news.mlab.sh
Back to the feed
threat-intel

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories

High
Summary

This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT targeting credentials, a significant intrusion campaign attributed to the North Korean APT group Famous Chollima, and the seizure of fraudulent consulting domains used to extract sensitive information. The overall trend indicates a maturing malware-as-a-service ecosystem and increasingly targeted attacks leveraging deception and social engineering.

A significant breach occurred with Flashpoint reporting the exposure of over 3.3 billion stolen credentials, stemming from the widespread infection of more than 11.1 million devices with infostealers like Lumma, Acreed, Rhadamanthys, Vidar, and StealC. These stealers, active across countries including India, Brazil, Indonesia, Vietnam, the Philippines, and the U.S., demonstrate the accessibility and scale of modern malware-as-a-service. Simultaneously, the threat actor ‘o1oo1’ has launched SilabRAT, a MaaS RAT sold for $5,000/month, focusing on credential theft through techniques like HVNC and browser profile cloning. This highlights the increasing sophistication of attackers and their ability to leverage existing tools and vulnerabilities. Furthermore, CrowdStrike identified the North Korean APT group Famous Chollima as responsible for 47% of state-sponsored hands-on-keyboard operations targeting the tech sector, continuing their IT worker infiltration campaigns. Finally, the U.S. Department of Justice seized 13 domains used to trick individuals, including security clearance holders, into divulging classified information, reflecting a broader trend of foreign actors exploiting job platforms for espionage.

Read the full article at The Hacker News