Malware
GlassWorm
According to Koi Security, this malware harvests NPM, GitHub, and Git credentials for supply chain propagation. It targets 49 different cryptocurrency wallet extensions to drain funds. It uses stolen credentials to compromise additional packages and extensions, spreading the worm further. Furthermore, it deploys SOCKS proxy servers, turning developer machines into criminal infrastructure and installs hidden VNC servers for complete remote access.
Indicators of Compromise 18
Domain moonsand[[.]]store Domain xfjcc[.]fun Filename Apple Sync Filename HDUtil.exe Filename content.js Filename force_enable.ps1 Filename go.bat Filename hwid.dat Filename install_silent.ps1 Filename nm_host.exe Filename patch_secure_prefs.ps1 Filename patch_secure_prefs_linux.py Filename protobuf.dll Filename termsrv.dll GitHub Repo SQL Server Management Studio SHA-256 ejkndncpkdcjcikfhiamcdehdoegilbj IP 206[.]237[.]30[.]232 Package Rilide
MITRE ATT&CK TTPs 23
T1003 T1013 T1021.001 T1021.003 T1027 T1055 T1059.001 T1068 T1070.004 T1071.001 T1078.001 T1078.002 T1082 T1086 T1090 T1105 T1136.001 T1190 T1218.011 T1548.001 T1548.002 T1557 T1566
OS Credential Dumping
Credential Access
T1013
Remote Desktop Protocol
Lateral Movement
Distributed Component Object Model
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Web Protocols
Command And Control
Default Accounts
Defense Evasion
Domain Accounts
Defense Evasion
System Information Discovery
Discovery
T1086
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Local Account
Persistence
Exploit Public-Facing Application
Initial Access
Rundll32
Defense Evasion
Setuid and Setgid
Privilege Escalation
Bypass User Account Control
Privilege Escalation
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Source Articles
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
PEEP is a post-compromise Chromium-based toolkit that installs a malicious browser extension to establish persistence and enable command-and-control (C2) operations within compromised Chrome or Edge browsers. The malware bypasses browser security checks by manipulating Secure Preferences and uses native messaging to execute host-level commands, steal credentials, and exfiltrate browsing data. It communicates with C2 servers every 30 seconds over HTTP, supports remote updates, and includes PowerShell and Python scripts for cross-platform deployment, indicating active targeting of both Windows and Linux environments.
hacker-news ·4d ago
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.
hacker-news ·1mo ago