called OAuth consent phishing allow the intruders to gain persistent access to the targeted accounts without stealing their passwords, according to a recent FBI warning. The bureau’s Internet Crime Complaint Center described the technique in a September 1 public service announcement, noting that it has been observed since late 2025 and is targeting prominent individuals and their families and personal contacts. 

The FBI describes OAuth consent phishing as accessing accounts without requiring the user’s password. OAuth is the framework that allows the services to use the familiar “Sign in with” or “Continue with” authentication options. It allows the legitimate third-party applications to request access to the resources like emails, calendars, files, and cloud storage without requiring the users to share their passwords. 

The attackers are taking advantage of the legitimate procedure to get account access. The attack typically starts with sending a message that appears to be sent from a trusted contact or service. The victim clicks on the link and enters their credentials on a real login page of a trusted site. The user is then directed to an app authorization screen asking to allow specific permissions such as reading emails or accessing files. 

If the victim approves the request, the intruder receives an OAuth authorization token with the permissions granted. This changes the response needed to compromise. Unlike with traditional credential phishing, changing the password will not eliminate the malicious OAuth token. The FBI recommends that the victims revoke the unauthorized authorization through their application security settings. Changing the credentials or using a new MFA code will not remove the granted access. The campaigns can also scale. 

In recent months, security researchers have documented 10 to 15 new operations of this type every 24 hours in recent months, with several million attacks recorded during a single four-week period earlier this year. Phishing kits such as Kali365 and EvilTokens have further lowered the technical barrier for attackers. Security tools can help address some of the attack steps, without preventing the user from voluntarily approved malicious permission request. 

The network can block known phishing domains, malicious redirectors, and scam infrastructure before the victim reaches them. Dark web monitoring can also alert users if their email addresses appear on cybercrime forums after an account compromise. The change highlights a shortcoming in traditional account-security advice: protecting passwords and MFA remains important, but users must scrutinize the applications and permissions they authorize.

A Go Worm Stole MemTensor's CI Tokens and Shipped Backdoored Packages to npm and PyPI

 



On September 23, 2026, an attacker spent roughly five hours poisoning two packages belonging to MemTensor, the company behind the MemOS operating system for AI memory. By the time a researcher flagged the issue on GitHub at 4:17 AM UTC, malicious versions were already sitting at the top of the npm and PyPI registries, ready to install for any developer who ran a plain `npm install` or `pip install MemoryOS` that morning.

The packages hit were `@memtensor/memos-cloud-openclaw-plugin` on npm and `MemoryOS` on PyPI. Security firm SafeDep, which flagged the incident through its threat intelligence monitoring, found that three npm versions, `0.1.21`, `0.1.23`, and `0.1.25`, and one PyPI version, `2.0.34`, all contained the same Go binary: a credential-harvesting implant the attacker internally called `sckit`, built under the module path `supplychain.local/campaign`.


How the Attacker Got Inside the Pipeline

The attacker did not need a zero-day. Instead, they exploited a well-understood weakness in how GitHub Actions jobs share environment state.

The OpenClaw plugin publishes to npm through a GitHub Actions release workflow that reads its publish token from a repository secret. The attacker, operating through a GitHub account called `Memtensor-AI`, pushed a short-lived branch named `sc/release-0.1.21-20260922-cloud`, made a three-line change to a validation script that runs earlier in the same job, then deleted the branch. They repeated this process five times between 00:48 and 02:03 UTC.

The change was precise: it wrote a `BASH_ENV` entry into `$GITHUB_ENV`, which is GitHub's mechanism for passing environment variables between steps. Because Bash reads the file named in `BASH_ENV` before running any non-interactive script, this let the attacker's shell script execute silently before the real publish step. That script called `collectStageZero()` from within the package itself, passed the `NPM_TOKEN` to the `sckit` binary, then deleted itself and exited with a failure code. The publish step failed visibly, so nothing appeared on npm from that run. The token was already gone.

The PyPI compromise used the same `BASH_ENV` trick but through a different entry point. The attacker pushed an unsigned commit to the MemOS repository that replaced the standard build backend in `pyproject.toml` with a custom wrapper called `sckit_poetry_build`. On import, that wrapper injected its own bridge script into the CI environment. The bridge ran only inside the PyPI upload action's container, captured `INPUT_PASSWORD` (the PyPI token), sent it to a server at `10729e014d0e.skyleen[.]fr`, and then exited cleanly. Two hours later, a follow-up commit removed the capture code, and the next tag push uploaded the fully malicious wheel to PyPI using MemTensor's own legitimate credentials.


What the Package Does After Install

The implant activates at runtime, not at install time, so `--ignore-scripts` offers no protection. In the npm plugin, it fires when the OpenClaw gateway starts and again on every memory recall. In the Python library, it starts the first time `configure_logging()` runs, which happens on nearly every import path. The binary launches detached in the background with no output.

Once running, `sckit` scans the entire home directory for credentials. Its target list, visible in its strings and symbol names, covers `.npmrc`, `.pypirc`, `.git-credentials`, `.netrc`, SSH private keys, HashiCorp Vault tokens, and Microsoft MSAL token caches. Two compiled regular expressions recognize both secret-like variable names and token format patterns for AWS, GitHub, npm, PyPI, HuggingFace, Slack, and Stripe. Collected data goes to subdomains of `skyleen[.]fr`, the campaign's control infrastructure, over encrypted channels using X25519 key exchange and XChaCha20-Poly1305.

The binary also carries worm logic. Functions named `findRepositories`, `prepareRemoteNode`, `prepareRemotePython`, and `recursivePublish` describe how it uses stolen credentials to inject itself into other repositories. It plants a GitHub Actions workflow named `runtime-update.yml` and a `.sckit/` directory into reachable projects, turning each victim into a potential carrier. The campaign configuration encodes an expiry date of late October 2026, suggesting the attacker planned a defined window of operation.


Developers Need to Act Now

Anyone who ran an affected version should treat every credential in their home directory as stolen. That includes cloud CLI tokens, SSH keys, and any `.env` files. SafeDep recommends pinning to `0.1.20` for the npm plugin and `2.0.33` for `MemoryOS`, killing any running `sckit` process, deleting the state directories at `$HOME/.openclaw/.cache/runtime` and `$HOME/.memos/.cache/runtime`, and checking any repository with push access for the `runtime-update.yml` workflow file.

The attack sits inside a larger pattern. The first half of 2026 alone produced 37 supply chain attack campaigns and 497 indexed malicious packages, which is 4.5 times the package volume of the entire preceding year. What separates this incident is the operational sophistication: the attacker used the target project's own CI pipeline as the delivery mechanism, left no workflow run logs behind, and built self-propagation directly into the implant. For maintainers who publish from CI, PyPI's trusted publishing removes long-lived tokens from the job entirely. Required reviewers on release environments would have blocked the MemTensor runs before they started.



Cyberattack Hits University of Munich, Exposing Student Data

 

Germany’s Ludwig Maximilian University of Munich (LMU) is investigating a significant cyberattack that potentially exposed sensitive student information, including financial aid and health insurance data. The breach, detected on a Wednesday, led the university to disconnect affected servers and engage external cyber security experts while cooperating with law enforcement. 

The compromised records reportedly include students’ names, dates of birth, contact details, LMU email addresses, bank account information, and details about their courses of study and prior educational qualifications. In some cases, health insurance numbers and identifiers linked to Germany’s student financial aid program may also have been accessed, along with data related to leaves of absence. However, the university confirmed that examination records, specific course content, and individual academic performance data were not affected. 

Operational impact and response 

Following the discovery of the breach, LMU took several systems offline as a precaution, temporarily disrupting some internal services. While teaching activities continued uninterrupted, enrollment processes were briefly suspended and are expected to resume with extended deadlines to ensure students are not disadvantaged. Some students reported difficulties accessing university services needed for semester preparation, including course registration and grade viewing. The institution has not disclosed the number of affected individuals or the duration of unauthorized access, and no ransom demand has been publicly confirmed. 

Universities remain attractive targets for cybercriminals due to their extensive networks containing vast amounts of personal and financial information across large populations of students, researchers, and staff. Recent ransomware attacks have affected prominent U.S. institutions such as the University of Texas, University of Oklahoma, Stanford University, and the University of Michigan, with several incidents occurring after holiday breaks. Other notable cases include disruptions at the University of Pennsylvania, Columbia University, and Harvard University over the past years.

LMU has enlisted specialists to monitor dark-web forums and other platforms for signs that the stolen information is being circulated or misused. While there is currently no evidence that the data has been altered, deleted, or published, the investigation remains ongoing to determine the full extent of the breach. The attacker has not yet been identified, and the university continues to work with cybersecurity professionals and authorities to secure its systems and protect affected students.

TraderTraitor Mac Malware Targets IT Firm Through Weaponized Terraform Projects

 

A North Korean-linked cybercrime group known as TraderTraitor has tied another macOS infection in an IT services company with no cryptocurrency ties to the exploitation of fake job interviews to gain access to developer systems. The second victim, which has been identified as an India-based IT services provider, was targeted through one of the employees’ Apple Silicon MacBook belonging to a DevOps engineer. 

The compromised machine was used to manage AWS, OVH and OpenStack environments with the help of Terraform and Ansible, while the account also held cloud credentials and source code access. SentinelOne attributed the breach to the same FLATROOF and ROOFDECK macOS backdoors employed by TraderTraitor in the attack targeting LayerZero Labs that resulted in the $292 million heist from crypto project KelpDAO. Initially detected on March 18 the malicious implants remained undetected until March 29, when they were triggered by the victim launching a workspace within the Cursor development environment. 

FLATROOF implant, which has been dropped as SystemUpdate, can be used to execute arbitrary shell commands, terminate processes and steal data. Its capabilities also include harvesting browser information, terminal history, installed applications, running processes, system properties and the macOS login keychain database. ROOFDECK, which was deployed as iSync utility, allows for full command and control over the compromised system while also facilitating reverse shell access, file transfer exfiltration of data, reconnaissance, and persistent access through the use of LaunchAgents. 

It also has the capability to read the clipboard content, which may also contain passwords, cryptocurrency seed phrases and two-factor authentication (2FA) credentials. On April 20, which came shortly after the public disclosure of the LayerZero breach, the threat actors deployed a modified version of ROOFDECK while removing the initial implants. The new sample continued to communicate with the C2 infrastructure controlled by the attacker until June 1. “The incident serves as a stark reminder that developer endpoints must always be protected and monitored for suspicious activity,” the report noted. 

“These machines can serve as a gateway to cloud infrastructure, source code and deployment resources, which makes them attractive targets even for organizations with no direct involvement in crypto operations.” It added that organizations should carefully monitor developer workstations for anomalous behaviors, including the launch of unsigned binary from the home directory, processes spawned by the development environments, and unusual network connections. 

It also recommended conducting regular audits of the Terraform lock files and make sure that the providers listed in them are legitimate before launching unfamiliar coding assignments or repositories.

Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang

 




The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with their own branding, and is now threatening to put Clop through the same extortion process Clop runs on its corporate victims.

The attack happened Friday night, September 19. ShinyHunters found an unauthenticated file upload flaw in Grav CMS, the content management system Clop was running its leak site on, and used it to push a text file directly onto the server. The file read: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time." It also linked back to ShinyHunters' own Tor site. The file was confirmed live and downloadable directly from Clop's server.

Hours later, ShinyHunters said they had gone further. A visit to Clop's site showed the entire page replaced with ASCII art of Umbreon, the Pokemon ShinyHunters uses as its logo, and the line "rooting your systems since '19 ;)". The same Umbreon artwork had appeared when ShinyHunters defaced HackForums back in August 2020. Clop's defaced page was still live at the time of writing.

ShinyHunters claimed full access to the server and said they took source code, Grav CMS plugins, and everything stored in the server's /var/log directory, which typically holds authentication logs, system activity records, and the IP addresses of everyone who connected to it. They also claim to have pulled the private keys for Clop's Tor onion service. Those keys are what tie a .onion address to its server. With them, ShinyHunters could host a copy of Clop's site at the exact same onion URL, on infrastructure they control. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said.

The plan is to post an extortion message on their own site and give Clop 72 hours to respond.

The defacement and the uploaded file are independently confirmed. The claims about stolen source code, server logs, and Tor private keys come only from ShinyHunters and have not been independently verified. Clop has not commented.

The dispute behind this attack goes back about a year. In August 2025, Clop quietly began exploiting a zero-day vulnerability in Oracle E-Business Suite, tracked as CVE-2025-61882, a server-side request forgery flaw that gave attackers remote access to enterprise systems without authentication. Oracle did not patch it until October 2025, after Mandiant confirmed active exploitation. By then, Clop had already sent mass extortion emails to executives at dozens of companies, including Cox Enterprises, The Washington Post, Logitech, Michelin, and Estee Lauder.

ShinyHunters says that exploit was originally theirs and that Clop used it without authorization. In October 2025, ShinyHunters, operating under the name "Scattered Lapsus$ Hunters," leaked the proof-of-concept publicly. Oracle confirmed it matched the exploit used in the Clop attacks. ShinyHunters said the leak was deliberate, intended to disrupt Clop's campaign and expose what had been taken from them.

What followed, according to ShinyHunters, was a direct threat from a Clop representative. "During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," the group said. Those allegations have not been independently verified.

This is not the first time criminal groups have turned on each other. In March 2025, DragonForce defaced the leak sites of rival operations BlackLock and Mamona. Later in 2026, two groups called 0APT and KryBit hacked and leaked each other's operational data until both were left severely damaged. The difference in the Clop case is the scale of the target. Clop's leak site is the operational center of its entire extortion model, the platform it uses to name victims and apply public pressure when ransoms go unpaid. Losing control of it, and potentially the keys that anchor its onion address, is not a minor disruption.

ShinyHunters' own Tor site went offline shortly after the attack. No connection to Clop has been established.

RatHat Android Malware Uses AI to Control Infected Devices

 

A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and using a variety of methods to maintain its presence. Researchers at Zimperium’s zLabs found indications that RatHat may be associated with threat actors based in China after they discovered Chinese language prompts within the malware’s AI subsystem. 

The malware is reported to be distributed through malicious advertising, SMS messages and phishing websites that promote APK downloads outside Google Play. RatHat takes advantage of Android’s Accessibility permissions to obtain extensive control over infected devices. This allows it to enable Developer Options and Wireless Debugging, granting it a local shell-level execution environment without the need for a separate computer. Researchers observed similarities with this technique that have been previously seen in the ToxicPanda and RedHook Android malware families. 

The malware utilizes Android Debug Bridge (ADB) access to install a Go-based agent called liblocal-service.so. The agent can execute commands with ADB shell privileges, bypassing battery restrictions and establishing persistence. It can also restore the malware in the case that the main component is removed or stopped. The relationship works in both directions, with the malware being able to restore the agent if the agent itself is deleted. 

RatHat also makes use of a second component, libmedia_codec.so, which acts as an FRP reverse-proxy client and establishes a persistent tunnel to the attackers. The malware has the ability to display HTML overlays over targeted banking and cryptocurrency applications in order to acquire the users’ credentials. Its information-stealing capabilities include SMS messages and notifications, including one-time passwords. RatHat can also monitor text changes, extract URLs from browser address bars and capture lock-screen PINs, passwords and unlock patterns. 

One of RatHat’s most interesting features is its AI-powered interface automation engine. According to Zimperium, the malware converts the Android Accessibility tree into XML and sends the resulting information to an unnamed popular AI assistant. This system can recognize the screen coordinates of requested interface elements and determine their displayed text and provide navigation commands such as scrolling instructions. This enables the malware to navigate Android interfaces more dynamically than other malware that exclusively rely on predetermined scripts. 

Zimperium stated that the AI-driven system makes the malware more adaptable and arguably harder for security software to detect. RatHat actively prevents victims from uninstalling the malware. When an uninstall confirmation screen appears, the malware can intercept the process and cancel the removal and display a fake Google Play overlay, which shows a fraudulent error message. The malware also contains a number of anti-analysis measures, including APK container manipulation, an unusually large 61MB Android manifest and invalid DEX pseudo-instructions that are designed to confuse or disrupt the functionality of security analysis tools. 

Android users are advised to avoid downloading APK files from outside Google Play unless the publisher is explicitly trusted and to be careful when granting Accessibility permissions to applications. In addition, users should regularly scan their devices using Google Play Protect.

Cyberattack Knocks International Meteor Organization Website Offline

 

A cyberattack has forced the International Meteor Organization (IMO), one of the leading providers of meteor observation, to take much of the website offline. Founded in 1988, the Belgium-based independent organization reported that the cyberattack caused severe damage to the aging infrastructure and left the organization dealing with several weeks of partial downtime as it transitions to new infrastructure. 

The organization has replaced its website with a static notice informing the visitors about the incident and warning that features will return gradually. “We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” the organization said. It explained that it expects several weeks of partial downtime while transitioning to new infrastructure and services. The IMO has prioritized restoring its fireball reporting system which is already available for users to submit their observations. The organization also shared its meteor and asteroid-related information on its Facebook page. 

The IMO was formed to bring amateur and professional meteor observers and scientists together. The organization has played an essential role in the development of international standards for meteor observations and the maintenance of a global database of meteor and fireball reports containing photographs, videos and telescopic observations. The organization has not publicly identified those responsible for the attack, and no hacking group had claimed responsibility as of Wednesday afternoon. The organization also did not respond to requests for additional comment. The incident comes shortly before the IMO’s annual international conference that is set to take place next week in France. 

It is unclear if the cyberattack will impact the event or the organization’s other activities. The incident also shows the growing interest of cybercriminals in targeting organizations involved in space and scientific research. U.S. agencies have warned that the rising economic importance of the space industry can attract attackers and organizations that engage in space-related activities can become potential targets. Attackers have targeted the National Science Foundation’s National Optical-Infrared Astronomy Research Laboratory in Hawai’i and the Atacama Large Millimeter Array observatory in Chile in 2023. 

The American Meteorological Society was also targeted by ransomware in the same year. For now, the IMO is focused on rebuilding its infrastructure and restoring the services after the attack, with additional website features expected to return as the transition progresses.

Brevo Breach Exposes Customer Websites to ClickFix Malware


Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code was able to reach Brevo's own websites as well as customers' websites utilizing embedded Brevo services. 

Researchers at Sansec discovered that the incident was much more extensive than the six accounts previously revealed. When Brevo infrastructure was compromised on September 14, 2026, malicious JavaScript began to be served. In addition, Sansec found evidence that more than 100,000 customer websites utilizing Brevo components may have been exposed as a result of the attack. 

There were two main infection paths used in the campaign: a malicious WordPress plugin that targeted site administrators and a ClickFix overlay that was displayed to visitors. 

Malicious Code Reached Embedded Brevo Components

Brevo-hosted pages as well as JavaScript resources commonly embedded in customer websites were identified as containing the injected code. These included Brevo trackers, Conversations chat widgets, as well as other forms hosted on Brevo servers. 

Modified versions of the JavaScript assets directed browsers to infrastructure controlled by attackers, which served the malicious malware loader. Sansec identified several malicious subdomains under the Brevo domain sendibt1.com. A number of hostnames were affected, including cdn.sendibt1.com, cdn2.sendibt1.com, cdn3.sendibt1.com, cdn4.sendibt1.com, cdn9.sendibt1.com, cdn10.sendibt1.com, and cdn11.sendibt1.com. 

A SSL certificate for cdn.sendibt1.com was also discovered on August 25, which indicates that the attackers had gained access to Brevo's DNS records. A malicious content display was observed on September 14 from approximately 16:05 until 20:13 UTC, which was observed by researchers. 

A total of 2,549 breaches of Content Security Policy were reported across 12 sites during and after the attack window. These hosts stopped resolving on September 15, while the affected files were reported clean at the site of origin. 

ClickFix Campaign Targeted Website Visitors

Injected malware delivered different payloads depending on the visitor. When a visitor was detected as a WordPress administrator, it attempted to install a plugin from a Brevo subdomain controlled by the attacker. A fake verification prompt was displayed using the ClickFix technique to visitors, instructing them to copy a command and execute it under the pretext of demonstrating their humanity. According to Sansec, the malware did not activate for crawlers, developers, or automated scanners, therefore preventing it from being detected during routine inspections. 

WordPress Sites Faced a Deeper Threat 

A more significant risk was posed to WordPress administrators by the attack. When the compromised Brevo script identified an administrator already logged into a WordPress site, it attempted to download and install plugins from attacker-controlled infrastructure. 

BleepingComputer examined a copy of the plugin, which was disguised as Web Media Optimizer, but was actually a JavaScript loader and persistent backdoor. Installing this plugin allowed it to hide from the normal WordPress plugin list and copy itself into the must-use plugins directory, making its removal more difficult. Additionally, the plugin contacted attacker-controlled infrastructure to obtain additional JavaScript, allowing malicious content to continue loading even if the remote server was unavailable, as researchers discovered. 

A critical feature of the plugin was that it contained a hardcoded authentication mechanism capable of creating a valid administrator session without requiring the legitimate administrator password. This allowed attackers to continue access to a compromised WordPress installation beyond Brevo's original exposure period. 

Brevo Took Down the Malicious Infrastructure

After detecting the intrusion, Brevo removed the malicious Cloudflare Worker and associated routes. As a result of the compromise, Brevo revoked its API key and credentials, removed attacker-controlled hostnames and purified edge caches. Additionally, the hardcoded Cloudflare credential was removed from the source code of the company. 

Sansec reports that malicious hosts began to cease resolving on September 15 and Brevo's affected files were restored to their original versions. Although the delivery window ended, the malware was not removed from WordPress sites where the rogue plugin had already been installed. Additionally, Brevo SSO security incident reported on September 10 also occurred following the incident. It was reported that six customer accounts were accessed unauthorised and were used for phishing, as well as contact data exported from 43 other accounts in that incident. 

A public connection has not been established between Brevo's earlier incident and Cloudflare's subsequent compromise. The Brevo incident illustrates the threat of third-party services that extend beyond the infrastructure of the provider and affect websites which utilize embedded scripts. Additionally, the combination of ClickFix lures and persistent WordPress backdoors creates a higher risk for website administrators and visitors alike.

Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding

 

A tanker crossing the Gulf of Mexico was boarded by U.S. Coast Guard and FBI personnel last month after its onboard network came under attack from hackers, the Coast Guard has confirmed. The confirmation followed a Wall Street Journal report indicating that at least two U.S.-bound tankers had been targeted in separate cyber incidents. Bloomberg News named one of the affected vessels as VL Prosperity, while Iran's state-backed outlet Mehr reported the ship went dark for a day and a half after losing its communications systems. Neither the FBI nor several other federal agencies contacted for comment addressed the incident directly, instead referring inquiries to the Coast Guard. 

A spokesperson there said the boarding was carried out to verify that the ship's technology systems remained intact after signs emerged that the network had been infiltrated by actors operating from outside the country. The operation took place on August 21 and involved a joint team: Coast Guard law enforcement officers, a cyber protection unit, a vessel inspector, and cyber specialists from the FBI. The spokesperson emphasized that no disruptions to the ship's operations, structural stability, crew safety, or the surrounding environment had been identified so far. Coast Guard officials declined to elaborate on how the breach occurred, who may have been responsible, or whether the tanker boarded that day was in fact VL Prosperity. 

A second vessel was reportedly boarded three days later, on August 24, per the Journal's reporting. Mehr's account places the origin of the attack earlier, on August 7, while the Liberian-flagged VL Prosperity was passing through the Strait of Gibraltar en route from Egypt to a U.S. port. One crew member described to Mehr how the intruders were reportedly able to remotely increase engine speed and shut down tanks holding fuel and engine oil. Analysts cited by the outlet, without offering direct evidence, tied the episode to broader tensions between the U.S. and Iran, though no group has publicly claimed involvement. Bloomberg later placed the tanker off the Texas coastline. The Coast Guard said it remains in contact with port operators, ship owners, and regional maritime partners to keep operations running smoothly. 

A separate incident struck just a day earlier, when North Carolina Ports disclosed that an external hacker or group had breached its IT infrastructure, pushing staff to switch to manual processes. The organization said it activated emergency protocols and looped in both state agencies and the Coast Guard. Maritime infrastructure worldwide has increasingly become a target for ransomware operators over the past several years, a trend tied to the sector's growing reliance on connected systems. 

The Port of Seattle famously refused to pay hackers who disrupted its airport and seaport operations around Labor Day in 2024. Similar attacks hit European ports and shipping firms Royal Dirkzwager and DNV in 2023, while Oiltanking and Mabanaft both declared force majeure after 2022 cyber incidents. Freight company Expeditors International also spent months recovering operational systems following its own attack.

US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms


Three Indian-based companies have been accused of conducting hacking campaigns and stealing data from thousands of Americans and US businesses, according to a bipartisan group of US senators. As part of the request, the lawmakers sought restrictions that could limit companies' access to American technology and services in a letter to U.S. Commerce Secretary Howard Lutnick. 

Among the companies named in the letter are Sunkissed Organic Pvt Ltd, BellTrox Ltd, and CyberRoot Ltd. Democratic Senator Ron Wyden and Sheldon Whitehouse, along with Republican Senator Pat Harrigan, allege that the groups had engaged in targeted espionage activities against US citizens, businesses and legal professionals over the past fifteen years. 

A number of senators cited investigations conducted by Reuters and The Citizen Lab, in which they claimed that the companies had been involved in hacking campaigns targeting pharmaceutical companies, private equity firms, and attorneys employed by major law firms. It was stated in the letter that the groups operated under the direction of the Qatari government and some of these operations were intended to influence ongoing litigation. 

According to the senators, the alleged activities included targeting individuals who oppose Qatar's bid for the World Cup, as well as the family members of the former Republican Chairman of the House Permanent Select Committee on Intelligence. 

A number of allegations go beyond the hacking activities themselves, as well. A number of foreign legal actions were taken by legislators that were intended to restrict public reporting of the alleged activities. One such case involved Appin, in which executives related to the company obtained a global court order from an Indian court requiring Reuters to cease investigating the company. The order was subsequently lifted, allowing the investigation to be republished by Reuters. According to the senators, the episode illustrates the possibility of restricting the availability of American information through foreign legal proceedings. Additionally, previous reporting has documented legal threats to media outlets that cover alleged hack-for-hire operations related to Appin. The US Commerce Department has now requested that BellTroX, CyberRoot, and Sunkissed Organic Farms be added to the Entity List by the Bureau of Industry and Security of the US Commerce Department. By making such a designation, US companies may not export or transfer certain technologies, software, and other controlled items to these listed entities without a license. The requested restrictions would specifically target access to American software, cloud infrastructure, and cybersecurity tools. This move remains a request from Congress, and any Entity List designation requires the Commerce Department to take action. US authorities are now considering possible restrictions on the three firms' access to American technology and services in light of the lawmakers' request for the three firms to be under renewed scrutiny.

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

 

China-linked hackers took advantage of a vulnerability within Sogou Input Method, a widely used typing utility for Chinese characters on Windows, and managed to implant a backdoor onto their victims' computers, security company Gen Digital stated in research published Thursday. 

An initial crafted link would kick off the chain of events, giving the attackers end-to-end access to perform anything the logged in user would have access to. Tencent, which both owns and is developing Sogou, has alreadypatched the vulnerability in April 2026. The vulnerability was uncovered by Gen as they tracked a live ongoing breach by a group known as UNC3569, a China based hacker-for-hire. The group has been tracked since 2021 by Google Threat Intelligence to government, academic, technology, and financial targets, predominantly in Eastern and Southeast Asia. 

The planted backdoor (GRAYRABBIT), is a small program the group has been using for many years. As the first stage of gaining access to a machine, it is used to create a command shell remotely from the attacker, allowing for the uploading and downloading of files. More modules from the attacker's server could also be added into a system at any point via this command-line interface. Research produced in 2023 by Citizen Lab suggests that Sogou Input Method boasts over 455,000,000 monthly users on Windows, Android, and iOS respectively, and has captured approximately 70% of the Chinese input-method market. 

On Windows, this application functions by having several components send messages between one another utilizing its own custom link type, sgbiz:. Gen discovered that the program intended to process these links had an error. It failed to correctly screen command-line arguments from the user, meaning attackers can order Sogou's settings program to instead launch its skin store functionality, but directing it towards the attacker controlled website instead- the only functioning part of the application that opens the browsing window without checking which site you are visiting. 

This browser is already outdated; embedded within the Sogou package is version 80 of Chromium from March 2020. Neither the sandbox protection, nor the same-origin policy in this Chromium build were disabled in the codebase. This allowed a vulnerability released within the Java Script Engine in October 2021 (CVE-2021-38003, fixed in Chrome 95 October that year) to be taken advantage of once more by Chinese hackers. The exploit sends a downloader which can then fetch a few files from an Alibaba Cloud server situated in Hong Kong. 

One file was a DLL designed to spoof and hide inside a pirated copy of 7-Zip. Running processes would be scrutinized for analysis methods in a sandboxed environment prior to deployment of the GRAYRABBIT, which sends out requests for and receives information from a command server, encrypted by RC4 over port 443. Gen alerted Tencent on April 9 th 2026 (the vulnerability has been noted under the designation CVE-2026-51990), and Tencent provided a fix within twelve days in version 16.3.0.3498 (released April 21 st). 

It should be noted that the vulnerability present with the old Chromium build and compromised securities does not appear to have been amended. Users are instructed to update their version of Sogou Input Method without delay, and maintain an eye on the indicators of compromise on publication, which includes the malicious DLL, backdoor files, and applicable command and control websites.