Weekly review

ThreatNoir Morning Brief — August 20

2026-08-20Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 20, 2026

The cybersecurity landscape continues to face evolving threats across critical infrastructure, browser ecosystems, and enterprise software. Today's briefing covers AI-powered attacks targeting industrial control systems, a massive malicious Firefox extension campaign targeting cryptocurrency wallets, ongoing exploitation of PTC software vulnerabilities, and fraudulent recovery services exploiting ransomware victims.

US Warns of AI-Powered Attacks on Siemens PLCs in Critical Infrastructure

U.S. cybersecurity agencies have issued warnings regarding threat actors deploying AI-generated scripts to exploit Siemens S7 Series programmable logic controllers in critical infrastructure environments across the United States. The use of artificial intelligence to automate and refine attack scripts represents a significant escalation in the sophistication of industrial control system targeting. These attacks pose direct risks to essential services and operational technology networks that depend on Siemens equipment for core functions. Source: US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

77 Firefox Extensions Linked to Crypto Wallet and Credential Theft

Researchers at Socket have identified a coordinated campaign involving 77 Firefox extension identities designed to steal cryptocurrency wallet secrets and user credentials. The investigation revealed 40 confirmed malicious extensions actively stealing wallet recovery phrases, private keys, and credentials through multiple attack vectors. An additional 37 extensions employ deceptive sports-score shells as cover while sharing publishing infrastructure and code patterns indicative of malicious intent. The campaign, provisionally tracked as "Offside Wallet Theft Factory," has operated since at least March 2026 and employs sophisticated techniques including remote-controlled phishing delivery through Supabase projects, wallet secret exfiltration via Cloudflare Workers, interception of Rabby wallet keyrings before encryption, and direct credential and clipboard data theft to hardcoded command-and-control infrastructure. The threat actors impersonate legitimate Web3 products including OKX, Rabby Wallet, and TronLink while using repurposed extension identities and deceptive marketplace descriptions to evade detection. Even brief installations can result in permanent compromise of cryptocurrency assets once recovery phrases or private keys are exposed. Source: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft

The Long Tail of Clop's PTC Hack Is Just Beginning to Emerge

The Clop data theft extortion group likely exploited a critical vulnerability in PTC's product lifecycle management software in June 2026, approximately one month before sending extortion demands to victims. The attack on PTC's Windchill and FlexPLM products represents a significant supply-chain compromise affecting organizations that depend on these tools for product development and lifecycle management. The delayed emergence of victim notifications suggests the full scope of the breach may still be unfolding, with additional compromised organizations potentially unaware of their exposure. The vulnerability, tracked as CVE-2026-12569, has enabled the threat group to conduct mass data exfiltration campaigns against enterprise customers. Source: The long tail of Clop's PTC hack is just beginning to emerge

Rogue Ransomware Affiliate Poses as Data Recovery Firm to Steal Payments

A suspected ransomware affiliate is actively impersonating a legitimate ransomware recovery service called "Ransom Busters" to defraud victims. The threat actor contacts organizations before ransomware attacks become public knowledge, falsely claiming to possess decryption keys and offering to delete stolen data in exchange for payment. This social engineering tactic exploits the panic and urgency surrounding active ransomware incidents to extract additional funds from victims already suffering financial losses. The rogue operation has been linked to ransomware variants including Anubis, DragonForce, and Settra. Organizations should verify the legitimacy of any recovery service contact and avoid engaging with unsolicited offers of decryption assistance. Source: Rogue ransomware affiliate poses as data recovery firm to steal payments

Organizations should remain vigilant regarding emerging threats across industrial control systems, browser extensions, enterprise software supply chains, and incident response processes. Implementation of robust verification procedures, extension auditing, vulnerability management, and incident response protocols remains essential to mitigating these evolving risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
IP Address1
  • 77.91.100.175
    Command and Control (C2) server IP address.
Domain3
  • api-sports.io
    Legitimate sports data provider, but used with hardcoded credentials in deceptive extensions.
  • cloudflare.com
    Legitimate cloud service, abused for exfiltration via Cloudflare Workers.
  • supabase.co
    Legitimate cloud platform, abused for remote control of phishing extensions.
URL7
  • hxxps://winter-smoke-a612[[.]]icy-star-f45c[[.]]workers[[.]]dev/
    Cloudflare Worker used for exfiltrating recovery phrases.
  • hxxps://winter-waterfall-0606[[.]]rihaniomar21[[.]]workers[[.]]dev/
    Cloudflare Worker used for exfiltrating wallet secrets.
  • hxxp://id[[.]]gemachriverdale[[.]]org:9000/hook/ptvve
    Endpoint for exfiltrating serialized keyring data.
  • hxxp://77[[.]]91[[.]]100[[.]]175/html/app[[.]]php
    C2 server for credential collection.
  • hxxp://77[[.]]91[[.]]100[[.]]175/html/continue[[.]]php
    C2 server for clipboard data exfiltration.
  • hxxps://portal-web3-extension-welcome[[.]]pages[[.]]dev/home
    Phishing page hosted via Cloudflare Pages, loaded by Supabase-controlled extensions.
  • hxxps://dry-bush-5408[[.]]animalrescueeducationcenter-org[[.]]workers[[.]]dev/
    Cloudflare Worker used for exfiltrating recovery phrases.
SHA-2565
  • 08b7b064fa9a…
    SHA-256 hash for a malicious Firefox extension (Safe-Themes - Browser Extension).
  • 4d0912d57508…
    SHA-256 hash for a malicious Firefox extension (Portal).
  • 26427220b996…
    SHA-256 hash for a malicious Firefox extension (Rabbit For Desktop).
  • 39827e214c31…
    SHA-256 hash for a malicious Firefox extension (exrb).
  • 894398430972…
    SHA-256 hash for a malicious Firefox extension (trl).