Monday, August 31, 2026

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.

The ongoing insider threat is part of what has been described as the IT worker scheme, where North Korea leverages its network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world and remotely earn income to further Pyongyang's unlawful nuclear weapons and ballistic missile programs.

This entails relying on stolen or forged identity documents, VPNs, and proxy services to mask their true identity and location. The yearslong campaign is also tracked under the monikers Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole.

"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.

In one case in February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after they were found repeatedly connecting through Astrill VPN and IPRoyal Proxy, fraudulently created identity documents, similarities between two of the employees' passports, and glaring word anomalies in electronic bills submitted as proof of residence during the onboarding process.

"Despite the likelihood of passports and resident identity cards being fraudulent, there's still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed," Huntress added.

A second case this month at an unnamed financial services firm uncovered the presence of PiKVM on their device. The use of KVM switches like PiKVM or TinyPilot has been previously attributed to the North Korean IT worker scheme, allowing the remote threat actors to connect to devices hosted on laptop farms.

The "employee" is also said to have accessed a third-party file-sharing service SendGB to download a modified version of a legitimate GitHub profile, likely for use as their own profile picture on an internal communications tool.

Days after the installation of PiKVM, the same device also had a Guermok USB capture card attached to it so as to enable "video streaming through it to be sent as a webcam input in web conferencing applications such as Zoom." Although the use of Guermok by itself isn't suspicious, the fact that PiKVM installation and Guermok USB attachment happened one after the other raises red flags.

In a third case investigated by Huntress in August 2026, a sales and marketing hire onboarded 13 days earlier appeared to have stolen or borrowed an existing identity to land the job, substituting the legitimate individual's face with the suspected DPRK worker after the former's details, including name, date of birth, and location, along with their mugshot were posted online by law enforcement post their arrest.

"Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding," Huntress said. "When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process."

These are far from isolated cases. Recorded Future's Insikt Group said it observed one cluster linked to PurpleDelta applied to jobs at over 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology sectors, between late 2024 and early 2025.

The threat actors, comprising multiple operators likely based in China, are suspected to have maintained 22 fabricated personas, some synthetically generated using artificial intelligence (AI) and using identity documents sourced from an illicit ID-generation service called TrustID Card ("trustidcard[.]com").

Describing PurpleDelta as maintaining a "high operational tempo," the threat intelligence company said the threat actors have applied to at least 60 positions per day across 10 job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas, and maintained extensive tracking spreadsheets to coordinate applications across identities.

"During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim," Recorded Future added. "Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work."

In addition, PurpleDelta operators have been found to rely on identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, as well as coordinate via Telegram and Slack to complete work, and communicate with facilitators who procure and maintain company-issued hardware on the operators' behalf.

"PurpleDelta activity is almost certainly ongoing and will very likely continue to expand in scale and sophistication as North Korean IT workers adapt to increased awareness and detection efforts," Recorded Future explained.

"The increasing integration of AI tools into PurpleDelta's tradecraft presents a compounding risk. The use of custom ChatGPT assistants, real-time AI transcription during interviews, and AI-generated profile photos lowers the barrier to plausible deception and enables operators to perform credibly in technical roles they may not fully understand."

The findings coincide with a number of related developments -

  • The U.S. Federal Bureau of Investigation (FBI) is investigating how a North Korean IT worker successfully gained employment at an unnamed federal government agency. It's believed that the remote IT employee was doing contract work rather than being hired directly.
  • The operators are funneling Western salaries through a web of front companies and intermediaries, including entities like Sobaeksu, Saenal, and Songkwang that have been sanctioned in the U.S. for sanctions evasion. According to DTEX, the scheme is also being used to support the regime's objectives, such as weapons manufacturing and supporting Russia's war effort. In all, the scheme is estimated to have made $1.97 million in payments between December 2025 and February 2026 flowing through the sanctioned Ryongbong General Corporation.
  • Earlier this May, two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in prison each for running a laptop farm for North Korean remote IT workers. The two separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in illicit revenue.
  • A month before that, 42-year-old Kejia Wang and 39-year-old Zhenxing Wang were sentenced to 108 and 92 months in prison, respectively, for operating a similar laptop farm at their homes in New Jersey and helping IT workers obtain remote jobs at more than 100 American companies, generating roughly $5 million and causing losses of more than $3 million to the victim companies. Four other men, Oleksandr Didenko, 29, Audricus Phagnasay, 25, Jason Salazar, 30, and Alexander Paul Travis, 35, were sentenced in February and March.
  • A series of reports from Nisos have revealed how DPRK operatives are using employment fraud to target cryptocurrency firms with an aim to conduct asset theft. One of the IT workers was also caught applying for a lead AI architect role at the human risk management company, inadvertently exposing their use of PiKVM to maintain control of their device located in a laptop farm containing 20 machines.
  • In April, Microsoft disclosed it observed Jasper Sleet actors accessing Workday Recruiting Web Service endpoints that are exposed through external career sites likely to obtain details about open roles and recruitment workflows. During the recruiting phase, the adversary is known to communicate with the target organization's hiring team using emails, and legitimate platforms like Microsoft Teams, Zoom, or Cisco Webex for interviews. Upon being hired, the threat actors create new Workday profiles and update payroll information, typically tied to a facilitator.

"Operating under synthetic identities, these individuals present themselves as highly experienced developers from all over the world to secure lucrative, long-term remote roles," Group-IB said. "This is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse."

"Beyond the immediate risk of data theft, organizations that unknowingly hire these workers face severe legal and compliance risks, as employing or paying DPRK IT workers could constitute a direct breach of U.N., U.S., and U.K. financial sanctions."

The persistent nature and the scale of the threat have prompted nearly a dozen governments to issue a joint alert late last month, urging all countries, companies, and other entities to intensify efforts to understand the scope of the DPRK worker schemes and implement appropriate countermeasures.

"Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.)," cybersecurity and intelligence agencies from the U.S., Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the U.K.



from The Hacker News https://ift.tt/0QbTdeL
via IFTTT

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The boring parts caused most of the trouble.

A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.

Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look.

Here is the week...

⚡ Threat of the Week

U.S. Disrupts Chinese Proxy Network Enabling Cyber Espionage — The U.S. Federal Bureau of Investigation (FBI) disrupted infrastructure associated with a technical quartermaster who sold reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. The QTYF group is said to have created and operated the QScan and QTRouter frameworks, which have been used to target U.S. critical infrastructure networks. It's employed by the China-based Nanjing Xinjiuwei Network Technology Company.

🔔 Top News

  • OpenAI Says Reward Hacking Drove AI Agents to Breach Hugging Face — OpenAI revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident took place during cybersecurity evaluations of several OpenAI models, and it was mainly fueled by what it described as a "highly capable, internal-only research model" comparable in scale to GPT‑5.6 Sol. "The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks – they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems," it said.
  • TerminalFix Uses Fake Cloudflare CAPTCHAs to Drop Reverse Tunnel Implant — A new ClickFix variant, dubbed TerminalFix, aims to trick users into running a malicious command in Windows Terminal or PowerShell instead of directing them to the Windows Run dialog. The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command. The attack chain, according to Microsoft, is a sophisticated multi-stage process that leverages DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a bespoke custom reverse-tunnel implant that grants the attacker persistent, network-level proxy access through the infected machine.
  • PaperCut Flaws Under Attack — Threat actors are chaining together two new security flaws in PaperCut NG and MF to execute arbitrary code on susceptible instances. "CVE-2026-81578 allows you to bypass authentication, and from there, you can edit a configuration file to exploit CVE-2026-82078 and gain Remote Code Execution," Jake Knott, head of threat intelligence at watchTowr, told The Hacker News. Huntress said it observed limited exploitation on two customer environments, with the attackers executing Base64-encoded commands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver."
  • China-Made ZBT Routers Ship with 2 Backdoors — A firmware analysis of ZBT Deep Orange 3G/4G/LTE Router uncovered two new backdoors called SPEAKINGSTONE (CVE-2026-74233, CVSS score: 9.3) and DARKLANTERN (CVE-2026-74232, CVSS score: 9.3). The development came after at least 21 firmware images from the Chinese company were found to contain another backdoor called ENDLESSDOORS (CVE-2026-66747, CVSS score: 9.3) that's designed to start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. The two new backdoors predate ENDLESSDOORS. "SPEAKINGSTONE, like ENDLESSDOORS, is a phone-home implant that connects back to ZBT's cloud infrastructure and accepts remote commands," VulnCheck said. "DARKLANTERN is a backdoor that listens on the WAN and executes arbitrary commands. No authentication required. Both are written in Nim. Both communicate over UDP. Both are launched by the same binary, a connectivity watchdog called inetdetect."
  • Fire Ant Targets Trusted Infrastructure in 2026 — The China-linked threat actor known as Fire Ant (aka UNC3886) has continued to remain active in 2026, going beyond hypervisors to target trusted infrastructure, including routers (including Cisco IOS XR routers), TACACS servers, authentication systems, and Linux management hosts to maintain covert access, collect credentials and traffic, and reach connected high-value environments. "The compromise impacted both the direct and third-party environments," Sygnia said. "Its trusted infrastructure relationships created potential reachability into connected external environments, including high-value networks and critical infrastructure. Fire Ant appeared to use this trusted position to explore access paths beyond the initially compromised environment." Compromised routers were used for covert connectivity, traffic collection, command-output manipulation, and suppression of logging. In addition, the threat actor used deployed long-lived implants across Linux management infrastructure, including Medusa rootkit-related components, custom SSH backdoors, Zabbix-masquerading malware (aka BridgeAgent) that acts as a pathway for actor-controlled access into connected environments, and packet-triggered backdoors. Another tool in Fire Ant's arsenal is TacTap, which is used for TACACS credential collection. "The actor also manipulated the evidence sources defenders depend on," Sygnia added. "It suppressed router logging, altered command output, captured administrative credentials, tampered with host logs, and deployed multiple persistent backdoors."

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — From CVE-2025-30237 through CVE-2025-30241, CVE-2025-15628, CVE-2026-9254, CVE-2026-16348, CVE-2026-78541 (TP-Link), CVE-2026-17106 aka CopyEscape (Docker), CVE-2026-70426 (Jenkins), CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, CVE-2026-15920 (Django), CVE-2026-19598 (Pods), CVE-2026-19874 (Konami Metal Gear Online 3), CVE-2026-75149, CVE-2026-67618 (Marimo), CVE-2026-77775, CVE-2026-77776 (Headroom LLM Proxy), CVE-2026-0251 (Palo Alto Networks GlobalProtect App), CVE-2026-59568, CVE-2026-59567, CVE-2026-59565 (Zscaler Client Connector), CVE-2026-69251, CVE-2026-73601, CVE-2026-69253, CVE-2026-69256, CVE-2026-73602, CVE-2026-69259, CVE-2026-69264, CVE-2026-73484, CVE-2026-69255, CVE-2026-70477, CVE-2026-73485, CVE-2026-73486, CVE-2026-73487, CVE-2026-70470, CVE-2026-69254 (Flowise), CVE-2026-19912, CVE-2026-19913 (Kaltura HTML5 Player Library), CVE-2026-79282, CVE-2026-79290, CVE-2026-79054, CVE-2026-79121, CVE-2026-79224, CVE-2026-79052, CVE-2026-79150, CVE-2026-78935, CVE-2026-79012, CVE-2026-79200 (Google Chrome), CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 (Ubiquiti UniFi), CVE-2026-18431 (Avada WordPress theme), CVE-2026-7791 (Amazon Skylight Workspace Config Service), CVE-2026-73554 (DoltHub), CVE-2026-19516 (Grafana MCP), CVE-2026-75604, GHSA-2xp9-vwfh-vxw4 (Next.js), CVE-2026-65643 (cPanel and WebHost Manager), CVE-2026-76639, CVE-2026-76640 (Unitree G1 EDU), CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 (ServiceNow AI Platform).

🎥 Cybersecurity Webinars

  • AI Can Build Attack Paths in Minutes. Is Your SOC Ready? → AI can now discover zero-days, generate working exploits, and chain full attack paths, often within minutes of disclosure. Learn how to assess your AI threat readiness and build the visibility, context, and response speed needed to keep pace.
  • AI Finds Flaws Faster. Your Exposure Answers Can’t Take DaysAI is speeding up vulnerability discovery, but the answer that matters is still slow: Are we exposed? See how Tines unified SBOM, application, cloud, and vulnerability data into one view to assess exposure faster and execute human-reviewed response playbooks at machine speed.

📰 Around the Cyber World

  • Play Ransomware Encryption — The closed ransomware group known as Play (aka PlayCrypt) has been found to employ a double extortion model, encrypting systems after exfiltrating data and threatening to publish stolen data on their Tor-hosted data leak site if ransom is not paid. In one incident observed in early 2026, the threat actor deployed SystemBC after gaining initial access, followed by reconnaissance, lateral movement, data exfiltration, and abusing SentinelOne's own legitimate removal tool to uninstall the product. "The threat actor gained initial access via a compromised SonicWall VPN, consistent with the group's well-documented pattern of exploiting external remote services," GuidePoint Security said. "What makes this case particularly instructive for defenders is the combination of three specific behaviors: Domain-wide tool staging via the SYSVOL share rather than per-host delivery, EDR removal using the victim's own SentinelOne uninstallation utility rather than a kernel-level driver exploit, and the recovery of a crash dump from a host where the encryptor failed to complete, an artifact that provides a rare forensic window into the encryption execution itself."
  • Email Bombing and Quick Assist for Ransomware Deployment — ZeroBEC disclosed details of an email bombing campaign targeting at least 10 users inside an organization, causing them to receive about 3,000 messages per day. "The messages were not a conventional phishing blast. Many were genuine verification, registration, deployment, and inquiry confirmations generated after the victims' email addresses were submitted to unrelated public platforms," the email security company said. About a day and a half after the email flooding, some of the users were contacted via Microsoft Teams by attackers masquerading as IT help desk personnel to help them tackle the problem. One of the employees, who was a local administrator, granted Microsoft Quick Assist access, enabling the attackers to deploy Xray-core, a reverse proxy tool, and expand their access. "The credential-theft step was woven directly into social engineering," ZeroBEC said. "The attacker mimicked the installation of a Windows security update and launched a local credential prompt from the compromised endpoint. The victim, who was still listening to the person he believed was IT, entered domain credentials into that prompt. The tooling validated and captured the credentials and then uploaded the resulting credential/configuration artifacts to an external Microsoft Dev Tunnel." Through the reverse tunnel, the threat actor conducted domain reconnaissance and attempted NTLM relay against certificate enrollment, all hallmarks of pre-ransomware deployment. It's worth noting the modus operandi shares overlaps with that of Aurora ransomware.
  • ValleyRAT Delivered via Rogue Installer — A malicious installer disguised as adware has been observed deploying a modified version of the Chinese desktop wallpaper management tool, QN Wallpaper, which then performs DLL sideloading to establish persistence on Windows systems by dropping a file to the Startup folder and ultimately launching ValleyRAT, a backdoor linked to a threat actor known as Silver Fox. The malware, besides taking steps to protect its process, can collect system information, reboot/shut down the computer, take screenshots, wipe logs, update command-and-control (C2) addresses, download additional modules, and send keylogger logs along with clipboard contents. Per Kaspersky telemetry, ValleyRAT and its related components have been detected more than 100,000 times, with more than 1500 unique users affected, mainly in China and India.
  • Brazil Fines ByteDance $29.81M for Privacy Violation — Brazil's data ‌protection authority, ANPD, fined TikTok's owner ByteDance 153.8 million reais ($29.81 million) for allegedly violating the country's General Data Protection Law. ANPD said that the local unit of China's ByteDance had processed personal data of teenagers aged 13 to 18 without ​a valid legal basis. The regulator estimated that TikTok may have processed the data of at ​least 8 million children during the review period.
  • DeepMind Debuts Double-Blind AI Evaluations — Google's DeepMind division launched a pilot of double-blind AI evaluations with an aim to keep external evaluations in a cryptographic "box" to stop benchmark contamination and protect intellectual property. To that end, Google said it's partnering with the Singapore AI Safety Institute, OpenMined, AVERI, and MLCommons, to test a Gemini Flash Lite model against confidential benchmarks in a privacy-preserving environment to increase evaluation integrity. "By using Confidential Space within Google Cloud’s Confidential Computing portfolio, we can cryptographically verify that both the external evaluation data and the proprietary model remain private to their respective owners," DeepMind said. "The evaluator cannot see the Gemini model weights, and Google cannot see the evaluator’s test prompts."
  • 34 Malware Families Targeting Banking Apps — Zimperium found 34 mobile malware families actively targeting more than 1,243 mobile banking and fintech apps across 90 countries globally. "The concentration of targeted applications across EMEA reflects where threat actors anticipate the highest return on investment, focusing heavily on the region's major financial centers," it said. Some of the active malware families in the EMEA region are TsarBot, CopyBara, HOOK, Nexus, Flubot, Eventbot, and MaliBot.
  • Fake KYC Apps Target Indian Customers to Deliver Ghost Penal — A new malware-as-a-service (MaaS) operation on Telegram, dubbed Ghost Penal, is selling ready-made Android banking trojan kits impersonating five major Indian banks. "The operation supplies a two-stage dropper protected by a custom native packer, a public cloud database that receives stolen UPI PINs and device data with no authentication required, and a downstream channel that relays intercepted one-time passwords for immediate fraudulent use," iZOOlogic said. The toolkit costs $25 for a five-credit pack and $400 for a three-month unlimited plan. One of the droppers containing the malicious payload masquerades as a video-calling application, while requesting access to SMS and telephony features. "The payload’s real functionality, including SMS interception, WebView-based KYC phishing, and data exfiltration, is not present in a static scan of the installed application," the company added. "It is protected by a native library, internally named libdpt.so, that decrypts a hidden code section in memory using RC4, forks the process before executing that code as an anti-debugging measure, installs hooks on libc and on the ART runtime’s class loader, and splices a second, hidden DEX archive into the application’s running ClassLoader. The same mechanism is then used in reverse to remove the trace of that injection."
  • Bauman University Leak Exposes Russia's Military Cyber Training Pipeline Leaked Bauman University records have revealed a long-running program that trained about 250 career and reserve students for special intelligence, operational information-technical effects, and information-technology protection under Department No. 4. "The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities," DomainTools said. "Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers." Department No. 4 is assessed to be tied to the GRU, with identified graduates assigned to military units associated with APT28 and Sandworm.
  • Pentagon's Anthropic Blacklisting Ruled Illegal — A U.S. judge blocked Anthropic's designation by the Pentagon as a supply chain risk earlier this year. "Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless," District Judge Rita Lin said. "The empty invocation of national security is not a blank check to punish and retaliate against government critics." Anthropic said it welcomed the ruling and it remained "focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology."
  • State of AI-Enabled Malware in August 2026 — Palo Alto Networks Unit 42's analysis of 405 malware samples that integrate AI in some capacity has found that only 12 of them reached a production environment, with about 97% existing only in sandboxes and on VirusTotal in the form of proof-of-concept and research code, security validating and testing, and AI-themed brand abuse. Among those that were detected in customer endpoints were FunkSec ransomware, a trojanized AI application called Recipe Lister, Oyster, Rhadamanthys Stealer, and a COM hijacking DLL. "For defenders, the practical takeaway is straightforward. Existing behavioral detection, cloud-based sandboxing and endpoint analytics catch these threats using the same mechanisms that stop conventional malware," it said. "The AI component does not evade detection. It changes how the code is authored, not how it executes."
  • Rogue Pornographic Android Apps Lead to Financial Fraud — The Indian Cyber Crime Coordination Center (I4C) warned that malicious Android applications masquerading as pornography apps under the names Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa are being used to disseminate a banking trojan capable of carrying out financial fraud. These bogus apps are circulated through Facebook and Instagram ads and instruct victims to sideload the APK file. "After installation, the app requests permissions that allow it to install additional applications and, by abusing accessibility permission, take control of the users' device, which may result in financial fraud," I4C said. "Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious/criminal activity. The app may prevent users from uninstalling it through the device settings." Details about the KYSS malware were published by security researcher Rudra Ponkshe in July 2026, describing it as a trojan designed to perform overlay attacks against 19 targets across Japan and Latin America, as well as abuse Android's accessibility services to grant itself extensive permissions, exfiltrate photos and contacts, and issue commands for subsequent execution.

Conclusion

The useful lesson is not that every attack became smarter. It is that more of them arrived through things already trusted: shipped devices, familiar prompts, support tools, valid access, and systems meant to protect the network.

That changes the question. “Is it working?” is no longer enough. Ask what else it can do, who else can reach it, and whether the evidence it produces can be trusted. Quiet systems deserve a second look.



from The Hacker News https://ift.tt/Nz7JREL
via IFTTT

Secure by default is your only way forward

Every worker a company employs, be it a person or a program, builds on a foundation someone else assembled, and that includes the newest hire on your team. This new hire got to work the moment they arrived, building with what your company already has in place and they’re shipping code at a pace your reviews can’t keep up with. Also, everything they make is going out under your name. If it were a human, they’d spend the first week asking where things live and who maintains what. This one never asks. It treats everything it finds as trustworthy, so everything it builds carries that unexamined trust forward. And because this new hire is an agent that’s working all night at machine-class throughput, the foundational problems that used to surface slowly now surface all at once.

The foundation that nobody audited

The line between a supply chain attack and an AI attack no longer exists. Take a look at what the average foundation holds, because most of it comes from outside the company. For a long time now, public base images have carried hundreds of packages that your application never uses. Every one of those packages adds to the attack surface. Almost none of them ever get reviewed because no team has time to read code it didn’t choose and doesn’t use. In most stacks, something like a ten-year-old Java service is keeping the business running on software whose maintainers stopped patching years ago. Platform teams have been coping in their own ways, usually with a golden-image program somebody built years ago and a scanner pointed at it all. Because the images underneath are so bloated, that scanner cries wolf about four hundred times a week. All of this together is why audit season now eats up most of a quarter.

Attackers know all of this, and they’ve been working on the foundation layer all year. They’ve poisoned packages and developer tools, and they’ve had real success harvesting coding-assistant credentials at scale. Most foundations were built for a world that no longer exists.

What a good foundation takes

The good news is that none of this is unsolvable. A foundation can be strengthened to carry what’s now being built on top of it. It has to meet a few requirements, and each one depends on who does the security work, because when the vendor doesn’t, your team picks up the slack. A foundation holds when every part of it is built from source by someone who signs the work and stands behind it. Nothing should ship that your application doesn’t need, because anything extra adds surface area to defend later. Patching needs the same treatment because new vulnerabilities keep landing no matter how clean an image starts. A fix should come with contractual backing and a date. You should know exactly what’s inside every image the day it ships. And none of this should force you to move your stack onto a different distribution just to get safer images. A migration like that becomes a quarter-long project in its own right, and the foundation can’t protect anything until the move is complete.

This is exactly what Docker Hardened Images were built for. They stay compatible with the Alpine and Debian images teams already run, so adoption amounts to a one-line change to the FROM line in your Dockerfile, with no migration project attached. The images are also minimal by design, carrying only what your application needs, which reduces the attack surface by up to 95% and leaves near-zero critical and high CVEs from day one. The difference is immediately visible in scanning. Scans complete much faster with low noise, and the few findings that do remain are worth directing the team’s attention to. When a CVE does get disclosed, the remediated image is available within seven days of the upstream fix, and what once consumed a sprint of engineering time closes as a pull request. The same evidence carries through to audits, which most organizations will eventually face. Every hardened image ships with a signed SBOM (Software Bill of Materials) and build provenance, a verifiable record of the image’s contents and build process. You present auditors with proof that already exists, and no one needs to spend weeks reconstructing it.

Furthermore, a hardened base image by itself may not be enough, because minimal images almost always need customization before they fit production workflows. Teams add their own CA certificates and init scripts, install additional system packages through apt and apk, or adopt separate products entirely to cover what the base image cannot, fragmenting their foundation across vendors. That’s usually where a hardened foundation breaks down, because customizing an image invalidates the provenance and the SBOM, and with them the assurances you paid for. Not with Docker.

Hardened system packages give everything you add the same built-from-source treatment, ensure your customizations run through the same hardened pipeline, and keep the guarantees intact, with the SLA still behind them. With Docker, the entire foundation stays within a single ecosystem.

One thing stays inevitable no matter how well you do all of this. The software you depend on will eventually go unsupported upstream, and without coverage, the security patches stop, and the compliance answers get harder every quarter. Extended Lifecycle Support closes that gap with commercially backed patches for up to five years past end of life, so the move to whatever comes next happens on your timeline and your terms, instead of upstream’s. That is what a solid foundation looks like, and it has never mattered more, because your newest employee, the agent, is stress-testing what everyone before it built.

The new layer

Agents build on this foundation the same way every human before them has, and the trust it carries passes into what they build. But there’s a new reality now. Agents have created a new layer on top, and it matters almost as much as the foundation itself. They pull packages from the foundation and wire tools together, running what they build as soon as it exists. They’re also non-deterministic and ephemeral. The same task can go differently every run, and the agent session that did the work no longer exists by the time anyone comes back with questions.

Every control in the standard stack was built for a human worker, one with a permanent identity and a predictable pace, whose work can be reviewed before it ships. Agents have none of those traits. The market’s first response was to ask for human permission before every agent action, and when the prompts got too cumbersome, teams moved to isolating agents. That created its own gap because the endpoint tools meant to watch the work sit on the host, and the more you isolate the agent, the less those tools see. There has never been a control surface built for a workflow like this, and retrofitting the old parts leaves teams stuck between prompt fatigue and blind spots.

So Docker built the missing layer, one that adds to your defense in depth without replacing anything you already run. At Docker, every agent session runs in its own disposable, MicroVM-based Docker Sandbox. The sandbox walls the agent off from the host at the operating-system level. Credentials get proxied in for the task at hand and never stored inside, and you decide what gets piped in and out of the box. Our own security team has blocked coding agents on the host outright and runs them in sandboxes with full autonomy, several at a time. An infostealer that lands in one of those boxes finds nothing to grab. Call it YOLO mode with guardrails.

The tools agents reach for are the next layer, built on the same foundation. Agents interact with the outside world through MCP (Model Context Protocol) servers, connectors that let them call external tools and access data. An agent grabbing connectors off the open internet is the package problem all over again. So Docker ships hardened MCP servers through the same catalog as the hardened images, built and signed the same way. The MCP Catalog and Toolkit give your teams one trusted place to find and run them. Every tool call routes through the MCP Gateway, where it is authenticated, authorized, and logged before reaching the external system. That turns enforcement from advisory to strict. 

Docker Scout enforces the policy at build time, so the secure path remains the default without anyone having to police it by hand. And where the box sits stops mattering, whether it’s a laptop or the cloud, because the boundary travels with the work, as Docker containers always have.

The winning playbook already exists

Docker wrote this playbook the first time. In the 2010s, software pulled in parts its builders didn’t control, and shipping outpaced review. Slowing down was never on the table, so Docker packaged the application and its dependencies into one portable, isolated unit, and speed and safety started pulling in the same direction. That bet is a large part of how the modern software supply chain took shape, and now we’re making it again for agents. One foundation and one boundary serve people and agents on the same supply chain, under the same policy. Security gets quieter, and development gets faster. There’s no separate AI security program to buy. Docker has been making the case that security is a developer experience problem from the start.

See it live in San Jose

We’re bringing all of it to WeAreDevelopers World Congress in San Jose, September 23 to 25. Docker’s CISO Mark Lechner will take the stage with One boundary for the agentic era, the boundary his own team lives inside, and the Docker Zone will run live demos all three days.

The newest hire starts Monday either way. What will you have ready for them to build on?



from Docker https://ift.tt/pwvHnLa
via IFTTT

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.

AI has moved from the browser tab to the endpoint with harnesses like Claude Code. They run on developers' machines, execute bash commands locally, and connect to third parties via MCP servers, skills, and plugins. All this so the user can outsource labor to the machine and focus on designing, thinking, and creating.

Local agents are not a niche category. They account for 68.6% of the AI agents Token Security discovers in customer environments, and they often inherit the employee's credentials, network position, and permissions.

The shift to the endpoint has major implications for security. With Claude Code, there is no centralized console to monitor endpoint agents across local configurations, identity and access, and runtime. Before August 2026, Anthropic's native controls had limited visibility into what those agents were actually doing, forcing teams to use third-party extensions just to achieve the bare minimum of governance.

With the new local session transcript endpoints in the Anthropic compliance API, you can better govern your local agents while understanding which limitations still exist.

A harness is not a chatbot

A harness is a sophisticated orchestrator. It takes user input and sends it to the LLM along with the full session context. The LLM itself doesn’t maintain state; it receives everything it needs from the harness to respond on an ad hoc basis. The component that actually runs commands, authenticates to third parties, and connects to MCP servers is the harness, not the LLM.

Compare an endpoint agent to a human body. The LLM is the brain: it processes the data and calls the shots. Everything else is the harness, from the hands and the legs to the sensory organs. It's a weird hybrid, and our security model has to adapt to fit it. The brain runs in Anthropic's cloud, but the hands run on your endpoints, and that is where your visibility and control have to live.

Unorthodox design

It’s en vogue to say that SaaS is dead, and it's a little SaaD, because classic SaaS took care of a lot of things for us. We expect a service to let us manage and monitor our enterprise from a central dashboard, control organizational policies, and clearly see what the agents within our enterprise can do.

That is not the case with local harnesses. Claude Code challenges the classic shared-responsibility model and puts more load on admins. In a Token-commissioned Cloud Security Alliance survey of 418 IT and security professionals, 68% rated their visibility into AI agents as high. In the same survey, 82% had discovered an agent in the past year that security, IT, or governance did not know existed.

Riddle me this: I live on your host as an agent, but I was here long before any LLM. I know more about your Claude Code than Anthropic does, because endpoints are my realm.

Because much of Claude Code’s execution happens locally, endpoint telemetry can reveal processes, files, and configurations that cloud services cannot see. But EDR provides evidence, not a governance model. It cannot connect an agent’s activity to its owner, intent, credentials, and permissions.

Anthropic's own tooling helps, but it isn't enough to prevent LLMs from performing destructive actions, even if those actions may be legitimate. There are three key layers for gathering data to govern local AI agents effectively. You need to understand what Anthropic gives you, what only an endpoint agent can collect, and what you need to do with the data.

Layer 1: Managed settings, the policy baseline

Anthropic's enforcement mechanism is managed settings. Every endpoint that installs Claude Code has a managed-settings record: a JSON file on Mac and Linux, and registry records on Windows. Its rules take precedence over global, project, and user settings, allowing you to enforce a baseline over every Claude Code session in the organization. On a Claude Code enterprise plan, you apply policies through the GUI; without one, your MDM can write the managed-settings record across endpoints.

The available rules cover a lot:

  • Allow and deny lists for specific MCP servers

  • Regexes over bash commands

  • Disabling skills from running commands, and more

They help, but they take a lot of maneuvering room away from your developers, and static allow/deny policies aren't built for the pace of modern AI. Worse, they don't know context or intent. In effect, they're a big boulder in the middle of a river, disrupting the stream but not stopping it.

Layer 2: The Compliance API

Until recently, Anthropic's Compliance API mainly covered claude.ai actions, meaning activity from the web interface and Claude Desktop, with very thin coverage of Claude Code. On August 11, 2026, Anthropic introduced new endpoints for local sessions:

Endpoint Returns
GET /v1/compliance/apps/sessions/local list of session metadata
GET /v1/compliance/apps/sessions/local/{session_id} one session's metadata
GET /v1/compliance/apps/sessions/local/{session_id}/messages the transcript

These give you visibility into agents running on endpoints, based on their interaction with Anthropic's models. Whatever is communicated to the model is logged in three block types: text, tool_use, and tool_result. Between them, they cover user prompts, bash commands, reads and writes, and even MCP commands.

The model holds no state server-side. The skill and plugin .md files only exist on the endpoint, so the harness resends the full context to the model on every turn. Anything that reaches the model reaches the Compliance API, which is pretty amazing for governance and monitoring.

Parsed the right way, session transcripts let you log tool usage and build an inventory of your agents: each one's skills, the MCP servers it uses, and its plugins.

The Compliance API also covers administrative actions, mostly at the organization level and less so for individual users changing configs. I expect that to widen over time.

Why you might still need OpenTelemetry

OpenTelemetry (or OTel) is an open-source standard for traces, metrics, and event logs, and every common harness has it built-in, only needing to be configured.

Some actions on the endpoint never reach the LLM, so the Compliance API never sees them. Hooks are the clearest case: they run locally, between the model's decision and the tool actually running, and can block a tool from executing or a prompt from being sent.

OTel also records tool-permission decisions and who made them, whether a policy, a hook, or the user waving it through. Also, permissions changes moved into bypassPermissions / auto mode will be logged in OTel but not the compliance API.

Transcripts vs. logs

OTel was built for logging atomic actions. Session transcripts are long, deeply descriptive JSON with no verbosity dial, and you have to process them to get the same logging outcome. If you don't want to collect and store extremely dense transcripts, OTel might be the easier tool (until a better one exists).

And there’s a hard boundary: If you run Claude Code on a model that isn't Anthropic's, you get no Compliance API coverage at all, because it only logs interactions with Anthropic's models. Sessions running on Bedrock, Foundry, or Google Cloud won't be covered.

One important note: local session transcripts can contain sensitive data, including PII, secrets, and customer data. Their storage becomes a sensitive data source in its own right. Treat it like one.

Layer 3: What only the endpoint can tell you

The Compliance API and OTel capture what agents DO. Neither can see what sits on disk: config files, installed skills and plugins and their .md files (unless they were used in a session), or processes launched outside a session. This is where an endpoint agent earns its keep. Harvest config files, retrieve skill and plugin .mds, and correlate EDR logs to catch risky bash commands coming from agents. Token Security finds an average of more than 10 configuration files per local agent, scattered across the endpoint.

One more thing lives on disk that you can also pull from the Compliance API: session transcripts. Claude Code stores all session history locally for 30 days by default, so users can quickly resume previous work. A malicious actor who gains access to the endpoint can also read those files, so the same caution applies.

Don't forget transcripts when you build a coverage plan. Start with responsible use: keep users from writing raw secrets into sessions, label projects and sessions that hold customer or sensitive data, and delete them on a schedule. Then add detection and response: find user prompts that contain cleartext secrets, and act on sessions that could compromise customer data.

A little about parsing transcripts

To get atomic-action logging out of your Claude Code sessions, you process the Compliance API transcripts. As above, each message is only text, tool_use, or tool_result, wrapped in fields like user, assistant (the LLM's responses), and more. Finding the actual plugins, skills, and MCP servers takes a few extra techniques.

Bash commands

The easy case: every command shows up as a tool_use with "name": "Bash", and the full command line sits in the input value.

MCP servers

These appear as a tool_use whose name is mcp__<server>__<command>. First-party servers use readable names, so you can often tell the type at a glance: Jira, Slack, Notion. User-connected servers show up as a UUID instead, and you recover the service from the command suffix (slack_send_message) or from a UUID-to-name map you maintain.

Every one of these represents a standing credential on that endpoint, and roughly a third come from outside the vendor ecosystem: 35.1% of MCP servers Token Security discovers are community-built or of unknown origin.

Skills

Skills aren't named in a field the way MCP commands are, but you can infer them. When a skill fires, the LLM can't use it without context, so the harness sends the SKILL.md over the API, either by injecting the skill content directly or by issuing a Read on its path. That Read gives away both the skill name and its location: the tool_use input holds the path, and the tool_result text holds the skill's content.

Plugins

Plugins are harder, because a plugin isn't a single file. It bundles different extension types, including skills and scripts. You recover plugin names through path conventions, when one of a plugin's script or .md files is Read into context.

All of this works without touching user prompts, on tool_use blocks and command lines alone.

Managed settings + local session transcripts + endpoint collection = Good but not enough

Claude Code's design creates challenges that no single layer can answer. Together, the three do a better job, but still fall short:

Layer Primary role What it misses
Managed settings Enforces static policy baselines Dynamic execution context
Session transcripts Retained per-session action records, retrieved on demand Offline local configurations
Endpoint / EDR Collects static configs and logs local processes LLM-specific semantic context

Even all three are not enough because none of them captures the context of your enterprise, and they don’t go deep enough in tying access to intent. An admin reviewing the transcripts can't tell the difference between a malicious plugin pulled from the internet and a legitimate one written by an engineer. Closing that gap requires context from elsewhere in the organization, such as correlating the skills and plugins running on endpoints with those your internal repositories actually manage, which increases legitimacy. Once you have that context across the org, detecting a single malicious skill gives you a heat map of where it runs, and mitigation moves fast.

Telemetry can show what happened. Governance requires connecting those signals to an agent’s owner, purpose, identities, credentials, permissions, and access paths. That context makes it possible to determine whether access is justified, right-size it to least privilege, and revoke it when the agent’s purpose ends. Identity is the control plane that turns endpoint and session data into enforceable AI agent security.

Learn how Token secures AI agents across endpoints, cloud, SaaS, and developer environments with a quick demo, anytime.

Note: This article has been expertly written and contributed by Dan Abramov, Security Researcher.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/TC9YuN0
via IFTTT

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Executive Summary

Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring.

What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC).

We provide a technical breakdown of this operation’s attack lifecycle across two observed campaigns, both illustrating vishing manipulation that resulted in the attempted payload delivery via two distinct attack vectors.

These two campaigns demonstrate the weaponization of communication platforms as identity becomes a primary attack vector.

Palo Alto Networks customers are better protected from the threats described here through the following products and services:

If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.

Related Unit 42 Topics Phishing, Identity, Social Engineering

Overview: The Trust Gap

Spring Ring’s activity mirrors a broader trend in the threat landscape toward social engineering campaigns. According to our recently published Insights blog, threat actors have increasingly moved away from traditional phishing techniques toward trusted collaboration tools.

In the first four months of 2026, phishing alerts from collaboration tools represented 42% of all phishing alerts in Cortex, up from 30% of all phishing alerts in the preceding four months. In addition, according to KnowBe4’s Phishing Threat Trends Report, Teams-based attacks rose by 41% [PDF] between October 2025 and March 2026. They note that this surge is driven by attackers exploiting the platform's default “Chat with Anyone” feature to initiate direct chats with users outside their organization.

Previous Teams-based attacks, such as those by Cloaked Ursa (aka APT29), focused on credential harvesting and group chat-based social engineering. They often relied on malicious links or fake Entra ID tenants to appear legitimate.

Spring Ring’s approach relies on active human voice interaction. In this way, attackers can evade detection without a software exploit. Instead, they rely on exploiting the trust that employees place in software as a service (SaaS) collaboration platforms.

SaaS Applications: The New High-Value Target

SaaS applications are essential for business operations, storing an organization’s most critical and sensitive data. Unlike email, where users are trained to look for external sender banners or suspicious links, communications platforms provide a closed loop that attackers exploit by:

  • Leveraging platform trust: People are more likely to engage with a message from a help desk identity than a random email from an external domain
  • Exploiting human interaction: A professional voice on an audio call creates a level of trust that is difficult to manufacture in text, making the victim more susceptible to manipulation
  • Bypassing the monitoring gap: Voice calls are often less monitored, recorded or documented than employees’ digital file operations or email histories, providing attackers with a secluded environment to execute their lures

The Evolution of Collaboration Attacks

The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow. This shift moves the attack from a passive click-and-harvest model to a real-time engagement.

Attackers can then pivot based on the victim's responses. Once the trust gap is crossed, the path to domain-level privileges via open-source tools like PetitPotam is short.

Figure 1 shows an example of the warning that Teams users get when an external identity creates a chat with them.

A screenshot of Microsoft Team's notification about being added to a group chat. A warning message indicates the person is from outside the organization, advising caution against sharing account information. Options to "Delete" or "Accept" are available.
Figure 1. External chat created, Delete/Accept screen.

Anatomy of Spring Ring: How Attackers Masquerade as Internal Support

The Spring Ring campaigns are a coordinated operation that relies on impersonating corporate IT structures. Attackers can drop their lures into a victim's primary communication channel using external Microsoft Teams accounts.

The Discovery: Spotting the Pattern

Our investigation into this activity began after the release of a new detection suite for Microsoft Teams. By monitoring these alerts, we identified a suspicious pattern of chat creation across multiple tenants. Further investigation into these alerts led to the initial discovery of 26 distinct identities approaching targets across different organizations.

The Initial Hook: Crafted Personas and Domains

The attack begins with creating a Microsoft Teams chat using identities designed to mirror legitimate internal support units. The attackers opt for professional, urgency-focused display names such as help desk, IT assistance or support staff.

To strengthen the impression of legitimacy, the attackers operate from external .onmicrosoft[.]com tenants. These are meant to resemble legitimate corporate infrastructure. They are used by attackers to provision Microsoft 365 tenants. The subdomains are controlled by the adversaries.

Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised. Unit 42 has no evidence of any compromise or vulnerability within Microsoft's product related to this campaign.

Here are examples of these subdomains:

  • ithelp@InternalSystemsDaily[.]onmicrosoft[.]com
  • HelpDesk@ITProtectionDepartment[.]onmicrosoft[.]com
  • itadmin@MandatoryNetworkMonitoring[.]onmicrosoft[.]com
  • Internal@InternalUSAHelpDeskIT[.]onmicrosoft[.]com
  • ithelpdesk@CertifiedUpdateNetwork[.]onmicrosoft[.]com

In some instances, the actors went beyond generic role names and used specific names to increase the perceived authenticity of the technician on the other end of the line:

  • patrick[..]@infrastructureopsdesk.onmicrosoft[.]com
  • robert[..]@systemdeploymentcenter.onmicrosoft[.]com
  • clara[..]@systemsupportoperations.onmicrosoft[.]com

Names have been partially redacted because the attackers used specific names of legitimate industry personnel. The use of these names does not indicate a compromise of their accounts.

After the chat is created, the attacker initiates a voice call (the vishing element) to coerce the victim. After establishing a connection with what the victim believes is their own IT department, the attacker guides targeted employees through the steps to grant them remote control or execute malicious payloads.

The Scale of Spring Ring

Our telemetry reveals that these attackers often make several attempts — including leaving voicemails — before establishing a connection. We observed the attackers engaging victims in calls that varied in duration:

  • Many calls last only a few seconds or they are missed by the victim as the attacker cycles through targets
  • Successful calls often last between 10 and 15 minutes

Figure 2 shows several vishing attempts made by the same attacker identity on six different targets, with different conversation durations.

A screenshot of a table showing attacker call logs. Columns include Attacker Identity, Display Name, IP, and Call Duration. All Attacker Identities and Display Names are the same, with an IP address from Mullvad. Call Duration includes completed calls, missed calls, and voicemail, with times listed in hours, minutes, and seconds.
Figure 2. Examples of an attacker initiating calls with different targets, and different time durations.

The reach of these campaigns is significant:

  • More than 10 tenants were attacked: We observed the campaigns targeting many organizations across different industries
  • More than 150 targets were approached: The attackers contacted more than 150 individual employees
  • Persistent activity: We tracked the campaigns since January 2026 over a period of several weeks. According to our telemetry, these campaigns were active up until April 2026.

Technical Deep Dive: The RMM and Custom Dropper Combination

Once the attacker establishes trust through the initial vishing call, the Spring Ring campaigns transitioned into a technical execution phase designed to gain a permanent foothold. We provide a detailed analysis of two campaigns (Campaign A and Campaign B) that both began with a Microsoft Teams lure. They then diverged in their payload delivery, tool complexity and post-compromise activities.

Figure 3 shows the full attack flow of the two campaigns' attack methods.

a diagram illustrating Spring Ring attack flow, starting with creating a chat lure in Microsoft Teams. Two campaigns are shown: Campaign A leads to convincing the target to download RMM tools, then downloading obfuscated PowerShell-based malware. Campaign B involves convincing the target to download malware from a cloud endpoint, leading to persistence and environment enumeration, followed by attempted lateral movement using PetitPotam.
Figure 3. Full attack flow of the two Spring Ring campaigns.

Campaign A: From Support Tools to Obfuscated Payloads

In Campaign A, the attacker used a bring-your-own-tool approach, luring the victim to execute legitimate RMM software. The attacker posing as a technician walked the employee through launching built-in Windows tools like Quick Assist or downloading third-party RMM software. Once the RMM tool ran, the attacker could request remote control of the victim’s machine.

After gaining remote control, the attacker performed a series of basic enumeration commands to gain information on the host and domain. We observed them executing:

1

2

whoami /groups

net group /dom

After confirming the environment's value, the attacker pivots to payload delivery. The attacker used a PowerShell command line to download an obfuscated PowerShell-based remote access Trojan (RAT) from the attacker-controlled domain, san-sid[.]com. This malware used variable manipulations and arithmetic obfuscation designed to evade automated security analysis and sandbox detection.

By leveraging advanced AI and pattern-matching algorithms, we were able to de-obfuscate the RAT. We started by stripping away anti-analysis bloat from the code that was used to cause a time-out for deobfuscation tools.

The actual payload is a tiny, nine-line command and control (C2) stager. The script disables Antimalware Scan Interface (AMSI) via the amsiInitFailed flag and executes a test scan to verify the bypass. Upon verification, the script encrypts host data and beacons out to san-sid[.]com to download and execute further payloads.

Figure 4 shows a snippet of the obfuscated PowerShell-based RAT.

A screenshot of the obfuscated PowerShell-based RAT code snippet with various programming elements such as loops, conditional statements, and arithmetic operations. The code includes variable names, mathematical calculations, and logical operators.
Figure 4. A snippet from the obfuscated PowerShell-based RAT.

This campaign was blocked by automated Cortex XDR Agent protections during the malware's execution phase.

Campaign B: The Tailored Cloud Execution Chain

The second campaign used a more customized delivery method. During the vishing call, the attacker directed the victim to a cloud endpoint. The attackers tailored the cloud infrastructure and filenames to match the targeted organization and the specific user, for example:

<company_name>-org-filters-update-<victim_name>.s3.us-west-2.amazonaws[.]com

When the victim clicked a link containing their own company's name and downloaded <company_name>-org-filters-update-<victim_name>[.]exe, it triggered an execution chain:

  1. Staging and persistence: The executable moved itself to the \Temp\ directory and spawned copies (e.g., vhlp-*.exe and scnr-*.exe) as a persistence mechanism
  2. Browser hijacking: The malware launched a hidden, headless instance of Microsoft Edge, and the attackers wrote to the disk and sideloaded an Edge extension
  3. Lateral movement and authentication coercion: The attackers used Python (C:\ProgramData\IntegrityData\python.exe) to initiate a lateral movement sequence:
    1. SMB scanning: Initiated port 445 traffic targeting internal servers
    2. NTLM authentication: Generated NTLM traffic targeting the organization's DC
    3. PetitPotam exploitation: The attacker attempted a PetitPotam attack to coerce the DC into authenticating back to an attacker-controlled machine. This NTLM relay attack was designed to grant the attacker domain-level privileges

After attempting to coerce the DC, the attacker's domain-takeover attempt was blocked by Unit 42 Managed Detection and Response.

Summary of Tactical Divergence

By comparing the two campaign paths, we can better understand the diversity of threats targeting collaboration platforms. Table 1 compares the campaigns' specific methods of attack.

Feature Campaign A Campaign B
Initial Lure Microsoft Teams vishing Microsoft Teams vishing
Primary Delivery RMM tools Tailored hosting infrastructure executables
Stealth Mechanism Obfuscated PowerShell Headless Microsoft Edge and sideloaded extension
Lateral Movement Basic enumeration only PetitPotam NTLM relay

Table 1. Comparing the two campaigns’ methods.

This comparison highlights an important point for defenders. A simple vishing hook can lead to either a standard malware infection, or to a serious domain-level breach if the attacker pivots to payload delivery.

Identifying Teams Impersonation and Identity-Based Anomalies

Recognizing campaigns like Spring Ring requires a strategy of profiling external and internal entity behaviors. The attackers behind these campaigns operate within a legitimate ecosystem, so detection hinges on identifying small anomalies in how external identities interact with your organization.

Profiling the Identity

The first line of defense is recognizing the markers of the external actor. Our research into these campaigns highlights several consistent patterns:

  • Spoofed domain naming: Attackers mostly use external .onmicrosoft[.]com tenants that include keywords like internal, certified, network or infrastructure to project authority
  • Persona mimicry: They use professional display names, like IT help desk or admin, to increase the perceived authenticity of the technician during vishing calls
  • Infrastructure red flag: The source IP addresses for these connections often originate from commercial VPN services to mask the attacker's true location

Behavioral Metrics of the Interaction

Our researchers were able to identify key markers of Spring Ring activity by analyzing the metadata of these interactions, despite the deceptive nature of the attacker’s initial lures:

  • The chat-to-call ratio: A primary indicator is the rapid transition from a 1:1 chat request to an unsolicited audio call
  • Call curation profiling: Attackers cycle through targets quickly. We observed call patterns ranging from 30-second initial attempts to 15-minute sessions.
  • Multiple approaches: These actors demonstrate high operational volume, often approaching 5-6 identities within a matter of minutes using one of their spoofed identities

Recognizing Post-Compromise Behavior

Upon a successful compromise, we observed endpoint activity characterized by:

  • Atypical execution of RMM tools by users who do not require remote support
  • Access to unknown links, including cloud storage URLs or other file hosting servers that victims might be lured to access

Organizations can identify the Spring Ring lifecycle before the attacker transitions from a chat to a domain-level attack, by profiling these signals, the origin of the tenant and the subsequent attack flow.

Figure 5 shows one example of a Cortex alert on a new suspicious conversation created in Microsoft Teams. This alert is based on behavioral and metadata analysis of a newly created chat.

A screenshot of a Cortex alert in an application interface. The alert is titled "An external user started a conversation in Microsoft Teams with a suspicious user or chat name." It shows details like the description of the incident, occurrence count, and affected assets. The description mentions a user creating a Microsoft Teams chat with two users in the organization. Status and assignee fields are visible, but not filled. Other tabs include Overview, Resolution, War Room, and XDR Analytics.
Figure 5. Example of a Cortex alert on the creation of a suspicious chat in Microsoft Teams.

Conclusion

The Spring Ring campaigns demonstrate a strategic pivot in social engineering, where attackers move beyond email phishing to enterprise collaboration tools. Attackers turn an important productivity tool into a conduit for domain-level exploitation, masquerading as internal help desk personnel through vishing calls.

This activity highlights an important shift in the security landscape. Identity is now a primary perimeter, and the platforms we rely on for daily communication are being weaponized.

Looking forward, attackers might further refine their ability to operate within SaaS ecosystems. These platforms are not just an initial access vector, they contain sensitive documentation, workflows and communication logs that could allow an adversary to advance their attack chain.

Our analysis of the Spring Ring operation reinforces several key lessons:

  • Trusted SaaS applications are not inherently safe: Attackers exploit the confidence that employees place in communications platforms
  • Attack vectors are simple and scalable: By using seemingly legitimate external tenants and professional vishing lures, attackers can target hundreds of employees across many industries with minimal friction
  • Adaptability is key: Attackers are evolving their methods, shifting from basic credential harvesting to human-led lateral movement

As these threats evolve, organizations must prioritize user education regarding unsolicited external communication across collaboration platforms. Robust behavioral monitoring can help identify identity-based anomalies before they escalate to lateral movement.

Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

  • Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious.
  • Cortex XDR and XSIAM can help prevent the execution of both known and unknown malware through Behavioral Threat Protection and machine learning powered by the Local Analysis module. Beyond stopping initial execution via malicious droppers, Cortex XDR actively halts post-exploitation activities, such as PetitPotam NTLM relay attacks, before adversaries can achieve lateral movement.
  • Cortex Cloud Identity Threat Detection  can help deliver real-time protection against identity-based threats across cloud providers, IdPs, and SaaS applications. Using advanced behavioral analytics on real-time telemetry, ITDR baselines access patterns to detect anomalies, track complex attack chains—such as the Spring Ring lifecycle and trigger automated responses to contain compromised credentials.
  • The Cortex Advanced Email Security module can help extend the power of the Cortex platform into cloud-hosted email environments, providing a scalable, AI-driven layer for detection, investigation, and response. By automatically stopping email threats and malicious communications across enterprise environments, it provides seamless protection across one of your most vulnerable attack vectors.
  • Idira Threat Detection and Response can help enable security teams to counter identity-based attacks targeting Idira Next Generation Identity (NGI) Platform and the identities it secures. Using near real-time detection, powered by CORA AI, and leveraging Idira’s visibility across multiple contexts (like PAM, authentication, SSO, cloud, endpoints, browsers, and more), Idira ITP can apply automated, tailored non-disruptive in-session response to contain and minimize potential identity-based threats.
  • Idira Endpoint Privilege Manager can help enable enterprises to reduce risk, satisfy compliance, and streamline operations. It helps implement least privilege via policy-driven elevation and removal of standing admin rights, and blocks risky actions, such as execution of unvetted applications and access to memory of other processes, while providing audit-ready evidence and unified identity governance. Automation and consolidation improve efficiency and support Zero Trust strategies, strengthening security without slowing the business.
  • Idira Privileged Access Management can help unify privileged access across human, machine, and agentic identities to secure cloud access across multi-cloud environments. Building on proven PAM, it delivers centralized secrets management alongside modern controls like Just-in-Time access and Zero Standing Privileges. This enforces consistent least-privilege security across on-premises, cloud, and SaaS targets.
  • Idira Secure Infrastructure Access can help enforce Zero Standing Privileges (ZSP) through Just-in-Time (JIT) provisioning which grants temporary, tightly scoped access only as needed. Backed by continuous session recording and real-time command monitoring, SIA can detect high risk actions before an attacker compromises critical systems.

If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call:

  • North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
  • UK: +44.20.3743.3660
  • Europe and Middle East: +31.20.299.3130
  • Asia: +65.6983.8730
  • Japan: +81.50.1790.0200
  • Australia: +61.2.4062.7950
  • India: 000 800 050 45107
  • South Korea: +82.080.467.8774

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance.

Indicators of Compromise

Attacker Identities Used in Vishing Attempts – Generic

  • helpcenter@ithelpcenter365[.]onmicrosoft[.]com
  • helpdesk@itprotectiondepartment[.]onmicrosoft[.]com
  • helpdesk@newsystemmaintenance[.]onmicrosoft[.]com
  • helpdesk@officedesk365[.]onmicrosoft[.]com
  • helpdesk@officesecures[.]onmicrosoft[.]com
  • helpdesk@tbcsschid[.]onmicrosoft[.]com
  • internal@internalusahelpdeskIT[.]onmicrosoft[.]com
  • it_assistance@teams0137[.]onmicrosoft[.]com
  • it@infrastructurefirewall[.]onmicrosoft[.]com
  • itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com
  • itassistant@bilelonellc[.]onmicrosoft[.]com
  • ithelp@certifiednetworksec[.]onmicrosoft[.]com
  • ithelp@internalsystemsdaily[.]onmicrosoft[.]com
  • ithelp@itprotectiondepartment[.]onmicrosoft[.]com
  • ithelp@mandatorynetworkmonitoring.onmicrosoft[.]com
  • ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com
  • support@bilelonellc[.]onmicrosoft[.]com

Attacker Identities Used in Vishing Attempts – Usernames

Names have been partially redacted to protect the users associated with accounts that were impersonated by the attackers.

  • andreas[..]@idigitalserviceoperation.onmicrosoft[.]com
  • andrew[..]@hapsinfrastructureops.onmicrosoft[.]com
  • brandon[..]@devsitoperationhub.onmicrosoft[.]com
  • brian[..]@appssupportsys.onmicrosoft[.]com
  • christopher[..]@adevpsitplatformops.onmicrosoft[.]com
  • christopher[..]@itplatformops.onmicrosoft[.]com
  • christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com
  • clara[..]@systemsupportoperations.onmicrosoft[.]com
  • daniel[..]@opsnetsupportit.onmicrosoft[.]com
  • daniel[..]@apsitsupporthub.onmicrosoft[.]com
  • emily[..]@apsitechsupportdesk.onmicrosoft[.]com
  • eric[..]@appopshelp.onmicrosoft[.]com
  • henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com
  • james[..]@helpitsupportcore.onmicrosoft[.]com
  • james[..]@itcoretechhelp.onmicrosoft[.]com
  • jonathan[..]@itservicedesk.onmicrosoft[.]com
  • justin[..]@techopshelpsupp.onmicrosoft[.]com
  • kevin[..]@itopsupportdesk.onmicrosoft[.]com
  • kevin[..]@netopsdeskhelp.onmicrosoft[.]com
  • leon[..]@netcorevdapp.onmicrosoft[.]com
  • lucas[..]@applicationoperationsunit.onmicrosoft[.]com
  • martin[..]@syslanevdapp.onmicrosoft[.]com
  • matthew[..]@supportopsupp.onmicrosoft[.]com
  • michael[..]@appdeploymentservices.onmicrosoft[.]com
  • michael[..]@infratechopsdesk.onmicrosoft[.]com
  • michael[..]@itopsdeskhelp.onmicrosoft[.]com
  • patrick[..]@infrastructureopsdesk.onmicrosoft[.]com
  • rachel[..]@ioseccloudsupport.onmicrosoft[.]com
  • rebecca[..]@infrastructureopsservice.onmicrosoft[.]com
  • robert[..]@systemdeploymentcenter.onmicrosoft[.]com
  • ryan[..]@apstechopsdeskdev.onmicrosoft[.]com
  • ryan[..]@helpssupportcloudops.onmicrosoft[.]com
  • ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com
  • sarah[..]@secinfrahelpdesk.onmicrosoft[.]com
  • sarah[..]@apsscloudopsdesk.onmicrosoft[.]com
  • sarah[..]@helpitdevsupportops.onmicrosoft[.]com
  • sarah[..]@itdevsupportops.onmicrosoft[.]com
  • scott[..]@cloudinfrastr.onmicrosoft[.]com
  • steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com
  • thomas[..]@networkoperationsec.onmicrosoft[.]com
  • thomas[..]@seqapsitsupportops.onmicrosoft[.]com

Infrastructure Used in Vishing Attempts (VPNs and Proxies)

  • 193.32.248[.]251
  • 193.138.7[.]142
  • 185.65.134[.]209
  • 178.130.47[.]46
  • 5.181.3[.]106
  • 2.56.172[.]214
  • 185.234.67[.]53
  • 45.8.157[.]185
  • 80.66.72[.]215
  • 136.0.20[.]6
  • 185.213.155[.]226
  • 185.155.99[.]161
  • 92.118.232[.]131
  • 45.182.189[.]80
  • 185.65.133[.]51
  • 45.33.22[.]47

Malicious Files From Post-Compromise Activity (Campaign A)

  • SHA256 hash: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b (obfuscated PowerShell payload)

File description: Obfuscated PowerShell RAT dropper downloaded via Invoke-WebRequest

  • URL: hxxps[:]//san-sid[.]com/owners

Description: URL hosting obfuscated PowerShell payload used as RAT dropper

Cortex XDR Alerts and MITRE ATT&CK® Techniques

Table 2 lists the Cortex XDR alerts and the associated MITRE ATT&CK techniques these alerts detect.

Alert Name Alert Source MITRE ATT&CK Technique
External user started a Microsoft Teams conversation XDR Analytics, Identity Threats Phishing (T1566)
External user created a Microsoft Teams conversation with suspicious operations XDR Analytics, Identity Threats Phishing (T1566)
External user added a link to a Microsoft Teams chat XDR Analytics, Identity Threats Phishing (T1566)
External user call via Microsoft Teams XDR Analytics, Identity Threats Phishing: Spearphishing Voice (T1566.004)
Rare process execution by user XDR Analytics, UEBA User Execution (T1204)
Rare process execution in organization XDR Analytics, UEBA User Execution (T1204)
Multiple rare process executions in organization XDR Analytics, UEBA User Execution (T1204)
A process connected to an atypical rare cloud resource XDR Analytics Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)
Uncommon local scheduled task created XDR Analytics Scheduled Task/Job (T1053)
A browser was forced to load an extension using a special command-line argument XDR Analytics Software Extensions: Browser Extensions (T1176.001)
Uncommon browser extension loaded XDR Analytics Software Extensions: Browser Extensions (T1176.001)
SMB traffic from non-standard process XDR Analytics Network Service Discovery (T1046)
Rare NTLM access by user to host XDR Analytics, UEBA Use Alternate Authentication Material (T1550)
Unusual Encrypting File System Remote Protocol call (EFSRPC) to domain controller XDR Analytics, UEBA Forced Authentication (T1187)

Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)

Possible authentication coercion to a sensitive server XDR Analytics, UEBA Forced Authentication (T1187)

Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)

Possible Distributed File System Namespace Management (DFSNM) abuse XDR Analytics Forced Authentication (T1187)

Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)

Possible authentication coercion XDR Analytics, UEBA Forced Authentication (T1187)

Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)

Table 2. Cortex XDR alerts and MITRE techniques.



from Unit 42 https://ift.tt/CkTBH5z
via IFTTT