Back to Feed
MalwareOct 8, 2026

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Multiple threats emerge: malicious VS Code extensions, a new Windows RAT via WhatsApp, and exposed hacker tools.

Summary

This week's ThreatsDay bulletin highlights several security concerns, including malicious VS Code extensions like 'Coca-Cola Christmas' and 'Aurora Borealis Studio Theme' that hide Windows downloaders and use Solana transaction memos for C2. A new Windows RAT, VulcanRAT207.A, is being distributed via WhatsApp using a financial document lure and employs a BYOVD technique to disable security software. Additionally, the BraZetsu malware framework's C2 infrastructure was mapped, revealing its connection to the Infected Marketplace.

Full text

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories Ravie LakshmananOct 08, 2026Hacking News / Cybersecurity News The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now. What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned up. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Malicious VS Code themes exposed GlassWorm-Linked VS Code Extensions Discovered Socket said it discovered two suspicious VS Code themes still available on the Visual Studio Marketplace (Coca-Cola Christmas and Aurora Borealis Studio Theme) that claim to be color themes but share ties to Aurora Nocturne Night Theme, a previously removed malicious extension that concealed an obfuscated Windows downloader. Further analysis has uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes. An analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes has revealed that it contains a loader that decrypts and executes embedded JavaScript, avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos as a dead drop resolver to identify follow-on payload infrastructure. "That build contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity," Socket researcher Kirill Boychenko said. BraZetsu C2 infrastructure traced Mapping BraZetsu Infrastructure via TLS Certificates Last month, Group-IB published a detailed analysis of BraZetsu, a Python-based Windows malware framework that's designed to gain access to Windows hosts via phishing attacks. It's also linked to Infected Marketplace, an underground market that inventories compromised Windows hosts and sells the access after a deposit of about $5.80, settled through NowPayments. Hunt.io, in a new analysis of the network indicators, said "the command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure. The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host." WhatsApp lure deploys Windows RAT New VulcanRAT207.A Detailed A financial-document lure ("Statement.exe"), reportedly delivered via WhatsApp, has been found to deliver a previously tracked WebSocket remote access trojan (RAT) tracked as VulcanRAT207. As part of a multi-stage Windows intrusion. "After unpacking, the loader screened the host, attempted elevation, and injected a downloader into the LocalSystem Task Scheduler process," Morphisec said. "The chain retrieved a deployment bundle, used a signed GoFly driver ["GoFly64.sys"] to terminate selected Baidu security processes [using the BYOVD technique], established a Vulkan DLL side-loading task, and launched a WebSocket remote access trojan (RAT). The loader screens the host, attempts elevation, and uses PoolParty Variant 7 to place a downloader in the Windows Task Scheduler process without relying on CreateRemoteThread." The malware can collect system metadata, enable interactive shell access, terminate security processes, implement process injection techniques, replace clipboard text, enumerate local accounts, and terminate itself. Qilin suspect extradited Alleged Qilin Ransomware Group Member Extradited to Germany An alleged member of the Qilin ransomware group has been arrested in Japan and extradited to Germany. The suspect, a 28-year-old Russian national, was detained in Osaka in May and reportedly handed over to the German authorities on October 2, 2026. The suspect is believed to be a core member of the ransomware gang, and wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting more than $160,000 in cryptocurrency. Medical devices face PQC gaps PQC Readiness in Healthcare A new analysis from Forescout has revealed that most medical devices cannot be upgraded to post-quantum cryptography (PQC), leaving sensitive healthcare data vulnerable to future quantum-enabled attacks. The analysis, which covered over 2.5 million devices across more than 50 healthcare delivery organizations (HDOs), found that only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell (SSH) implementations capable of supporting a transition to PQC, compared to 50% of IT devices. "Across exposed healthcare systems, only 31% support TLS 1.3, the only TLS version capable of supporting standardized post-quantum cryptography," Forescout said. "Healthcare data – including medical histories, diagnostic images, lab results, and prescription records – remains valuable for a lifetime, making the sector especially vulnerable to harvest-now, decrypt-later (HNDL) attacks." Ransomware affiliate turns rogue Gentlemen Ransomware Affiliate Double Crosses Gang A Russian-speaking Gentlemen ransomware affiliate called Azazel robbed two dozen victims across six countries, then double-crossed his own gang by publishing the stolen data on a private leak site and pocketing the profits. Azazel "built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims," CloudSEK said. Power BI phishing delivers RMM Phishing Campaign Abuses Microsoft Power BI to Drop RMM Tools Huntress has detailed a phishing campaign where threat actors abused legitimate Power BI domains to make the attacks more persuasive, evade security controls, and trick victims into downloading ScreenConnect installers. "These emails led victims to a fake reference document on the Power BI domains, which prompted targets to 'Download Reference,'" Huntress said. "When they attempted to do so, a new tab opened to an attacker-controlled website, which would fingerprint victims before triggering a rogue ScreenConnect installer download. Notably, these webpages delayed the payload's automatic download. After a few seconds, a script programmatically activated a hidden download link that led to the installer." The campaign was first observed on September 10, 2026. File upload flaw enables web shells Flaw in Recreation Management Software Abused to Upload Web Shells A file upload vulnerability in a popular web-based recreation management software platform designed for local municipalities and parks has been weaponized to compromise three servers by adding a new account, using it to upload web shells, and ultimately stealing payment data. "User-agent strings suggest that the threat actor is based in China," Huntress said. "We also suspect the use of AI-generated scripts throughout the kill chain, from the large number of failed initial access probes to the final upload of PowerShell scripts with extensive comments in the provi

Indicators of Compromise

  • domain — c2.installscenter[.]com
  • domain — painel.installscenter[.]com
  • ip — 80.78.27[.]252
  • malware — GlassWorm
  • malware — BraZetsu
  • malware — VulcanRAT207.A
  • mitre_attack — T1204.002
  • mitre_attack — T1071.001
  • mitre_attack — T1055.012
  • mitre_attack — T1574.002
  • mitre_attack — T1555.003
  • mitre_attack — T1027
  • mitre_attack — T1140
  • mitre_attack — T1211
  • mitre_attack — T1562.001

Entities

VS Code (product)Visual Studio Marketplace (product)Aurora Nocturne Night Theme (product)Cosmic Nebula Themes (product)Coca-Cola Christmas (product)Aurora Borealis Studio Theme (product)