ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
Weekly threat roundup: XWorm phishing, GenieLocker ransomware, CastleLoader variants, ClickFix evolution, 370 Chrome
Summary
ThreatsDay bulletin reports multiple active threats including xplogs22 targeting Russia with XWorm phishing, Toy Ghouls deploying custom GenieLocker ransomware across Russian sectors, CastleLoader distributing Needle Stealer variants, and ClickFix evolving to use fileless WebDAV execution. Additional stories cover 370 Chrome vulnerabilities, SonicWall attacks, DNS hijacking campaigns, and abuse of reused credentials and exposed systems.
Full text
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories Ravie LakshmananJul 30, 2026Hacking News / Cybersecurity News A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway, here's the mess. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Phishing delivers XWorm Xplogs22 Targets Russia with XWorm A cybercrime group known as xplogs22 has been observed targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called LunaSpy as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection. Custom ransomware targets Russia Toy Ghouls Come Back with GenieLocker Ransomware The financially motivated extortion group known as Toy Ghouls (aka Bearlyfy and Labubu) has targeted organizations in the Russian Federation, primarily in the manufacturing, financial services, retail, and technology sectors, with a custom ransomware family called GenieLocker since March 2026. According to Kaspersky, the group previously relied on third-party encryptors like RedAlert, LockBit, and Babuk. "GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software," Kaspersky said. In at least one case, initial access to the target environment was obtained via an OpenVPN connection originating from an external partner's network, with the attackers likely exploiting the trusted relationship to breach the target, conduct reconnaissance, deliver additional tools for credential harvesting, and perform lateral movement via RDP and SSH to reach other Windows and Linux hosts. "During the impact phase, the attackers encrypted files on the compromised Windows machines with the PE version of the GenieLocker ransomware," Kaspersky said. "On the compromised Linux and ESXi servers, they stopped active virtual machines and encrypted their disks using the ELF version of GenieLocker." Details of the activity were first highlighted by F6 in March 2026. Crypto-stealing payloads deployed CastleLoader Delivers Needle Stealer The malware loader known as CastleLoader, which has been previously used to deliver CastleStealer and a Python-based remote access trojan (RAT) via ClickFix-style lures, has now been used to distribute two payloads tied to the Needle Stealer framework: a Rust-based desktop wallet spoofer, and a Golang-based malicious browser extension installer. Arctic Wolf said it also identified a new shellcode loader variant spreading via digitally signed installers. The campaign has been codenamed Noidret. The introduction of these new tools is seen as an attempt to focus on cryptocurrency-specific targeting and establish browser-level persistence. Fileless WebDAV execution ClickFix Continues to Evolve Speaking of ClickFix, CyberProof said it tracked a ClickFix variant that involves tricking victims into pasting a single command into the Windows Run dialog, which then communicates with a WebDAV endpoint and uses rundll32.exe to load a remote, non-DLL payload and call its first export by ordinal without having to leave any artifacts on disk. "The payload (gc.key, j.pm, or goog.ct) is a file served from the attacker WebDAV share and is not a standard DLL by extension," CyberProof said. "It is invoked by rundll32.exe through ordinal #1, which runs its primary routine while keeping the export name off the command line." Fake Claude guide spreads malware Fake Claude Install Guide Leads to MacSync Stealer Victims searching Google for how to install Claude on a Mac are being served sponsored results that lead them to a weaponized claude.ai/share conversation dressed up as an Apple Support install guide. The "guide" instructs them to open Terminal and paste a single curl command, ultimately leading to execution of MacSync Stealer. "MacSync is a six-stage kill chain, not a smash-and-grab," Huntress said. "The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow." Malware, intrusions, and influence ops Cybercriminal Campaign Delivers Commodity Malware A Russian-speaking threat group is said to be behind an active campaign called Operation STANDOFF that combines commodity-malware distribution, a proxy-botnet that conscripts victims into relay infrastructure, targeted hands-on-keyboard intrusion of enterprise networks, and an AI-driven, multi-channel influence and engagement-manipulation capabilities under one roof. "The operation is materially more than a botnet," VMRay Labs said. "It couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team." The influence apparatus uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services. The activity uses a pay-per-install (PPI) loader masquerading as software installers that delivers Raccoon Stealer, RedLine, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig cryptocurrency miner, while a second, targeted operations layer relies on a bespoke, multi-operator command-and-control console through which human operators conduct hands-on-keyboard intrusions of selected victims. Fleet takeover flaw exposed Exploiting Volvo/Eicher's Fleet Management Platform Security researcher Eaton Zveare has disclosed details of a vulnerability in My Eicher, a fleet management system developed by the Volvo Group and Eicher Motors for Indian commercial vehicle customers, that enabled the discovery of unauthenticated internal and. admin APIs that could be exploited to gain high-level access to systems and even enable account takeover. "Account takeover made it possible to gain control over a person's (or company's) entire fleet, which could consist of hundreds of vehicles," Zveare said. Following responsible disclosure on November 3, 2025, the issue was addressed at some point by November 20. AI agents automate exploitation Chinese-Speaking Threat Actor Abuses AI Models for Autonomous Attacks A Chinese-speaking threat actor has been carrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions (CVE-2026-33824). The actor, operating under the aliases knaithe and KnYuan, has leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator, while orchestrating the operation through Telegram to enumerate targets, source exploit tools, and initiate attacks without human intervention. "Hermes Agent provided orchestration (terminal access, Telegram-based command and control, and the skills syst
Indicators of Compromise
- malware — XWorm
- malware — LunaSpy
- malware — GenieLocker
- malware — CastleLoader
- malware — Needle Stealer
- malware — ClickFix
- malware — Formbook
- malware — Snake Keylogger