Daily Drop (1303)
05-23-26
Saturday, May 23, 2026 // Buy Bob a Coffee // Ghostwire
Beijing-Linked Webworm APT Uses Discord and Microsoft Graph for Stealthy Espionage Operations in Europe
Bottom Line Up Front (BLUF): China-aligned APT group Webworm is targeting European government organizations using unconventional command-and-control channels including Discord and Microsoft Graph APIs. Researchers say the group has shifted away from traditional malware families toward stealthier proxy infrastructure, cloud-hosted tunneling tools, and API-based backdoors designed to blend malicious traffic into legitimate enterprise communication patterns.
Analyst Comments: Discord, Microsoft Graph, OneDrive, GitHub, and cloud VPN infrastructure all provide attackers with two major advantages: encrypted traffic that blends into normal enterprise activity and operational resilience against simplistic IOC blocking. The Microsoft Graph usage is particularly notable because defenders increasingly allow Graph API traffic by default across enterprise environments. Once attackers hide C2 inside trusted SaaS APIs, network-level detection becomes dramatically harder unless organizations baseline process-level behavior and application context. Discord-based C2 serves a similar purpose—most security tooling is not tuned to treat chat application APIs as suspicious telemetry channels.
READ THE STORY: DR
Chinese APT Calypso Deploys New Linux and Windows Malware Against Telecom Providers
Bottom Line Up Front (BLUF): Chinese-linked threat group Calypso, also referred to as Red Lamassu, has been targeting telecommunications providers across the Asia-Pacific region and parts of the Middle East since at least 2022 using two newly identified malware families: Showboat for Linux systems and JFMBackdoor for Windows environments. The campaign focuses heavily on persistence, stealth, lateral movement, and long-term espionage inside telecom infrastructure.
Analyst Comments: Telecom providers remain one of the highest-value espionage targets on the planet. If you compromise a telecom operator, you are not just accessing one company—you potentially gain visibility into customer metadata, routing infrastructure, enterprise communications, roaming traffic, and interconnected government networks. That is why Chinese operators keep returning to this sector year after year. The Linux targeting here is especially notable. Enterprise security visibility on Linux infrastructure still lags behind Windows in many environments, particularly inside telecom and network operations systems. Showboat appears designed specifically for that gap: persistence, SOCKS5 proxying, port forwarding, stealth process hiding, and dead-drop retrieval through public websites all point toward infrastructure-focused operations rather than smash-and-grab malware activity.
READ THE STORY: DS
Middle East Telecom Infrastructure Increasingly Abused for Large-Scale Cybercrime and C2 Operations
Bottom Line Up Front (BLUF): Researchers are tracking widespread abuse of Middle Eastern telecom and hosting infrastructure by threat actors operating command-and-control (C2) networks, ransomware delivery systems, phishing infrastructure, and botnets. Hunt.io identified more than 1,350 active C2 servers across 98 providers in 14 countries, with Saudi Telecom Company (STC) alone accounting for roughly 72% of observed regional C2 activity. The findings suggest attackers are increasingly leveraging ISP-scale infrastructure and compromised customer devices to build resilient, difficult-to-disrupt operational networks.
Analyst Comments: Disposable VPS nodes and short-lived cloud instances still exist, but mature operators increasingly prefer blending into high-volume telecom environments where malicious traffic becomes statistically insignificant against legitimate customer activity. The STC concentration is particularly interesting. Researchers are not suggesting Saudi Telecom itself was compromised directly—instead, attackers appear to be leveraging infected customer systems, residential links, or poorly monitored hosted infrastructure sitting inside the provider’s network space. That effectively turns large telecom ecosystems into distributed relay layers for C2 operations.
READ THE STORY: GBhackers
Russian Hackers Blend RDP, VPN, and Supply Chain Attacks to Expand Initial Access Operations
Bottom Line Up Front (BLUF): Russian state-linked threat actors are increasingly combining exposed RDP services, compromised VPN infrastructure, supply chain intrusions, and modern phishing techniques to gain initial access into government, infrastructure, and enterprise networks. The tradecraft is not particularly new, but the operational layering makes detection harder and gives attackers multiple fallback paths when one vector fails. Organizations with weak remote access hygiene or unmanaged third-party relationships remain especially exposed.
Analyst Comments: RDP abuse, credential stuffing, OAuth phishing, and supplier compromise all work because most enterprises still struggle with visibility across remote access systems and federated identity workflows. The notable shift here is how these actors are chaining techniques together—steal cloud tokens through device-code phishing, pivot into VPNs, move laterally over trusted supplier connections, then maintain persistence through legitimate remote administration channels. That creates intrusion activity that often looks like normal business traffic until the damage is already done.
READ THE STORY: GBhackers
Russian Satellites Maneuver Near ICEYE Surveillance Asset, Raising Anti-Satellite Concerns
Bottom Line Up Front (BLUF): Four recently launched Russian military satellites have maneuvered into near co-planar orbits with an ICEYE commercial radar imaging satellite used by Ukraine and Western governments. Analysts say the orbital adjustments resemble the early stages of rendezvous and proximity operations (RPO), a tactic associated with counterspace and anti-satellite missions. While Russia’s exact intent remains unclear, the moves signal continued escalation in the militarization of low-Earth orbit.
Analyst Comments: Orbital plane changes are expensive in terms of fuel consumption, so satellites generally do not perform them casually. Russia burning that much delta-v to align with an ICEYE asset strongly suggests deliberate positioning rather than routine orbital maintenance. The bigger issue is precedent. Russian military satellites have already demonstrated shadowing behavior against US reconnaissance platforms, and this latest maneuver appears to extend the same playbook toward commercial ISR providers supporting Ukraine. That blurs the line between civilian and military targets in orbit—a trend that has been accelerating since the invasion began.
READ THE STORY: arsTECHNICA
Iranian APT Screening Serpens Expands Espionage Campaigns With Advanced .NET Evasion and Recruitment Lures
Bottom Line Up Front (BLUF): Palo Alto Networks Unit 42 identified a major evolution in operations conducted by Iranian-linked APT group Screening Serpens (UNC1549 / Smoke Sandstorm), including six new RAT variants deployed against targets in the U.S., Israel, UAE, and other Middle Eastern entities between February and April 2026. The campaigns combine highly tailored recruitment-themed phishing with advanced AppDomainManager hijacking techniques that disable .NET security telemetry before endpoint defenses fully initialize, significantly increasing stealth and persistence capabilities.
Analyst Comments: Screening Serpens has clearly moved beyond basic phishing and commodity malware delivery into coordinated, modular intrusion operations designed for stealth, persistence, and operational resilience. The AppDomainManager abuse is the standout here. Rather than using noisy in-memory patching or ETW tampering that EDR tools increasingly detect, the group manipulates legitimate .NET runtime configuration behavior to disable telemetry before most monitoring even starts. That is a very different level of tradecraft compared to traditional DLL sideloading operations. It also reflects a broader trend among advanced actors: abusing native framework behavior instead of deploying obviously malicious code.
READ THE STORY: Unit 42
CISA Opens KEV Submissions to Researchers as AI Accelerates Exploit Development
Bottom Line Up Front (BLUF): CISA has launched a formal public submission process allowing researchers, vendors, and private-sector partners to nominate vulnerabilities for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. The move is designed to speed up identification of actively exploited bugs as defenders face a surge in AI-assisted vulnerability discovery and exploit development. The change also signals growing pressure on CISA to keep the KEV relevant as commercial threat intelligence platforms move faster than government timelines.
Analyst Comments: The KEV catalog has become one of the few vulnerability lists defenders actually trust because it prioritizes exploitation over theoretical severity. The problem is speed. Threat actors—and increasingly AI-assisted tooling—are compressing the window between disclosure and exploitation faster than traditional coordination models can handle. Opening submissions to external researchers effectively turns the KEV into a crowdsourced exploitation intelligence pipeline. That helps defenders, but it also creates a verification problem. If CISA cannot validate submissions quickly and accurately, the catalog risks becoming noisy or reactive instead of authoritative. There is also a broader issue here: many security teams already treat commercial exploitation telemetry feeds as leading indicators while viewing KEV as confirmation after the fact. CISA is clearly trying to close that gap.
READ THE STORY: The Record
Google Releases Chromium PoC Before Patch, Expanding Browser Botnet Exposure Window
Bottom Line Up Front (BLUF): Google’s release of proof-of-concept exploit code for a still-unpatched Chromium vulnerability is drawing criticism from security researchers and defenders alike. The flaw, first reported in 2022, abuses the Browser Fetch API and Service Workers to establish persistent browser-to-C2 communication channels, potentially enabling stealthy browser-based botnets across Chrome, Edge, Brave, and Opera installations.
Analyst Comments: Most organizations still treat browsers as user applications rather than semi-persistent execution environments with networking, storage, background processing, and authentication access. That mindset gap is exactly why vulnerabilities like this are dangerous. The technical mechanics here are not especially sophisticated, but the scalability is what matters. Attackers do not need kernel access or malware installation if they can maintain reliable browser-level persistence across thousands of systems. A lightweight botnet built entirely from legitimate browser processes is significantly harder to distinguish from normal traffic, especially in remote work environments where outbound HTTPS noise is already massive.
READ THE STORY: GBhackers
Attackers Bypass MFA on SonicWall VPNs Due to Incomplete Patch Remediation
Bottom Line Up Front (BLUF): Attackers are actively exploiting SonicWall Gen6 SSL-VPN appliances even after organizations applied firmware patches for CVE-2024-12802. The issue stems from incomplete remediation requirements involving manual LDAP configuration changes that many administrators missed. Threat actors linked to ransomware activity are reportedly bypassing MFA protections, brute-forcing credentials, and moving laterally inside victim networks within minutes of initial access.
Analyst Comments: Security teams often assume firmware updates fully remediate vulnerabilities, but this flaw required manual reconfiguration steps outside normal patch management workflows. Predictably, many organizations updated firmware, saw the version check pass, and moved on while the vulnerable LDAP configuration remained intact. The operational concern here is speed. According to ReliaQuest, some attackers reached internal file servers within 30 minutes of VPN access. That suggests mature intrusion workflows designed for rapid environment assessment and ransomware staging. The observed use of Cobalt Strike and BYOVD techniques also points toward experienced operators rather than opportunistic scanning activity.
READ THE STORY: Securityaffairs
Shai-Hulud npm Worm Campaign Signals New Era of Autonomous Supply Chain Attacks
Bottom Line Up Front (BLUF): Palo Alto Networks Unit 42 warns that the Shai-Hulud malware campaigns have transformed npm ecosystem attacks from isolated package compromises into self-propagating software supply chain operations capable of autonomously stealing credentials, poisoning CI/CD pipelines, compromising GitHub Actions workflows, and republishing infected packages at massive scale. Recent 2026 campaigns impacted hundreds of npm packages, major enterprise ecosystems, AI tooling, SAP development infrastructure, and open-source projects with hundreds of millions of downstream downloads potentially exposed.
Analyst Comments: The important evolution here is automation. Once a single maintainer account, CI pipeline, or GitHub Actions runner is compromised, the worm handles propagation on its own—harvesting npm tokens, GitHub PATs, cloud secrets, SSH keys, CI/CD credentials, and then reinfecting every package the victim can publish. The May 2026 TanStack incident is especially concerning because it did not require stolen credentials initially. The attackers chained together GitHub Actions workflow weaknesses, cache poisoning, and OIDC token extraction directly from runner memory. That is a much more sophisticated threat model than simple maintainer compromise or typosquatting. It also demonstrates that SLSA provenance alone is no longer enough. The packages were technically built by the legitimate pipeline—just with poisoned internal state.
READ THE STORY: Unit 42
Law Enforcement Seizes “First VPN” Infrastructure Used by Ransomware and Cybercrime Actors
Bottom Line Up Front (BLUF): International law enforcement agencies have dismantled the “First VPN” service, a privacy-focused VPN platform heavily used by ransomware operators, fraud groups, and other cybercriminal actors to conceal infrastructure and operational traffic. Authorities seized servers across 27 countries, arrested the alleged administrator in Ukraine, and reportedly obtained user databases and connection records tied to ongoing cybercrime investigations.
Analyst Comments: That changes the impact dramatically. Criminal actors often assume “no-log” VPN marketing equals operational security, but history keeps showing that trust assumptions around underground infrastructure eventually collapse under pressure from law enforcement or internal compromise. The operational fallout could be significant if Europol genuinely obtained usable connection metadata tied to ransomware and fraud operations. VPN services occupy a critical layer in cybercriminal tradecraft because they abstract attribution, infrastructure hosting, and operator location. Once investigators gain visibility into that layer, they can begin correlating sessions, wallet activity, infrastructure overlap, and intrusion timing across unrelated investigations.
READ THE STORY: Bleepingcomputer
Items of interest
CISA Credential Leak Sparks Congressional Scrutiny After GitHub Exposure of Sensitive GovCloud Access
Bottom Line Up Front (BLUF): CISA is under congressional pressure after researchers discovered a publicly exposed GitHub repository containing privileged AWS GovCloud credentials and internal agency access data. The leak, reportedly tied to a contractor-managed repository named “Private-CISA,” raised immediate concerns about potential persistence opportunities for nation-state actors and highlighted ongoing operational security failures inside the federal government’s top cyber defense agency.
Analyst Comments: If valid privileged credentials are sitting in a public repository, attackers skip reconnaissance and exploitation and move straight to access operations. The bigger issue here is not just exposure — it’s trust erosion. CISA is the agency responsible for advising critical infrastructure operators on cyber hygiene, yet it suffered the same GitHub credential leakage problem security teams warn junior developers about weekly. The most concerning detail is the mention of AWS GovCloud credentials potentially enabling persistence. If a state actor accessed the repository before remediation, the risk shifts from “credential leak” to possible long-term cloud foothold establishment. Depending on IAM permissions, temporary tokens, logging gaps, or federated trust relationships, this could become far more serious than a simple secrets exposure.
READ THE STORY: Cyberscoop
CISA Contractor AWS Leak + Industrial Robot Exploits (Video)
FROM THE MEDIA: We analyze a high-stakes CISA supply chain breach involving AWS GovCloud and investigate critical command injection vulnerabilities threatening industrial robot fleets. This briefing also covers new npm-targeting malware and the latest global efforts to dismantle cybercrime infrastructure.
Introduction to secret leaks and getting started with GitHub Secret Protection (Video)
FROM THE MEDIA: Have your secrets leaked? Learn about what you can do to mitigate risk -- and stop secrets from leaking in the first place.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


