Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset Pierluigi Paganini
    iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is not the phishing itself. It’s what happens after the phishing succeeds. “Once the target completes a p
     

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

24 de Agosto de 2026, 04:17

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets.

Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is not the phishing itself. It’s what happens after the phishing succeeds.

“Once the target completes a phishable Google login, the toolkit uses the authenticated session to enroll a passkey controlled by the operator.” reads the report published by Abnormal Security. “In the seller’s recorded demonstration, the account owner later changes their password, invalidating the active session—but the operator authenticates with the newly enrolled passkey and returns to the mailbox.”

That’s the architecture. The phishing flow gives the attacker a temporary window. iAuthFlow v2 uses that window to create a permanent key that doesn’t close when the window does.

The toolkit uses a browser-in-the-middle attack. The victim sees what looks like a real Google login page, while iAuthFlow v2 runs another browser on the attacker’s server. Everything the victim types, including their email, password and two-factor code, is sent to that remote browser, which logs in to Google. The victim provides the credentials, while the attacker gets the authenticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a more trustworthy appearance.

Once the relay gives the attacker’s browser Google’s session cookies, iAuthFlow v2 holds the target on a “Verification, Processing” page while the toolkit works inside the account.

This pause is a named state in the software, not a recording artifact. The session log timestamps tell the story precisely: login at 21:37:18, passkey created and saved at 21:37:24. Six seconds to establish persistent access.

The passkey module navigates the target’s Google passkey settings through the authenticated browser and requests a new credential. Google may ask for identity re-verification before allowing the enrollment; the demo shows the toolkit handling this. The enrolled passkey is then stored on the attacker’s side, and the toolkit records “Passkey created and saved.”

“The log records “Passkey created and saved.” At this point, the operator no longer has only the authenticated session created through the phishing flow.” continues the report. “The newly enrolled passkey is a separate authentication credential registered to the target’s Google account. The subsequent demonstration shows Google offering that passkey during a later sign-in, consistent with the operator retaining the credential needed to use it.”

This is more serious than simply stealing a session cookie because a password reset does not remove a passkey. Changing a Google password ends active sessions, revokes app passwords and invalidates some OAuth tokens. A passkey is different: it is a separate cryptographic credential linked to the account and remains active until it is manually removed.

The demo shows the risk clearly. After the victim changes their password, the attacker’s session stops working. But the attacker can choose “Try another way,” use the passkey they previously added and regain access to the mailbox. The victim may have no idea this happened.

Abnormal notes a technically plausible mechanism for how iAuthFlow v2 stores and uses the passkey: Chromium’s software-based virtual authenticators, which support WebAuthn registration and retain private keys without requiring the target’s physical device. The researchers don’t confirm this is what the toolkit uses, since the demonstration doesn’t reveal the implementation. What they confirm is that the behavior shown is consistent with how passkeys work, and there’s an available path to produce it.

The toolkit targets Google in the build Abnormal examined, but the seller advertises versions for Microsoft, iCloud, and LinkedIn. The same post-authentication persistence logic applies wherever passkeys can be enrolled.

Containment after an iAuthFlow v2 compromise needs to go further than incident response teams are often used to going.

“That cleanup is particularly important with iAuthFlow v2 because neither a password reset nor session revocation removes an attacker-enrolled passkey.” states the report. “Restore the account only after unauthorized authentication methods and other persistence mechanisms have been removed.”

The full sweep should cover unauthorized passkeys and security keys, malicious Gmail filters and forwarding rules, delegated access, OAuth grants and app permissions, and recovery settings. Organizations running Google Workspace can use the Security Investigation Tool to audit the account before declaring it clean.

The best way to prevent these attacks is to rely on authentication methods that cannot be easily stolen through phishing. WebAuthn-based authentication is tied to the real website, so stolen passwords or codes cannot be used through a relay attack. Google Workspace can enforce this with the “Only security key” option for 2-Step Verification and through the Advanced Protection Program. These settings also disable app passwords, which the toolkit may target on less protected accounts.

The toolkit’s price and professional sales channels suggest this is an ongoing business, not a one-time release. If a Google account is compromised but appears clean after a password reset, security teams should also check the account’s passkeys and security keys before closing the case.

“iAuthFlow v2 illustrates how phishing has evolved beyond stealing credentials or even hijacking a single authenticated session. Once an attacker gains legitimate access to an account, that access can become a starting point for establishing new authentication methods, modifying account settings, and creating other forms of persistence.” concludes the report. “Response and recovery cannot end with a password reset or session revocation. Organizations must also examine what changed after authentication—especially newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings—and remove anything the attacker left behind. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, iAuthFlow v2 phishing toolkit)

U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

9 de Agosto de 2026, 13:44

IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data.

IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used in systems including rotary-wing aircraft, THAAD and Patriot missile systems, fighter aircraft, airborne radar systems, satellites and spacecraft, military radios, and torpedoes.

IEH Corporation disclosed a cyberattack in an 8-K filing with the SEC. The company discovered the breach on August 4. An employee clicked a link disguised as a Microsoft document-sharing link from what appeared to be a prospective business contact, entered their Microsoft 365 credentials into a fake login page, and handed an attacker full access to their inbox.

“On August 4, 2026, IEH Corporation (“IEH” or the “Company”) discovered that it sustained a cybersecurity incident whereby a threat actor using an alias gained unauthorized access to the Microsoft 365 mailbox of an employee of the Company. As soon as the incident was observed, the Company took action to contain the unauthorized access.” reads the 8-K report filed with SEC. “An investigation determined the compromise originated from a phishing attack in which a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link. The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access.”

The attacker accessed company’s mailbox, exposing emails, attachments, customer data, engineering documents and potentially export-controlled information. No data exfiltration was confirmed. The U.S. Defense Manufacturer secured the account and removed malicious mailbox rules.

The phrase “export-controlled technical information” is the part worth paying attention to. IEH’s products fall under ITAR and EAR regulations, exporting that kind of data to an unauthorized foreign party isn’t just a breach, it’s a potential federal violation.

The attack didn’t require any technical sophistication. Someone posing as a business contact sent a convincing link, and one click was enough. The fact that malicious mailbox rules had been created, and had to be disabled, suggests the attacker was in the account long enough to set up persistence, likely to maintain access or intercept future emails silently.

IEH reported nearly $30 million in revenue for fiscal year 2026, a small company by most standards, but one sitting inside defense supply chains that attackers have strong reasons to target. The company says it currently has no evidence the incident will materially affect business operations and is continuing its investigation.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Defense Manufacturer)

  • ✇Security Affairs
  • South Korea Warns of State-Backed Watering Hole Attacks Pierluigi Paganini
    South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and wateri
     

South Korea Warns of State-Backed Watering Hole Attacks

31 de Julho de 2026, 18:25

South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses.

South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean citizens and businesses. The warning names two attack techniques: phishing emails and watering hole attacks, and it doesn’t sugarcoat how little a victim has to do wrong.

The phishing side runs on two tricks. In one version, attackers disguise themselves as job applicants and send a resume email with a link instead of an attachment, pointing to a blog or GitHub page the attacker controls. In the other, they impersonate an actual recruiter, sometimes hijacking a real headhunter’s email account, and attach a password-protected ZIP file labeled as a job offer that infects the machine the moment it’s opened.

The watering hole method is the part that should worry ordinary readers more. Attackers compromise legitimate sites people already trust, news portals and hospital websites among them, along with smaller sites that simply have weak security, and use them as launch points. As the advisory puts it, the danger is that “visiting the site alone can be enough to trigger an infection.”

That’s possible because the malicious code doesn’t rely on tricking the user into clicking “install.” It pairs the compromised website with an old, unpatched vulnerability sitting in security software already installed on the visitor’s PC, the kind of software Korean banking and government sites require. No prompt appears, no warning shows up, the page looks completely normal, and the infection happens silently in the background.

This lines up closely with what AhnLab documented separately in its own technical report, Operation Double Barrel, which the advisory cites directly as a reference. AhnLab traced the same watering hole technique across 15 compromised Korean websites between 2025 and mid-2026, hitting media outlets, hospitals, and manufacturers, and found the attackers exploiting flaws in two specific pieces of Korean financial security software to inject backdoors into legitimate Microsoft processes. In one especially odd case, the malicious code only activated when visitors used Naver’s Whale browser, a level of targeting precision that suggests real reconnaissance rather than a scattergun approach.

Once infected, the advisory lists what’s actually at stake, and it’s not a short list. Saved browser passwords and manually typed credentials get siphoned off, documents and photos get pulled from the machine, and infected computers become a stepping stone to infect every other device on the same office or home network. For businesses specifically, the advisory adds that stolen source code and customer data become leverage: “pay up, or we publish and distribute the data.”

None of the fixes here are exotic. The advisory tells individuals to update every piece of security software, especially old electronic-signature and authentication tools that rarely get touched after installation, turn on two-factor authentication, stop saving passwords in the browser, and never open an attachment or link from an unfamiliar sender without verifying it through an official channel first. Organizations get a longer list: network segmentation for critical servers, mandatory multi-factor authentication instead of shared default passwords, regular phishing-awareness training, and immediate reporting to the relevant agency the moment something looks off.

It’s a strange kind of milestone when a national intelligence service has to remind an entire country that clicking a news headline isn’t automatically safe anymore. But that’s effectively where things stand: the browser tab you already trust might be doing more than loading a page.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, South Korea)

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

24 de Julho de 2026, 06:54

UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis.

CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing emails to deliver malware families including LONEPAGE, MATCHBOIL, and DRAGSTARE.

UAC-0099

The latest campaign, observed earlier this summer, uses a trojanized Notepad++ plugin as the infection mechanism. It’s a meaningful change in delivery method for a group that’s been refining its toolset steadily for three years.

The attack starts with a phishing email carrying an image attachment. Clicking it opens a URL hidden behind a link shortener, which redirects to a file-sharing service such as EasySend[.]co where a ZIP archive waits. Inside the ZIP is a VBScript file disguised as a PDF document.

Running the VBScript triggers two things simultaneously. A legitimate decoy PDF downloads and opens in front of the victim to hold their attention, while in the background the script fetches a second archive called Evernote.zip. That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.

“The mentioned archive contains a VBS script with a double extension, the name of which may intentionally contain a significant number of spaces before the final .vbs extension , for example “Zavodskyi rayon.pdf .vbs”. In turn, when launched, the script will download a decoy file (for example “Zavodskyi rayon.pdf”) and the “Evernote.zip” archive.” reads the advisory. “The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”

The VBScript extracts everything and launches Notepad++, which loads NppExport.dll as it starts up. The victim sees a text editor open normally and has no reason to suspect anything happened.

The malicious DLL, codenamed LUNCHPOKE by CERT-UA, uses the bundled WinRAR binary to unpack the password-protected archive. That archive contains two files: RemoteLibUpdater.exe and InitTest.dll. LUNCHPOKE copies them to a specific directory and creates a scheduled task that runs RemoteLibUpdater.exe every three minutes. The three-minute interval is aggressive and keeps the implant active even after unexpected process termination.

“The file “NppExport.dll” is classified as a LUNCHPOKE utility , the main purpose of which is to create the directory ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\ “, extract the contents of the archive “updater.rar” to it using a password (in particular, the files “RemoteLibUpdater.exe” and “InitTest.dll”), copy the standard utility “schtasks.exe” to the file ” %PUBLIC%\Wallpapers\Background.exe ” and create a scheduled task with the name ” \W1n3r-U09oTy-Ap5\Updates ” to run the file ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\RemoteLibUpdater.exe ” with the arguments “setup nodisplay” every three minutes (the name of the directory ” fFthY3-Ytrevc3w-ab3 ” changes).” states CERT-UA.

RemoteLibUpdater.exe is BURNYBEAR, a loader whose job is to execute InitTest.dll. That DLL is a modified version of MATCHBOIL, a C#-based loader capable of fetching and running additional payloads, now designated MATCHBOIL.V2. The update indicates active development on the toolchain rather than a static deployment.

BURNYBEAR includes an unusual built-in sabotage behavior.

“The executable file “RemoteLibUpdater.exe” is classified as a BURNYBEAR utility , the functionality of which is designed to load the DLL file “InitTest.dll”. However, if “RemoteLibUpdater.exe” is launched incorrectly, namely without specifying arguments, BURNYBEAR instead activates logic designed to exhaust computer resources (RAM and CPU).” states the report.

That behavior serves a dual purpose: it makes behavioral analysis harder by producing unexpected output if someone runs the binary without the correct arguments, and it provides a rough sandbox detection mechanism since automated analysis environments often execute binaries without arguments.

This campaign arrives alongside a separate U.S. government advisory documenting Laundry Bear, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025. That campaign uses a “half-click” exploit abusing CVE-2025-66376 to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client. The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:

CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.

The campaign’s use of a bundled legitimate WinRAR executable rather than relying on one already installed is notable: it means the attack chain doesn’t depend on the victim having a vulnerable version present, which makes the update recommendation more relevant as a general hygiene measure than as a specific remediation for this particular campaign. Organizations receiving unexpected emails with image attachments that open URLs through link shorteners should treat those as high-risk regardless of what the displayed content looks like.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Notepad++)

  • ✇Security Affairs
  • Government and Healthcare Are the Weakest Links in Global Email Security Pierluigi Paganini
    Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results aren’t flattering. More than 8 percent of organizations had zero protection in place, and only 0.6 percent — 33 domains out of 5,849 — score
     

Government and Healthcare Are the Weakest Links in Global Email Security

3 de Julho de 2026, 05:01

Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks.

Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results aren’t flattering. More than 8 percent of organizations had zero protection in place, and only 0.6 percent — 33 domains out of 5,849 — scored full marks. That’s 33 organizations out of nearly 6,000 doing everything right.

Government came last, with an average score of 2.73 out of 8.

“121 out of the 452 domains we scanned had zero protections in place (27%)–the highest of all sectors.” reads the report published by Comparitech. “No government domains scored full marks, but three did score 7.5 – Australia’s national science agency (CSIRO), the Mila – Quebec Artificial Intelligence Institute in Canada, and The Alan Turing Institute in the UK (also dedicated to data science and artificial intelligence).”

China’s government domains averaged just 0.9, with 65 percent having no protection at all. France wasn’t far behind at 1.4 average and 47 percent unprotected. The UK and US were the best performers in the sector, but even 17 percent of US government domains had zero protection — despite a Department of Homeland Security mandate requiring DMARC on all federal email domains.

Healthcare providers ranked second-worst at 3.43.

“85 out of the 438 domains we scanned had zero protections in place (19%) — the second highest of all sectors.” continues the report. “Four domains scored full points. Three of these were part of the UK’s NHS (NHS Blood and TransplantManchester University NHS Foundation Trust, and University Hospitals Birmingham NHS Foundation Trust), and one was the Dutch cancer specialist, Prinses Máxima Centrum.”

Chinese healthcare provider domains averaged 2.1, with 45 percent fully unprotected. The Netherlands was the outlier in healthcare, averaging 6.0 with zero unprotected domains — and four domains there scored perfect marks, including three NHS trusts in the UK and a Dutch cancer center.

Universities showed an interesting failure mode. Nearly 86 percent had a DMARC record in place, which sounds good. But 42 percent of those had left DMARC in monitoring-only mode, which means phishing emails pass straight through without being blocked or quarantined. Setting up DMARC and never enforcing it is roughly equivalent to installing a lock and leaving the key in it.

Technology companies led the field with an average score of 4.83, and only 2 percent of their domains had zero protection. Only two domains in the entire study scored perfect 8/8 across all sectors: microsoft.com and f5.com. On the country side,

“Asian countries/territories had the lowest average scores, with China (2.3), South Korea (2.84), Hong Kong (3.07), and Japan (3.53) ranking among the lowest. The European countries of France (3.77), Germany (3.8), and Spain (3.98) also scored poorly.” states Comparitech.”Among the highest-scoring countries were the Netherlands (5.51), Denmark (5.33), Norway (5.31), and Finland (5.19).”

The Nordic pattern isn’t accidental: GDPR creates pressure toward stronger data protection practices, and it shows in the scores.

MTA-STS, the protocol that enforces encrypted connections for email transfer, is almost universally ignored. Only 3 percent of all domains in the study had it in place. SPF was present on 90 percent of domains and DMARC on 81 percent, but having a record in place and enforcing it are different things: a DMARC policy set to p=none does nothing to stop a phishing email from landing in someone’s inbox.

“Our report highlights how each and every industry and country has room for improvement when it comes to email security. This is even the case within sectors and/or countries where email security is regulated to some degree.” concludes the report.

“Equally, certain sectors within specific countries face heavier regulation. For example, in the US, the Department of Homeland Security (DHS) mandates that DMARC should be in use on all government agency email domains. And, in the UK, the Government Digital Service (GDS) requires DMARC across governmental domains, and with p=reject (hard fail)”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Email Security)

  • ✇Security Affairs
  • Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails Pierluigi Paganini
    Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has been running since April 2026. The targets are specific: device names observed across compromised environments include strings like “reception,” “frontdesk,” “reservations,” “accueil,” “recepcja,” and “recepce” in Engl
     

Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails

27 de Junho de 2026, 12:20

Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence.

Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has been running since April 2026. The targets are specific: device names observed across compromised environments include strings like “reception,” “frontdesk,” “reservations,” “accueil,” “recepcja,” and “recepce” in English, French, Polish, Czech, and Spanish. The attacker knows exactly who opens guest-related emails without thinking twice about it.

The delivery mechanism is what Microsoft calls authentication laundering.

“The threat actor uses Calendly’s email notification system and Google’s URL redirect functionality to construct a multi-hop delivery chain in which the direct Calendly path passes Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) checks.” reads the report published by Microsoft.

The emails arrive with the display name “Booking Manager (via Calendly)” and carry lures about bedbug infestations, health inspections, guest complaints, final warnings, and threatened suspensions. They came in Japanese, Danish, and Dutch, with Japanese the most common. The researchers observed that the messages have no recipient name, no property name which suggests this is high-volume list-driven sending, not tailored spearphishing.

Upon clicking the embedded link, the victim is routed through four hops: a Calendly redirect to share.google, then to www.google.com, then to a freshly registered Cloudflare-fronted .cfd domain sitting behind a Turnstile challenge. That challenge serves double duty as an anti-analysis gate and a geolocation filter before the payload lands. The downloaded archive contains a shortcut file named IMG-<numbers>.png.lnk in Wave 1 or PHOTO-<numbers>.png.lnk in Wave 2, both sized consistently between 1,989 and 2,079 bytes, suggesting the same builder tool across the campaign.

Opening the shortcut fires PowerShell. The script uses BigInt arithmetic to decode a download URL, a technique that evolved across seven distinct obfuscation phases over the course of the campaign.

“A defining characteristic of this campaign is its steady but disciplined obfuscation evolution. Microsoft observed seven PowerShell obfuscation phases over the course of the campaign, but the underlying logic remained consistent: decode embedded data through arithmetic operations, recover the next-stage content, and retrieve a PowerShell script that runs from the %TEMP% folder.” continues the report. “This pattern suggests that the threat actor is iterating for durability against static detections rather than experimenting with entirely new tradecraft. “

The operators never abandoned PowerShell or Node.js. They just kept re-skinning the same working loader as detections caught up.

The decoded script downloads a legitimate Node.js v24.13.0 runtime from nodejs.org into user space, then runs a JavaScript implant tracked as TonRAT from AppData\Local\Nodejs\. No system-wide Node installation is needed. Wave 2 added an intermediate stage: the downloaded PowerShell script triggers dynamic .NET DLL compilation through csc.exe and cvtres.exe, producing small 3,072-byte DLLs with random names before reaching Node.js. Microsoft assesses this step is preparatory or conditional, as the compiled DLL wasn’t observed being explicitly loaded in available telemetry.

The persistence design is what makes this campaign technically notable.

“The persistence design itself is a meaningful post-compromise observation. The combination of a durable Node.js launch point in HKCU\Run and a repeatedly refreshed ProgramData payload through HKCU\RunOnce suggests an effort to maintain execution options across user sign-ins while also preserving a secondary recovery path.” states Microsoft. “This RunOnce loop is unusual enough that it might provide defenders with a strong hunting pivot even when file names, domains, or script syntax change.”

The RunOnce entry doesn’t fire once and disappear: the payload refreshes its own persistence after each execution, creating a loop. Microsoft observed this in practice: Defender blocked the PE payload xmnrwv9l.exe on a confirmed compromised device, but the Node.js Run key survived. Two days later, the implant reactivated, reconnected to new C2 domains, and resumed pushing additional payloads. Blocking one path left the other alive.

Post-compromise activity on a subset of devices included C2 beaconing to fixed IPs over non-standard ports including 56001, 56002, 56003, 8443, 8445, 8453, and 5555. Some hosts showed headless browser automation with --headless --no-sandbox flags, a geolocation check via ip-api.com, and a forced shutdown through cmd /c shutdown -s -t 0.

The forced shutdown may have served to interrupt user activity, reduce defender response time at a specific stage, or conceal visible symptoms after automated browser tasks completed. Microsoft has not confirmed data theft, ransomware deployment, or named any victims. The campaign’s ultimate objective remains unclear, which is itself a useful piece of information: whoever built this invested heavily in persistence and evasion for something they haven’t shown yet.

Complete remediation requires removing both persistence mechanisms simultaneously: the HKCU\RunOnce entry pointing into ProgramData, the HKCU\Run key pointing to the Node.js component, the Node.js runtime itself, and all associated .js files under AppData\Local\Nodejs\. Start with reception, reservations, and front office systems, and treat any device where Node.js appears in user-space paths as potentially compromised until proven otherwise.

The report includes Indicators of compromise (IoCs) for this campaign.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, hospitality)

❌
❌