The Good, the Bad and the Ugly in Cybersecurity – Week 35
The Good | Authorities Launch New Operations Against Cybercrime Networks & Supply Chain At 2026-8-28 16:1:30 Author: www.sentinelone.com(查看原文) 阅读量:2 收藏

The Good | Authorities Launch New Operations Against Cybercrime Networks & Supply Chain Attackers

Operation Jackal IV, coordinated by INTERPOL across 22 nations, has led to the arrest of 58 individuals and the identification of over 200 suspects linked to West African cybercrime networks. The joint action successfully dismantled elements of the Black Axe syndicate, which orchestrates global romance, investment, and business email compromise (BEC) scams. Law enforcement agencies across South Africa, Argentina, and Romania also disrupted major Crime-as-a-Service (CaaS) providers, freezing millions of dollars in illicit financial assets.

The FBI, collaborating with the DoJ, have disrupted the global QScan and QTRouter hacking platforms operated by Chinese state-sponsored threat actors. The group QTFY, which maintains direct ties to China’s military and intelligence services, used these compromised IoT botnets to mask cyber espionage traffic targeting critical U.S. networks, including the Federal Reserve and NASA. Law enforcement successfully seized the core command-and-control (C2) domains hardcoded within the malicious frameworks.

From the U.S. Treasury is a new operation dubbed Economic Outcast, imposing sweeping sanctions on five Mabna Institute members and nearly 60 Iran-linked entities. Under the direction of Iran’s Ministry of Intelligence and Security (MOIS), the attackers breached multiple American critical infrastructure organizations, state governments, and defense contractors. These state-sponsored actors then exfiltrated datasets, executed high-value cryptocurrency heists, and now face federal indictments alongside a $10 million dollar reward for information leading to their arrest.

The Australian Federal Police (AFP) have arrested and charged two individuals for principal roles in TeamPCP, a cybercrime syndicate. The group systematically compromised trusted open-source projects, including Trivy, Checkmarx KICS, and LiteLLM, by stealing developer credentials and distributing backdoored software updates across major ecosystem release channels. This massive software supply chain campaign potentially compromised organizations worldwide and facilitated the unauthorized theft of hundreds of thousands of credentials.

The Bad | ‘NovaCookies’ Phishing Toolkit Exploits DocuSign Services to Steal Session Tokens

Security researchers have disclosed details of NovaCookies, a subscription-based phishing platform that systematically targets corporate networks to steal authenticated Microsoft 365 sessions. Operating as an Adversary-in-the-Middle (AitM) proxy, this malicious toolkit is advertised on Telegram for $320 monthly. The campaigns actively compromise hundreds of organizations across several nations, including the U.S., the U.K., Germany, and the U.A.E.

To establish a foothold, attackers distribute counterfeit document-sharing lures within genuine DocuSign notifications. Styled as a share notice, the decoy claims an accounting department shared a remittance-advice PDF and invites the recipient to open it. Since these notifications originate from legitimate servers, they bypass standard sender-authentication checks and reputation filters. The malicious link is embedded inside the shared document, below the inspection layer of most security gateways. Once clicked, the attack uses an OAuth error-redirect technique to guide the browser through legitimate Microsoft or Google endpoints before routing traffic to the phishing infrastructure. This transition ensures every intermediate step appears trustworthy until the user reaches the proxy.

Source: Island.io

NovaCookies is a variant of the Sneaky2FA platform, which operates on a centrally managed model where the operator hosts the infrastructure rather than individual affiliates. The kit offers customized flows targeting common identity providers. Affiliates register landing pages on .vu domains, utilizing deceptive, alternating-case subdomains like PwPt-sHaRe to masquerade as legitimate Microsoft portals. While these checks obscure the landing pages, the proxy relays credentials and multi-factor authentication (MFA) codes in real time to Microsoft. Because each individual hop of the attack chain appears legitimate, security analysts emphasize that the browser remains the critical intersection where these events converge.

The Ugly | Threat Actors Deploy Spark RAT to Target Cambodian Organizations

A recently uncovered campaign is targeting both individuals and organizations in Cambodia with Spark RAT, which functions as a Go-based, open-source remote access trojan. Distributing compressed archives through targeted phishing emails, the threat actors deploy diverse lures, including Cambodian government notices, public health announcements, and dental records. The multi-stage attack sequence begins when a victim executes an Inno Setup installer, which initiates a dynamic link library side-loading chain using a signed Tencent application to deliver intermediate payloads.

To guarantee execution, the DLL loader performs timing-based anti-sandbox checks to detect virtual environment delays and scans running processes in an attempt to weaken its permissions. The loader then decrypts shellcode hidden within an embedded PNG file to run a second stager that determines whether the malware operates with SYSTEM privileges. If these elevated rights are present, the malware proceeds directly to inject mode. Otherwise, it configures a Windows service for local persistence. Ultimately, the stager injects malicious shellcode into the legitimate vssvc.exe process, monitoring execution to re-inject the payload if terminated.

Source: Acronis

The intrusion chain utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique that abuses a legitimate but vulnerable OPSWAT AppRemover driver, ardrv.sys, to escalate privileges and neutralize security programs. Operating under CVE-2026-36425, this driver enables the malware to terminate active security processes, including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. The program also patches Antimalware Scan Interface and Event Tracing for Windows, executes user-mode termination of security tools, and injects Spark RAT into ctfmon.exe. Although operational tactics and driver usage closely mirror the Chinese-speaking Silver Fox syndicate, analysts classify the campaign as an unattributed cluster due to the absence of shared infrastructure, certificates, or code reuse.


文章来源: https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-35-8/
如有侵权请联系:admin#unsafe.sh