Skip to main content
CybersecurityIoT & Mobile Security

Ransomware Affiliate Betrayal Exposes Insider Threats

Hospital corridor with medical devices and staff walking in distance.

Only 6% of Internet of Medical Things devices surveyed can be upgraded to post-quantum cryptography, Forescout found — a specific, stark gap that leaves lifetime health data exposed to future “harvest-now, decrypt-later” attacks.

Forescout's findings: medical devices and the PQC shortfall

Forescout analyzed more than 2.5 million devices across more than 50 healthcare delivery organizations and reported that just 6% of IoMT devices and 16% of medical OT devices use SSH implementations capable of supporting a transition to post-quantum cryptography, compared with 50% of IT devices. The company also found that only 31% of exposed healthcare systems support TLS 1.3, which it calls “the only TLS version capable of supporting standardized post-quantum cryptography.” Forescout warned this mix of legacy cryptography and long-lived data makes healthcare systems attractive candidates for harvest-now, decrypt-later (HNDL) operations.

Malicious development tools: VS Code themes and poisoned packages

Researchers uncovered multiple developer-focused supply chain threats. Socket reported two suspicious Visual Studio Code themes still available on the Visual Studio Marketplace — Coca-Cola Christmas and Aurora Borealis Studio Theme — that share ties to a previously removed malicious extension named Aurora Nocturne Night Theme. Socket researcher Kirill Boychenko said an analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes revealed a loader that decrypts and executes embedded JavaScript, avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos “as a dead drop resolver” to identify follow-on payload infrastructure; Boychenko added the build “contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity.”

At the same time, StepSecurity reported the npm package "@subql/common" version 5.8.3 had been compromised with a hidden payload that collects credentials and supports remote shell access. SafeDep described 42 malicious RubyGems published from an account named "reqthrottle_3474" targeting cryptocurrency developers, and flagged a cluster of nine npm packages (published by "dirtyblanket") that embed a self-spreading Linux worm which installs a backdoor and attempts to propagate via SSH keys and npm tokens.

Multi-stage intrusions: WhatsApp-delivered RAT and Power BI-enabled RMM

Morphisec detailed a WhatsApp-delivered lure file named "Statement.exe" that unpacks a chain of components culminating in a WebSocket RAT tracked as VulcanRAT207. The loader screened hosts, attempted elevation, injected a downloader into the LocalSystem Task Scheduler process, used a signed GoFly driver to terminate selected Baidu processes, set up a Vulkan DLL side-loading task, and launched the RAT. Morphisec said the malware can collect metadata, enable interactive shell access, terminate security processes, replace clipboard text, enumerate local accounts, and self-terminate.

Huntress documented a separate phishing campaign that abused legitimate Power BI domains to host fake reference documents. Targeted users were prompted to “Download Reference,” which opened a new tab to an attacker-controlled site that fingerprinted victims and then triggered a rogue ScreenConnect installer download — the page delayed the automatic download before a script programmatically activated a hidden download link.

Exposed infrastructure, predictable cookies, and sloppy choices that matter

ThreatMon found an attacker-controlled staging service at 151.243.232[.]123 containing 17 named post-exploitation tools and traces of activity linked to Mexican airline Viva Aerobus. The environment reportedly included credential-dumping scripts, Mimikatz output, SQL credential-testing utilities, and file-transfer tooling; operators used Microsoft SQL Server xp_cmdshell to run commands and return payloads via chunked, Base64-encoded query output.

Resecurity described an authentication bypass in a yard management system caused by two session-cookie design flaws: the cookie was signed with a hard-coded secret identical to the cookie name ("session_secret_example"), and the signed value was a public database identifier (CUID) instead of a random session ID. Resecurity warned these weaknesses could be combined to forge valid cookies for arbitrary users — including accounts with elevated privileges. Huntress also reported a file-upload vulnerability in web-based recreation management software used by municipalities that allowed attackers to create accounts, upload web shells, and steal payment data.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: watch developer tooling and CI environments for poisoned packages (the "@subql/common" compromise, the RubyGems cluster, and the dirtyblanket worm), and tighten storage and handling of SSH keys and tokens that the SafeDep analysis showed can enable fast lateral propagation.
  • Policymakers and regulators: the Forescout numbers — 6% and 16% upward compatibility for PQC and 31% TLS 1.3 support — highlight a concrete upgrade gap in healthcare that will complicate any sector-wide cryptographic transition or regulation tied to post-quantum readiness.
  • Affected enterprises and procurement leaders: supply-chain vetting is no longer just about dependencies — developer-facing artifacts, marketplace extensions, and digitally distributed themes can carry loaders or use unconventional channels such as Solana memos to reach follow-on infrastructure, as Socket and Boychenko documented.

Across these items the tension is the same: attackers mix sophistication and opportunism, but many successful intrusions still hinge on old, avoidable design mistakes — hard-coded secrets, predictable identifiers, unpatched cryptographic stacks, and exposed staging servers. The week’s reporting closes on a plain question left by the details themselves: if attackers and defenders alike keep leaving obvious gaps, which side will learn to stop being careless first?

Original story