Back to Intelligence

DARKLANTERN/SPEAKINGSTONE Implants, Evilginx AiTM & AnonyMousKIT PhaaS: OTX Credential-Theft Detection Pack

SA
Security Arsenal Team
August 29, 2026
11 min read

Threat Summary

The four OTX pulses describe one converging criminal and espionage supply chain rather than four isolated events. The common objective is durable access to credentials, session tokens, wallet secrets, device unlock workflows, and edge-network persistence.

The browser-extension campaign uses 19 Chrome/Edge extensions as a modular loader. After installation, the extensions strip or weaken Content Security Policy controls, inject script through XSS-style workflows, and open WebSocket channels to attacker infrastructure such as api.extensionanalyticspro.top, ggle-analytics.com, cookie-whitelist.com, and whale-alert.life. The payload priority is cryptocurrency wallet secret theft and credential harvesting, which maps to user execution, browser session/cookie theft, web-protocol C2, and exfiltration over application-layer protocols.

The ZBT router firmware pulse is the strategic persistence layer. SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS were reportedly embedded in router firmware moving through a global supply chain. DARKLANTERN is the highest-risk artifact for SOCs because it is described as an unauthenticated UDP backdoor on port 9992 with root shell potential and a trivial MAC-address bypass. Even if the initial lure is credential theft, compromised routers convert one phish into long-lived interception, DNS manipulation, traffic steering, and quiet re-entry.

AnonyMousKIT shows the monetization workflow. It packages phishing-as-a-service with AI-assisted vishing and multi-channel lures across email, SMS, WhatsApp, and voice. The reported objective is highly specific: harvest Apple credentials and recovery context to defeat Activation Lock and increase resale value of stolen iPhones. The reported scale, 506 domains and 168 storefront brands since early 2024, indicates a reseller model where takedown of one lure domain does not disrupt the operation.

The Russian espionage pulse adds the identity-layer endgame: Evilginx-style adversary-in-the-middle pages, OAuth phishing, Microsoft device-code phishing, and WhatsApp targeting against academia, think tanks, government, and education. Lure hosts such as drive.google.sharefolders.org and drive.google.formshare.cloud are designed to defeat user suspicion by visually chaining trusted brand names under attacker-controlled parent domains.

Collectively: initial access is delivered through extensions, multi-channel phishing, OAuth/device-code consent, and edge implants. Credential and token capture is the center of gravity. Persistence is achieved through browser components, router firmware, reusable PhaaS storefronts, and valid sessions after MFA. Attribution is mixed and should be treated cautiously: the Russian clusters are tracked as UNC6293, UNC7005, and UNC5976 in the referenced reporting, while the extension, PhaaS, and firmware-implant operators remain unknown in the pulse metadata.

Threat Actor / Malware Profile

DARKLANTERN: firmware-resident UDP backdoor associated with ZBT router images. Distribution is supply-chain embedding rather than classic phishing. Behavior includes listening on UDP/9992, weak or absent authentication, MAC-address bypass, and potential root shell exposure to internet-resident attackers. Persistence survives reboot because it lives in firmware or firmware-added services. Anti-analysis is primarily stealth: network defenders may not inspect router telemetry, and endpoint tools cannot see the implant.

SPEAKINGSTONE and ENDLESSDOORS: additional firmware implants in the same ecosystem. Treat them as complementary phone-home or post-exploitation components. Operational concern is not only host compromise but upstream supply-chain trust: device images, update channels, reseller firmware, and management interfaces.

Malicious Chrome/Edge extension framework: distribution through official or quasi-official extension stores using utility-themed names. Payload behavior includes CSP header stripping, script injection, WebSocket C2, wallet secret theft, credential harvesting, and extension-to-browser privilege abuse. Persistence is the installed extension ID, synced browser profiles, and enterprise policy gaps. Anti-analysis includes extendable modules, benign-looking analytics domains, and C2 over WebSocket that can blend with normal browser telemetry.

AnonyMousKIT AI PhaaS: credit-metered phishing platform with reseller storefronts. Distribution is multi-channel social engineering: email, SMS, WhatsApp, and AI voice calls. Payload behavior is credential capture for Apple ID and Activation Lock defeat workflows, likely including device model, IMEI/serial context, recovery email, and support-style pretexts. Persistence is commercial: new domains and storefront brands rotate as old ones are reported.

Evilginx / UNC6293 / UNC7005 / UNC5976 activity: AiTM reverse-proxy phishing and OAuth/device-code abuse. Distribution is targeted lures impersonating Google Drive, Microsoft sign-in, file sharing, and WhatsApp workflows. Payload behavior captures credentials and session cookies or induces consent/device-code approval, bypassing many MFA deployments. Persistence is token replay, mailbox rules, OAuth grants, and trusted device sessions. Anti-analysis includes short-lived lure domains, brand-chain hostnames, TLS, and infrastructure pivoting.

IOC Analysis

The indicator set contains IPv4 addresses, domains, hostnames, URLs, SHA1/SHA256 file hashes, and one protocol artifact: UDP/9992.

  • IPv4 indicators such as 47.107.224.89, 45.156.37.159, and 185.158.250.155 are block-and-pivot items. Add to EDR network IOC, firewall deny, proxy block, and Sentinel watchlists. Then pivot on passive DNS, NetFlow, TLS JA3/JA4 where available, and autonomous-system neighbors.
  • Domains and hostnames are higher value than IPs for phishing and extension C2 because actors rotate hosting faster than brands. Key examples: cookie-whitelist.com, cookie-whitelist.top, whale-alert.life, api.extensionanalyticspro.top, ggle-analytics.com, blockfolioaddressmonitor.pro, cryptopricebadgequickglance.pro, apple-unlock.com, buscar-lphone.com, suporte-lcloud.com, findmy-dispositivos.com, findsupport.live, fileshareapp.org, sharefolders.org, formshare.cloud, usercontent.online, and the deceptive host drive.google.sharefolders.org.
  • URLs such as http://api.active-enable-right-click.top/?uuid= and http://ggle-analytics.com/ should be decoded for UUID patterns, extension IDs, campaign tags, and beacon timing. Preserve full URL, query string, user-agent, TLS certificate, and response body hash when proxy logs permit.
  • File hashes from the firmware pulse should be pushed to EDR/NDR and firmware validation workflows. Endpoint antivirus rarely sees router images, so use hashes in threat-hunting, malware detonation, asset inventory, and supplier assurance checks rather than expecting AV to catch them on laptops.
  • Tooling: OTX pulses for context, MISP/OpenCTI for structured sharing, SIEM watchlists for matching, Suricata/Zeek for UDP/9992 and DNS anomalies, YARA for hash adjacent samples, urlscan.io/VirusTotal passive DNS for pivots, and sandbox detonation for extension CRX and firmware extraction.

Normalize indicators before blocking: strip scheme for domain controls, keep full URLs for proxy analytics, lowercase hostnames, defang in tickets, and tag confidence/TLP. Do not bulk-block google.com or apple.com based on deceptive substrings; match the attacker-controlled parent domains exactly and alert on lookalike patterns.

Detection Engineering

YAML
---
title: OTX Browser Credential Theft and AiTM Infrastructure Match
id: 8f9a2d10-otx-2026-08-29-001
status: experimental
description: Detects endpoint network connections to OTX indicators tied to malicious Chrome/Edge extensions, AnonyMousKIT PhaaS, Evilginx/AiTM lure parents, and firmware implant C2.
author: Security Arsenal
logsource:
  category: network_connection
  product: windows
  definition: 'Sysmon EventID 3 or equivalent network connection telemetry'
detection:
  selection_process:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\rundll32.exe'
  selection_ioc_host:
    DestinationHostname|contains:
      - 'cookie-whitelist.com'
      - 'cookie-whitelist.top'
      - 'whale-alert.life'
      - 'api.extensionanalyticspro.top'
      - 'active-enable-right-click.top'
      - 'ggle-analytics.com'
      - 'blockfolioaddressmonitor.pro'
      - 'cryptopricebadgequickglance.pro'
      - 'apple-unlock.com'
      - 'buscar-lphone.com'
      - 'suporte-lcloud.com'
      - 'com-maps.info'
      - 'findmy-dispositivos.com'
      - 'id-ubicacion.com'
      - 'findsupport.live'
      - 'zu7pl.pro'
      - 'fileshareapp.org'
      - 'sharefolders.org'
      - 'formshare.cloud'
      - 'usercontent.online'
      - 'www.ac-link.com'
  selection_ioc_ip:
    DestinationIp:
      - '47.107.224.89'
      - '45.156.37.159'
      - '185.158.250.155'
  condition: selection_process and (selection_ioc_host or selection_ioc_ip)
fields:
  - Image
  - ProcessId
  - User
  - DestinationHostname
  - DestinationIp
  - DestinationPort
  - Initiated
falsepositives:
  - Rare analyst research detonation
level: high
tags:
  - attack.credential_access
  - attack.t1555
  - attack.t1557
  - attack.t1071.001
  - attack.t1185
---
title: DARKLANTERN UDP 9992 Backdoor Communication
id: 8f9a2d10-otx-2026-08-29-002
status: experimental
description: Detects UDP traffic to port 9992 associated with the reported DARKLANTERN unauthenticated ZBT router backdoor and phone-home implant behavior.
author: Security Arsenal
logsource:
  category: network_connection
  product: windows
  definition: 'Use with endpoint, Zeek, Suricata, firewall, or NDR network telemetry mapped to network_connection'
detection:
  selection_port:
    DestinationPort: 9992
  selection_udp:
    Protocol: udp
  selection_direction:
    Initiated: true
  condition: selection_port and selection_udp and selection_direction
fields:
  - Image
  - Computer
  - SourceIp
  - DestinationIp
  - DestinationPort
  - Protocol
falsepositives:
  - Legacy lab services explicitly approved for UDP/9992
level: critical
tags:
  - attack.command_and_control
  - attack.t1095
  - attack.t1071
  - attack.persistence
---
title: Browser Credential Store Access by Non-Browser Process
id: 8f9a2d10-otx-2026-08-29-003
status: experimental
description: Detects suspicious access to Chrome or Edge Login Data and Cookie stores by processes that should not read browser credential databases, consistent with infostealer and extension-assisted credential theft.
author: Security Arsenal
logsource:
  category: process_access
  product: windows
  definition: 'Sysmon EventID 10. Tune aggressively in environments with backup, DLP, or EDR browser inspection.'
detection:
  selection_target:
    TargetImage|contains:
      - '\User Data\Default\Login Data'
      - '\User Data\Default\Cookies'
      - '\User Data\Default\Network\Cookies'
      - '\User Data\Profile'
  selection_granted:
    GrantedAccess|contains:
      - '0x1FFFFF'
      - '0x10'
      - '0x2'
  filter_legit:
    SourceImage|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\msedgewebview2.exe'
  condition: selection_target and selection_granted and not filter_legit
fields:
  - SourceImage
  - SourceProcessId
  - TargetImage
  - GrantedAccess
  - User
falsepositives:
  - EDR, DLP, backup, forensic collection
level: high
tags:
  - attack.credential_access
  - attack.t1555.003
  - attack.t1539
KQL — Microsoft Sentinel / Defender
let IoC = dynamic(['cookie-whitelist.com','cookie-whitelist.top','whale-alert.life','api.extensionanalyticspro.top','active-enable-right-click.top','ggle-analytics.com','blockfolioaddressmonitor.pro','cryptopricebadgequickglance.pro','apple-unlock.com','buscar-lphone.com','suporte-lcloud.com','com-maps.info','findmy-dispositivos.com','id-ubicacion.com','findsupport.live','zu7pl.pro','fileshareapp.org','sharefolders.org','formshare.cloud','usercontent.online','www.ac-link.com','47.107.224.89','45.156.37.159','185.158.250.155']);
let Net = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (IoC) or RemoteIP in (IoC) or RemotePort == 9992
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, Protocol, ActionType;
let BrowserStore = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName !in~ ('chrome.exe','msedge.exe','msedgewebview2.exe')
| where ProcessCommandLine has_any ('Login Data','Cookies','Network\Cookies','User Data')
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256;
Net
| union BrowserStore
| sort by TimeGenerated desc
PowerShell
# OTX credential-theft and implant hunt: run elevated on endpoints and from a management host for edge checks
$IoCDomains = 'cookie-whitelist.com','cookie-whitelist.top','whale-alert.life','api.extensionanalyticspro.top','active-enable-right-click.top','ggle-analytics.com','blockfolioaddressmonitor.pro','cryptopricebadgequickglance.pro','apple-unlock.com','buscar-lphone.com','suporte-lcloud.com','com-maps.info','findmy-dispositivos.com','id-ubicacion.com','findsupport.live','zu7pl.pro','fileshareapp.org','sharefolders.org','formshare.cloud','usercontent.online','www.ac-link.com'
$IoCIPs = '47.107.224.89','45.156.37.159','185.158.250.155'
$Out = Join-Path $env:TEMP ('otx-hunt-' + (Get-Date -Format yyyyMMddHHmmss) + '.csv')
$rows = @()

Get-NetTCPConnection -ErrorAction SilentlyContinue | Where-Object { $IoCIPs -contains $_.RemoteAddress -or $_.RemotePort -eq 9992 } | ForEach-Object {
  $rows += [pscustomobject]@{Type='TCP'; Local=$_.LocalAddress + ':' + $_.LocalPort; Remote=$_.RemoteAddress + ':' + $_.RemotePort; State=$_.State; OwningProcess=$_.OwningProcess}
}
Get-NetUDPEndpoint -ErrorAction SilentlyContinue | Where-Object { $_.LocalPort -eq 9992 } | ForEach-Object {
  $rows += [pscustomobject]@{Type='UDP9992-Listener'; Local=$_.LocalAddress + ':' + $_.LocalPort; Remote=''; State='Listen'; OwningProcess=$_.OwningProcess}
}
foreach ($d in $IoCDomains) {
  try {
    $r = Resolve-DnsName -Name $d -ErrorAction Stop
    foreach ($a in $r) { if ($a.IPAddress) { $rows += [pscustomobject]@{Type='DNS'; Local=$env:COMPUTERNAME; Remote=($d + ' -> ' + $a.IPAddress); State='Resolved'; OwningProcess=''} } }
  } catch {}
}
$browserRoots = @((Join-Path $env:LOCALAPPDATA 'Google/Chrome/User Data'),(Join-Path $env:LOCALAPPDATA 'Microsoft/Edge/User Data'))
foreach ($root in $browserRoots) {
  if (Test-Path $root) {
    Get-ChildItem $root -Directory -ErrorAction SilentlyContinue | Where-Object { $_.Name -match '^(Default|Profile)' } | ForEach-Object {
      $ext = Join-Path $_.FullName 'Extensions'
      if (Test-Path $ext) {
        Get-ChildItem $ext -Directory -ErrorAction SilentlyContinue | Sort-Object LastWriteTime -Descending | Select-Object -First 40 | ForEach-Object {
          if ($_.LastWriteTime -gt (Get-Date).AddDays(-120)) { $rows += [pscustomobject]@{Type='RecentExtension'; Local=$_.FullName; Remote=''; State=$_.LastWriteTime; OwningProcess=''} }
        }
      }
      foreach($store in 'Login Data','Cookies',(Join-Path $_.FullName 'Network/Cookies')){
        $p = if(Test-Path $store){$store}else{Join-Path $_.FullName $store}
        if(Test-Path $p){ $rows += [pscustomobject]@{Type='BrowserStorePresent'; Local=$p; Remote=''; State=(Get-Item $p).LastWriteTime; OwningProcess=''} }
      }
    }
  }
}
foreach($rk in 'HKCU:/Software/Microsoft/Windows/CurrentVersion/Run','HKLM:/Software/Microsoft/Windows/CurrentVersion/Run'){
  if(Test-Path $rk){
    Get-ItemProperty $rk | ForEach-Object {
      $_.PSObject.Properties | Where-Object { $_.Value -match 'chrome|edge|extension|update|analytics|unlock|apple|wallet' } | ForEach-Object {
        $rows += [pscustomobject]@{Type='RunKey'; Local=$rk; Remote=($_.Name + '=' + $_.Value); State='PersistenceReview'; OwningProcess=''}
      }
    }
  }
}
Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { ($_.TaskName + $_.Actions.Execute + $_.Actions.Arguments) -match 'chrome|edge|extension|analytics|unlock|apple|wallet|9992' } | ForEach-Object {
  $rows += [pscustomobject]@{Type='ScheduledTask'; Local=$_.TaskName; Remote=($_.Actions.Execute + ' ' + $_.Actions.Arguments); State=$_.State; OwningProcess=''}
}
$rows | Export-Csv -NoTypeInformation $Out
Write-Host ('Wrote ' + $Out + ' with ' + $rows.Count + ' leads')

Response Priorities

Immediate: block the listed domains, hostnames, URLs, and IPs at proxy, DNS, firewall, EDR, and mail controls. Add exact-parent-domain blocks for sharefolders.org, formshare.cloud, usercontent.online, findsupport.live, and the extension/PhaaS domains; alert on drive.google.* deception patterns without blocking Google. Isolate any asset with UDP/9992 exposure, unknown router firmware, recent extension installs followed by crypto or Apple ID prompts, or browser credential-store access by a non-browser process. Preserve memory, browser profiles, extension CRX files, DNS cache, proxy logs, OAuth consent logs, and router configuration before wiping.

24h: assume credential and token exposure where any indicator matched. Revoke active sessions for Microsoft 365, Google Workspace, Apple ID, VPN, SSO, and password managers. Reset passwords from a known-clean device, not through the suspected browser profile. Review OAuth grants, device-code flows, mailbox rules, MFA changes, recovery email/phone changes, Apple Activation Lock status, and WhatsApp linked devices. Force re-enrollment of phishing-resistant MFA for executives, researchers, IT admins, finance, and anyone in education or government targeting scopes. Validate ZBT and edge device firmware hashes against vendor-signed images and remove resold or unmanaged firmware from service.

1 week: harden architecture around the observed vectors. Enforce browser extension allowlists and block side-loaded CRX; monitor extension inventory drift and synced profiles. Require FIDO2/passkeys or number-matching plus token-binding where possible; treat Evilginx-class AiTM as a reason to shorten session lifetime and alert on impossible travel plus token replay. Put routers and IoT edge devices on managed update paths, disable WAN-side management, alert on UDP/9992 and unexpected outbound beacons, and add firmware assurance to procurement. Build PhaaS resilience with brand-lure detection, DMARC enforcement, SMS/vishing reporting, and targeted exercises for academia, think tanks, technology, telecommunications, and government users.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.