• Koi researchers have uncovered a seven-year browser extension operation that has silently compromised at least 4.3 million Chrome and Edge users worldwide. The threat actor, dubbed ShadyPanda, systematically abused browser marketplaces to turn seemingly legitimate extensions into long‑term surveillance and remote access platforms. Koi’s investigation identified two ongoing campaigns linked to the same actor. A 300,000‑user remote […]

    The post 4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • South Korean e-commerce giant Coupang has admitted to a significant data breach that exposed the personal information of about 33.7 million customers. This figure is close to the company’s entire user base, making it one of the most significant known data breaches in the country. According to Coupang, the stolen data includes names, phone numbers, […]

    The post Coupang Data Breach Exposes Personal Information of 33.7 Million Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a significant decision that will affect millions of mobile phone users, the Indian government has ordered all smartphone companies to install a specific security app on every new device sold in the country. The Department of Telecommunications (DoT) issued this order on November 28, 2025. The government has told phone makers that they have […]

    The post Mandatory ‘Undeletable’ Security App to Be Installed on Every Smartphone in India appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Senate and House Armed Services committees will open bipartisan inquiries into U.S. military strikes on suspected drug-running boats in the Caribbean Sea, with a focus on an alleged follow-on attack that The Washington Post reported killed two survivors of the initial operation.

    Senate Armed Services Committee Chair Roger Wicker, R-Miss., and ranking member Jack Reed, D-R.I., issued a joint statement Friday promising “vigorous oversight” of the killings.

    “The Committee is aware of recent news reports — and the Department of Defense’s initial response — regarding alleged follow-on strikes on suspected narcotics vessels in the SOUTHCOM (Southern Command) area of responsibility. The Committee has directed inquiries to the Department, and we will be conducting vigorous oversight to determine the facts related to these circumstances,” Wicker and Reed said.

    Similarly, House Armed Services Committee Chair Mike Rogers, R-Ala., and ranking member Adam Smith, D-Wash., said in a joint statement Saturday that the panel “is committed to providing rigorous oversight of the Department of Defense’s military operations in the Caribbean.”

    “We take seriously the reports of follow-on strikes on boats alleged to be ferrying narcotics in the SOUTHCOM region and are taking bipartisan action to gather a full accounting of the operation in question,” according to the statement.

    The inquiries mark a rare bipartisan check on President Donald Trump’s administration since his second term began in January. With the exception of voting to release the federal case files on convicted sex offender Jeffrey Epstein, which Trump eventually endorsed, Republicans have largely left Trump’s decisions and policies unchallenged.

    Follow-on attack reported

    Lawmakers’ attention was retrained on the already legally questionable U.S. operations targeting alleged narcotics boats after an investigative report published Friday by The Washington Post revealed Secretary of Defense Pete Hegseth gave verbal orders to kill everyone during a Sept. 2 operation —  the first of several U.S. boat strikes in the Caribbean Sea that have killed roughly 80.

    According to the report, two survivors clung to burning wreckage after an initial hit. Adm. Frank M. “Mitch” Bradley, who was commanding the attack from Fort Bragg in North Carolina, ordered a second, or follow-on, strike to fulfill Hegseth’s order and kill the remaining survivors. States Newsroom has not independently confirmed the details.

    Hegseth called the report “fabricated, inflammatory, and derogatory,” in a post on social media Friday.

    Sen. Tim Kaine, D-Va., told CBS News’ “Face the Nation with Margaret Brennan” on Sunday that the follow-on strike could rise “to the level of a war crime if it’s true.”

    "If that reporting is true, it's a clear violation of the DoD's own laws of war, as well as international laws about the way you treat people who are in that circumstance," Kaine said.

    A working group of former military lawyers issued a statement Friday urging Congress to investigate the Sept. 2 strike.

    “Since orders to kill survivors of an attack at sea are ‘patently illegal,’ anyone who issues or follows such orders can and should be prosecuted for war crimes, murder, or both,” according to the statement published by Just Security, a journal focused on national security published by the New York University School of Law Reiss Center on Law and Security.

    A bipartisan effort, led by Kaine, to stop Trump’s deadly strikes in the Caribbean narrowly failed in the Senate in early November.

    White House confirms second strike

    White House press secretary Karoline Leavitt was met with numerous questions about the Post report at Monday’s press briefing.

    A reporter asked Leavitt, “Does the administration deny that that second strike happened, or did it happen and the administration denies that Secretary Hegseth gave the order?”

    “The latter is true, and I have a statement to read for you here,” Leavitt said, adding that Trump and Hegseth have authority to conduct lethal attacks on designated narco-terrorist groups.

    “With respect to the strikes in question on Sept. 2, Secretary Hegseth authorized Admiral Bradley to conduct these kinetic strikes,” she said. “Admiral Bradley worked well within his authority and the law directing the engagement to ensure the boat was destroyed and the threat to the United States of America was eliminated.”

    Leavitt’s statement was not entirely consistent with Hegseth’s denial on Friday, in which he called the reporting “fabricated.”

    Trump echoes Hegseth denial

    Trump told reporters aboard Air Force One on Sunday he “wouldn’t have wanted that” when asked about the alleged follow-on strike that killed the two survivors.

    “The first strike was very lethal. It was fine, and if there were two people around — but Pete [Hegseth] said that didn't happen,” Trump told reporters. 

    “Pete said he did not order the death of those two men,” Trump continued in a back-and-forth with the press.

    Trump also said Saturday he was closing the airspace above Venezuela, but tolda reporter who asked Sunday if the move previewed a U.S. airstrike of the country not to “read anything into it.”

    “To all Airlines, Pilots, Drug Dealers, and Human Traffickers, please consider THE AIRSPACE ABOVE AND SURROUNDING VENEZUELA TO BE CLOSED IN ITS ENTIRETY,” he wrote on his own social media platform just before 8 a.m. Eastern Saturday.

    Trump confirmed reports he spoke to Venezuelan President Nicolás Maduro late last month but would not reveal details of the conversation.

    The U.S. has been amassing Navy vessels and troops off the coast of Venezuela for months, including the recent addition in mid-November of the Navy’s most advanced aircraft carrier, the USS Gerald Ford.

    This story was originally published by Stateline.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • At the lowest point of the Civil War, Abraham Lincoln characterized the core factor between victory and defeat as finding a general who understood the “awful arithmetic” of war. War is a contest of blood and treasure; each can, and must, ultimately be counted and measured. It has been the same for every conflict before and after. 

    Yet this arithmetic is constantly changing, and never faster than right now. If the United States cannot update its calculations to properly reflect our new era, our failure will not just cost us blood and treasure, but will drive us toward defeat.

    Cost imposition has long been a tenet of U.S. strategy. During the Cold War, the U.S. launched expensive programs such as stealth and Star Wars not just for their tactical value, but to send a strategic signal to the Kremlin: neither your economy nor your war machine can keep up. Gorbachev, persuaded, gave up the decades-long competition with the U.S. 

    The very same concept of cost imposition was also elemental to the most celebrated operations of the past year. In Operation Spider’s Web, Ukraine used inexpensive drones, reportedly costing less than $500 each, to damage strategic bombers worth many millions of dollars, degrading Russia’s long-range strike capabilities for years to come. Similarly, in Operation Rising Lion, cheap Israeli drones took out Iranian surface-to-air missiles and radars, paving the way for the destruction of command and nuclear facilities worth tens of billions of dollars. In each, the tactical became the strategic through new operational concepts that leveraged the new math of new technologies. 

    Now contrast this with our own approaches, which overwhelmingly rely on sophisticated but costly overmatch.

    The most lauded U.S. operation of 2025 was Operation Midnight Hammer, our followup to Rising Lion. One estimate put its cost at $196 million, from combining B-2 bomber’s nearly $160,000 per flight hour and Tomahawk missiles' rough price of $1.87 million apiece. (It does not count the initial purchase of the seven B-2 Bombers that cost $2.1 billion each, nor the $4.3 billion submarine that launched the missiles.) 

    Perhaps it was worth spending one-fifth of a billion dollars to damage Iranian nuclear facilities, but the numbers in Operation Rough Rider—the strikes against the Houthis last spring—illustrate the problem more starkly. The Pentagon spent roughly $5 billion on munitions and operating costs to stop attacks on Red Sea shipping, which simply started back up this month.

    The same awful arithmetic haunts the current operations in the Caribbean against the Venezuela-based, government-connected Cartel de los Soles. The entity was recently designated by the Trump administration as a foreign terrorist organization, as part of its argument that US forces are engaged in an “armed conflict.” The cartel was declared by the Department of Justice to be the hub of a cocaine transport network, shipping a reported street value of between $6.25 billion and $8.75 billion in drugs (the cartel gets an unknown, but clearly lesser, percentage of that overall value in actual profit). 

    To battle this foe, the United States has assembled a fleet that cost at least $40 billion to buy in total. The carrier Ford alone cost $4.7 billion to develop and $12.9 billion to build. The fleet is backed by at least 83 aircraft of assorted types, including 10 F-35Bs ($109 million apiece), seven Predator drones ($33 million each), three P-8 Poseidons ($145 million per), and at least one AC-130J gunship ($165 million). To be sure, all of these assets will continue to serve long after Operation Southern Spear is wound down, but this is how we are using the investment. 

    But the current cost of operations and expendables hardly tells a better story. The Ford alone costs about $8 million a day to run. The F-35s and AC-130J cost about $40,000 per flight hour; the P-8s, about $30,000; the Reapers, about $3,500.

    Analysis of the strike videos on the 21 boats show that U.S. forces have fired AGM-176 Griffins ($127,333 apiece in 2019), Hellfires (running about $150,000 to $220,000) and potentially GBU-39B Small Diameter Bombs ($40,000). In some cases, they are reportedly firing four munitions per strike: “twice to kill the crew and twice more to sink it.”

    All this is arrayed to sink motorboats, 21 at last report. One of the boats was described by Pentagon officials as a 39-foot Flipper-type vessel with four 200-horsepower engines. New ones go for about $400,000 on Boats.com, but the old, open top motorbots in the videos are obviously well below that in cost. Their crews have been reported as making $500 per trip.

    Put in comparison, the cost of the US naval fleet deployed is at least five times what the cartel makes in smuggling. The air fleet deployed costs at least another two times more.  It is roughly 5,000 times the cost of the suspected drug boats that have been destroyed. Indeed, just the cost of operating the Ford off Venezuela for a single day has still not yet equaled the maximum cost the cartel paid for the boats it has lost.

    In the air, the U.S. military spent roughly 66,000 times more to buy each unmanned drone in the operation than the cartel paid each man that the unmanned drones killed. The US spent between 80 to 300 times more for each bomb or missile it has used than the cartel paid each man killed by those bombs or missiles. 

    The math is arguably even worse when we're on the defense. 

    In September, a wave of 19 Russian drones crossed into Polish airspace.. The Gerbera-type drones cost as little as $10,000—so cheap that they are often used as decoys to misdirect and overwhelm Ukrainian air defenses. NATO countered with a half-billion-dollar response force of F-35s, F-16s, AWACS radar planes, and helicopters, which shot down four of the drones with $1.6-million AMRAAM missiles. 

    This is a bargain compared to how challenging U.S. forces have found it to defend against Houthi forces using this same cheap tech. Our naval forces have fired a reported 120 SM-2, 80 SM-6, and 20 SM-3 missiles, costing about $2.1 million, $3.9 million, and over $9.6 million each. And this is to defend against a group operating out of the 187th-largest economy in the world, able to fire mere hundreds of drones and missiles. Our supposed pacing challenge, China, has an economy that will soon be the largest in the world and a combined national industrial and military acquisition plan to be able to fire munitions by the millions. 

    Even in America’s best-laid plans for future battlefields, there is a harsh reality that is too often ignored. The math of current battlefields remains literally orders of magnitude beyond what our budget plans to spend, our industry plans to build, our acquisitions system is able to contract, and thus what our military will deploy. 

    As a point of comparison, Ukraine is on pace to build, buy, and use over four million drones this year. The U.S. Army, meanwhile, aims to acquire 50,000 drones next year—about 1.25 percent of the Ukrainian total. In its most optimistic plans, it hopes to be able to acquire 1 million drones “within the next two to three years.” ​​ 

    When you spend orders of magnitude more than your foe, you are in what is known as a “losing equation.” And if we don’t change this math, we will need an update to Norm Augustine’s infamous “law” of defense acquisitions. Back in 1979, Augustine calculated that if the Pentagon couldn’t curtail the cost curve of its purchasing, by 2054 we wouldn’t be able to afford a single plane. 

    The 2025 version is that if we don't master the new math of the battlefield, we won’t be able to afford to win a single battle.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • India’s Department of Telecommunications (DoT) has ordered smartphone manufacturers to preload a government-backed cybersecurity app, “Sanchar Saathi,” on all new devices sold in the country.

    The order, issued privately on November 28, 2025, gives major players like Apple, Samsung, Xiaomi, Vivo, and Oppo 90 days to comply, requiring the “Sanchar Saathi” app to be installed as a non-removable feature on every handset.​

    The move signals a significant tightening of state control over consumer electronics in the world’s second-largest telecom market, which boasts over 1.2 billion subscribers.

    Government officials argue the measure is a critical defense against a surge in digital fraud and cybercrime. According to the directive, the app serves as a “citizen-centric” shield, enabling authorities to curb the use of stolen phones and combat spoofed IMEI numbers, which are often used in criminal activities.​

    Sanchar Saathi: A Digital “Communication Companion”

    Launched earlier this year, the Sanchar Saathi (Hindi for “Communication Companion”) platform was initially a web portal designed to empower mobile subscribers. The mandatory app version integrates several key safety features directly into the user interface:​

    • Chakshu: A reporting tool for suspected fraud communications, including malicious calls, SMS, or WhatsApp messages.​
    • Lost/Stolen Mobile Blocking: Uses the Central Equipment Identity Register (CEIR) to block stolen devices across all networks, rendering them useless to thieves.​
    • Connection Management: Allows users to check “Know Mobile Connections in Your Name” to identify unauthorized SIM cards registered against their identity.​
    • Genuineness Checks: Verifies if a device’s hardware and IMEI are authentic.​

    While the government highlights recovered devices over 700,000 lost phones have reportedly been traced using the system, the mandatory nature of the app has sparked immediate concern.​

    Industry Pushback and Privacy Fears

    The directive requires that the app be “undeletable,” a condition that is likely to upset privacy advocates and manufacturers like Apple, which has historically resisted preloading third-party software.

    Industry executives, speaking on condition of anonymity, expressed frustration over the lack of prior consultation, fearing the “forced” app could compromise user trust and device performance.​

    Privacy advocates are concerned that a government-controlled app with extensive system access could theoretically be used for surveillance. However, the Indian government has consistently denied such intentions, stating that the directive is solely a consumer protection measure.

    Manufacturers must also push the app to existing devices via software updates, ensuring the entire active user base is eventually covered.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A malicious Visual Studio Code extension posing as the popular “Material Icon Theme” has been used to attack Windows and macOS users, turning the add-on into a hidden backdoor.

    The fake extension shipped through the marketplace with backdoored files, giving the attackers a direct path into developer workstations once it was installed.

    After installation, the extension behaved like a normal icon theme, so most users had no reason to suspect anything was wrong.

    Behind the scenes, the package contained two Rust-based implants that were ready to run native code on both operating systems and reach out to a remote command server.

    Nextron Systems security researchers identified the implants in version 5.29.1 and traced their execution back to a loader script named extension.js placed in dist/extension/desktop next to the native payloads os.node on Windows and darwin.node on macOS.

    This shows how the malicious files mirror the folder tree of the real extension to blend in.

    darwin.node dylib (Source - Nextron Systems)
    darwin.node dylib (Source – Nextron Systems)

    Once the extension is activated in VS Code, extension.js loads the correct Rust implant for the current platform and hands control over to the attacker code.

    From that moment, the extension stops being a harmless add-on and becomes a loader for further stages that are fully controlled from outside the victim machine.

    Infection mechanism and command chain

    This section provides a complete technical breakdown of how the implants talk to their command server and fetch follow-up payloads.

    The Rust binaries do not use a fixed URL. Instead, they pull their instructions from data stored in a Solana blockchain wallet address, which acts as a hard-to-block control channel.

    A simplified view of the loader logic in extension.js is shown below:-

    function activate() {
      const bin = process.platform === "win32" ? "os.node" : "darwin.node";
      const native = require(__dirname + "/desktop/" + bin);
      native.run();
    }

    The native code reads the wallet data, base64-decodes it, and then contacts a command server to download a large base64 blob, which is an AES-256-CBC-encrypted JavaScript file.

    A fallback, from a Google Calendar event (Source - Nextron Systems)
    A fallback, from a Google Calendar event (Source – Nextron Systems)

    As a backup, the same next stage can also be fetched from a hidden Google Calendar event that stores the payload URL with invisible Unicode tricks. This illustrates the C2 chain from the blockchain wallet to the decrypted script.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Malicious VS Code Extension as Icon Theme Attacking Windows and macOS Users appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Advanced steganography techniques are becoming increasingly central to state-sponsored cyber operations.

    Recent analysis has exposed two Chinese technology companies, BIETA and CIII, that allegedly provide sophisticated steganography solutions to support advanced persistent threat campaigns.

    These organizations operate as front companies linked to China’s Ministry of State Security, playing a critical role in modernizing the country’s intelligence gathering capabilities.

    BIETA, formally known as the Beijing Institute of Electronics Technology and Application, operates from a location adjacent to the MSS headquarters in Beijing.

    The company maintains close institutional ties with government agencies and universities, including the University of International Relations, which functions as an MSS subsidiary.

    CIII, operating as Beijing Sanxin Times Technology Co., Ltd., presents itself as a state-owned enterprise while reportedly providing forensic and counterintelligence support services.

    Both organizations maintain detailed focus on developing advanced hiding techniques for malicious payloads.

    Security analysts at Telsy identified that these companies have dedicated substantial resources to steganographic research and development.

    Analysis of academic publications reveals that approximately 46 percent of BIETA’s 87 research papers published between 1991 and 2023 specifically address steganography.

    The companies have obtained multiple software copyrights for techniques including audiovisual-to-voice conversion systems and JPEG image forensic differentiation methods, both registered in 2017.

    Steganography implementation strategies

    The steganography implementation strategies employed represent a significant technical shift in APT operations.

    Rather than relying solely on traditional encryption, threat actors use Least Significant Bit steganography to conceal .NET payloads within image files.

    BIETA’s research extends beyond standard JPEG formats to include MP3 audio and MP4 video files for covert information transmission.

    Historical APT groups including APT1, Mirage, Leviathan, and Pirate Panda have all utilized similar techniques to distribute backdoors like TClinet and Stegmap without triggering conventional detection systems.

    The technical innovation extends to emerging technologies, with BIETA researchers exploring Generative Adversarial Networks for steganographic applications.

    This advancement suggests future APT operations may employ AI-driven methods to generate undetectable carrier files.

    Understanding these techniques remains essential for defensive security teams as state-sponsored actors continue refining their ability to hide malicious communications within seemingly innocuous media files, making detection increasingly challenging for traditional security monitoring tools and approaches.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Chinese Front Companies Providing Advanced Steganography Solutions for APT Operations appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new remote access trojan dubbed KimJongRAT has surfaced, posing a severe threat to Windows users.

    This sophisticated malware is believed to be orchestrated by the Kimsuky group, a threat actor with alleged state backing.

    The campaign typically begins with a phishing email containing a deceptive archive named National Tax Notice, which lures unsuspecting victims into initiating the infection chain.

    Upon opening the malicious archive, users are presented with a shortcut file disguised as a legitimate PDF document.

    Tax notice.pdf (Source - Alyac)
    Tax notice.pdf (Source – Alyac)

    When executed, this shortcut file triggers a hidden command that decodes a Base64 URL and abuses the legitimate Microsoft HTML Application utility to contact a remote server.

    This process stealthily downloads an additional payload known as tax.hta, effectively bypassing standard security checks.

    Alyac security analysts identified that this loader script is implemented in VBScript and employs clever evasion techniques.

    The malware attempts to evade detection by utilizing legitimate services like Google Drive to host its malicious components.

    Once active, the loader retrieves both decoy documents to trick the user and the actual malicious binaries required for the next stage of the attack.

    Exfiltration of sensitive data

    The primary objective of this campaign is the exfiltration of sensitive personal and financial data.

    The malware targets a wide array of information, including system details, browser storage data, and encryption keys.

    It specifically hunts for cryptocurrency wallet information and credentials for communication platforms like Telegram and Discord, making it a highly dangerous tool for identity theft and financial fraud.

    The most notable aspect of KimJongRAT is its ability to adapt its behavior based on the target environment’s security posture.

    The malware executes a specific VBScript command to check the status of Windows Defender before proceeding.

    It uses the code snippet Set exec = oShell.Exec(ss) followed by If InStr(output, “STOPPED”) > 0 Then to determine if the security service is active.

    If Windows Defender is disabled, the malware downloads a file named v3.log, which executes the primary payload.

    Conversely, if security is active, it retrieves an alternative file called pipe.log to circumvent detection.

    Regardless of the path taken, the malware establishes persistence by registering itself in the system registry, ensuring it runs automatically to transmit stolen data periodically.

    List of cryptocurrency wallets hijacked by malware (Source - Alyac)
    List of cryptocurrency wallets hijacked by malware (Source – Alyac)

    While the List of cryptocurrency wallets hijacked by malware highlights the breadth of targeted applications, it also highlights the specific financial intent behind this tailored threat.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post KimJongRAT Attacking Windows Users via Weaponized .hta Files to Steal Logins appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated cyberespionage campaign dubbed “Operation Hanoi Thief” has surfaced, specifically targeting IT professionals and recruitment teams in Vietnam.

    Discovered on November 3, 2025, this threat activity employs a complex multi-stage infection chain designed to harvest sensitive browser credentials and history.

    The attackers leverage a malicious spear-phishing strategy, distributing a ZIP archive named Le-Xuan-Son_CV.zip, which masquerades as a legitimate job application from a software developer based in Hanoi.

    The infection initiates when a victim interacts with a shortcut file, CV.pdf.lnk, contained within the archive. This file triggers a sequence of events utilizing “Living off the Land” (LOLBin) tactics.

    Specifically, it abuses the Windows ftp.exe utility with the -s flag to execute a batch script hidden within a pseudo-polyglot file named offsec-certified-professional.png.

    This file dual-functions as a harmless image lure and a malicious container, effectively evading traditional detection mechanisms by burying its payload within legitimate image headers.

    Data Exfiltration (Source - Seqrite)
    Data Exfiltration (Source – Seqrite)

    This command line argument is a critical indicator of the attack’s stealthy nature.

    Seqrite security analysts identified that this campaign is likely of Chinese origin, citing overlaps in tactics with previous state-sponsored activities.

    The primary objective appears to be intelligence gathering, focusing on the theft of login data and browsing habits from victims in the technology and HR sectors.

    By exploiting the trust inherent in recruitment processes, the threat actors successfully bypass initial perimeter security layers.

    Technical Analysis of the LOTUSHARVEST Payload

    The core of this attack is the execution of the LOTUSHARVEST implant. Once the initial script runs, it abuses DeviceCredentialDeployment.exe to conceal its command-line activities and renames system utilities like certutil.exe to lala.exe to bypass monitoring.

    In the infection chain, the script then extracts a base64-encoded blob from the polyglot file, decoding it into a malicious DLL named MsCtfMonitor.dll.

    Infection Chain (Source - Seqrite)
    Infection Chain (Source – Seqrite)

    This DLL is side-loaded using a legitimate ctfmon.exe binary copied to the C:\ProgramData directory.

    LOTUSHARVEST functions as a robust information stealer, employing anti-analysis checks like IsDebuggerPresent and IsProcessorFeaturePresent to crash if analyzed.

    It targets Google Chrome and Microsoft Edge, querying SQLite databases to extract the top 20 visited URLs and decrypting up to five saved credentials using CryptUnprotectData.

    Finally, the stolen data is formatted into JSON and exfiltrated via an HTTPS POST request to the attacker-controlled server eol4hkm8mfoeevs.m.pipedream.net/service.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Operation Hanoi Thief Attacking IT Professionals with Pseudo-Polyglot Payload to Hide Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶