Back to Intelligence

Packagist iOS Spyware Chain (CVE-2025-31277/CVE-2025-43529) + RMM Phishing Credential Theft: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
September 30, 2026
10 min read

Two converging campaigns surfaced in this morning's OTX feed, and together they paint a clear picture of where credential and wallet theft is heading in late 2026: trusted software supply chains and legitimate remote administration tooling as the delivery vehicle.

Campaign A — Packagist Supply Chain → iOS Spyware: Thirteen malicious Composer theme packages were published on Packagist across five vendor namespaces, targeting Vietnamese movie and comic streaming sites. Once injected into those sites, the JavaScript payload executes a dual-purpose operation: a mobile ad-fraud and gambling redirect chain for general traffic, and — specifically for iPhone visitors — a WebKit-to-kernel exploit chain weaponizing CVE-2025-31277 (WebKit) and CVE-2025-43529 (kernel escalation), with CVE-2026-43655 referenced as a third chained flaw. The end payload is spyware engineered to harvest cryptocurrency wallet seed phrases and credentials. Infrastructure analysis ties the operation to FUNNULL, the content-delivery network long associated with phishing and scam-hosting enablement (funnull01.vip, cre-ads.com, and direct-to-IP lure delivery at 23.225.52.67:4466).

Campaign B — RMM-Abuse Phishing: Since July 2026, threat actors have been pushing a masqueraded MSP360 RMM installer via meeting-invitation lures, PDF-themed attachments, and fake software update prompts across multiple industries. The social engineering is the malware: victims install a legitimate signed remote management tool, giving actors a persistent foothold that sails past signature-based AV. Post-foothold, actors deploy a modular toolkit including ScreenConnect, WindVerify, masquerade binaries named WindowsUpdate / WindowsSecurity_PIN / WindowsSecurity_Password / WindowsPassKey, visibility/evasion tools (SCHider, DefenderDT, DefenderControl, MouseHiderGUI, HideMouse), and NirSoft credential harvesters (WebBrowserBookmarksView, WebBrowserPassView). The objective is unambiguous: browser-stored credential and session theft, with Defender tampering to keep the access durable.

Collectively, these pulses describe an ecosystem where initial access no longer requires dropping obviously malicious binaries. Supply-chain poisoned packages and signed RMM installers do the work — and the monetization layer (crypto seeds, saved passwords, session cookies) flows into credential markets. Treat any organization with developer pipelines (Composer/PHP) or unmanaged RMM exposure as in-scope.

Threat Actor / Malware Profile

Cluster A — Packagist iOS Spyware (FUNNULL-linked infrastructure)

  • Distribution method: Typosquatted/malicious Composer theme packages on Packagist across five vendor namespaces; dependency-pulled into Vietnamese streaming and comic sites, which then serve injected JavaScript to mobile visitors.
  • Payload behavior: Conditional JavaScript execution — desktop/Android traffic is routed through an ad-fraud and gambling redirect chain; iOS Safari traffic receives a WebKit exploit (CVE-2025-31277) chained to a kernel escalation (CVE-2025-43529) to escape the browser sandbox and install spyware with no user interaction beyond page load.
  • Theft objective: Cryptocurrency wallet seed phrases, stored credentials, and session data; exfiltration rides the same FUNNULL-fronted infrastructure used for the redirect chain.
  • Anti-analysis: Device-fingerprinting gates the exploit chain to iPhones only; multi-stage delivery (theme package → site injection → conditional redirect → exploit) defeats static reputation scanning of the initial package; lure content served over direct-IP HTTP (23.225.52.67:4466/vip344.html) evades domain-based filtering.

Cluster B — MSP360/ScreenConnect RMM-Abuse Intrusion Set

  • Distribution method: Spear-phishing with meeting-invitation themes, PDF lures, and software-update prompts delivering a trojanized-but-signed MSP360 installer.
  • Payload behavior: The legitimate RMM agent phones home to attacker-controlled consoles, establishing interactive remote access. Actors then stage secondary tooling: ScreenConnect for redundant access, WindVerify for validation, and masquerade binaries (WindowsUpdate.exe, WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, WindowsPassKey.exe) to harvest credentials under the guise of OS dialogs.
  • Persistence: RMM agents register as services and auto-reconnect; ScreenConnect provides a second persistence channel so removal of one tool doesn't evict the actor.
  • Anti-analysis / defense evasion: DefenderControl and DefenderDT disable or tamper with Microsoft Defender; SCHider and HideMouse/MouseHiderGUI conceal windows and cursor activity from the victim sitting at the machine; NirSoft tools (WebBrowserPassView, WebBrowserBookmarksView) dump browser credential stores to disk for exfiltration over the RMM channel itself — no custom C2 protocol to detect.
  • C2 communication: Legitimate vendor infrastructure (MSP360 cloud, ScreenConnect relays). Blocking requires process and service intelligence, not just network IOCs.

IOC Analysis

The two pulses provide complementary indicator sets:

  • Network indicators (Cluster A): Domains (xemphimlau.com, funnull01.vip, cre-ads.com), hostname (im.ue8im.com), and a direct-IP lure URL (http://23.225.52.67:4466/vip344.html). These are immediately actionable at the DNS sinkhole, web proxy, and egress firewall layers. FUNNULL-fronted domains rotate quickly — block on sight but hunt historically for 30–90 days of DNS/proxy logs.
  • Vulnerability indicators (Cluster A): CVE-2025-31277, CVE-2025-43529, CVE-2026-43655. These are patch-priority IOCs for your iOS fleet. MDM queries for iOS version and Safari/WebKit patch level are your detection surface — you cannot log the exploit, only ensure the target set is empty.
  • File-hash indicators (Cluster B): 54 indicators including SHA256/SHA1/MD5 hashes of the trojanized MSP360 installer and secondary tooling. Load these into your EDR blocklist and threat intel platform (MISP, OpenCTI, Sentinel TI). Hashes are brittle — pair them with behavioral rules below, since re-signed installer variants will change hashes daily.
  • Behavioral indicators (Cluster B): Process names (DefenderControl, MouseHiderGUI, SCHider, WebBrowserPassView, WebBrowserBookmarksView) and masquerade names (WindowsUpdate.exe, WindowsSecurity_Password.exe running from non-system paths) are far more durable detection anchors than hashes.

Operationalization: Ingest both pulses via the OTX DirectConnect API or TAXII feed into your TIP, auto-expire network IOCs at 90 days, and correlate hash hits against EDR telemetry retroactively (most EDRs support hash-based retrohunt). Decode nothing — these are plain indicators — but enrich the FUNNULL domains with passive DNS to catch sibling infrastructure before it's published.

Detection Engineering

YAML
---
title: Trojanized MSP360 RMM Installer Execution
id: 7f3a1c2e-9b41-4e6a-a1d5-3c8f2e6b9d01
status: experimental
description: Detects execution of trojanized MSP360 RMM installers delivered via phishing lures (meeting invitations, PDF lures, fake update prompts) as reported in OTX pulse on RMM abuse for persistent access.
author: Security Arsenal
references:
  - https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
detection:
  selection_msp360:
    Image|endswith:
      - '\MSP360.exe'
      - '\MSP360Setup.exe'
      - '\CloudBackupSetup.exe'
      - '\RemoteDesktopSetup.exe'
    CommandLine|contains:
      - '/S'
      - '/silent'
      - '/quiet'
  selection_parent:
    ParentImage|endswith:
      - '\outlook.exe'
      - '\teams.exe'
      - '\acrobat.exe'
      - '\acrord32.exe'
      - '\explorer.exe'
  condition: selection_msp360 and selection_parent
falsepositives:
  - Legitimate IT-managed MSP360 deployments via software distribution (parent will be SCCM/Intune, not mail/browser clients)
level: high
tags:
  - attack.initial-access
  - attack.t1566
  - attack.command-and-control
  - attack.t1219
---
title: Defender Tampering and Credential Dump Tooling Deployment
id: 8e4b2d3f-ac52-5f7b-b2e6-4d9a3f7c0e12
status: experimental
description: Detects execution of defense-evasion and credential-harvesting tools (DefenderControl, DefenderDT, SCHider, HideMouse, WebBrowserPassView, WebBrowserBookmarksView) observed in RMM-abuse intrusions.
author: Security Arsenal
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\DefenderControl.exe'
      - '\DefenderDT.exe'
      - '\SCHider.exe'
      - '\HideMouse.exe'
      - '\MouseHiderGUI.exe'
      - '\WebBrowserPassView.exe'
      - '\WebBrowserBookmarksView.exe'
  selection_orig:
    OriginalFileName:
      - 'DefenderControl.exe'
      - 'WebBrowserPassView.exe'
      - 'WebBrowserBookmarksView.exe'
      - 'dControl.exe'
  condition: 1 of selection_*
falsepositives:
  - Rare; WebBrowserPassView/BookmarksView occasionally used by internal IT for recovery — whitelist approved admin accounts
level: critical
tags:
  - attack.defense-evasion
  - attack.t1562.001
  - attack.credential-access
  - attack.t1555.003
---
title: Masqueraded Windows Security Binary From User Path
id: 9f5c3e4a-bd63-6a8c-c3f7-5e0b4a8d1f23
status: experimental
description: Detects execution of binaries masquerading as Windows update/security components (WindowsUpdate.exe, WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, WindowsPassKey.exe, WindVerify.exe) running from user-writable or non-system directories.
author: Security Arsenal
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
detection:
  selection_name:
    Image|endswith:
      - '\WindowsUpdate.exe'
      - '\WindowsSecurity_PIN.exe'
      - '\WindowsSecurity_Password.exe'
      - '\WindowsPassKey.exe'
      - '\WindVerify.exe'
  filter_legit:
    Image|startswith:
      - 'C:\Windows\System32\'
      - 'C:\Windows\WinSxS\'
      - 'C:\Windows\SoftwareDistribution\'
  condition: selection_name and not filter_legit
falsepositives:
  - None expected for the security-themed names; WindowsUpdate.exe in SoftwareDistribution is legitimate
level: high
tags:
  - attack.defense-evasion
  - attack.t1036
  - attack.credential-access
KQL — Microsoft Sentinel / Defender
// RMM abuse & credential-theft hunt — OTX pulse 2026-09-30
// Looks for trojanized RMM installs, known-bad hashes, FUNNULL/iOS-spyware network IOCs, and credential dump tooling
let BadHashes = dynamic([
  "1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8",
  "499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a",
  "6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc",
  "a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657",
  "1798612c9445ea7c411f269d984e2aaed4bfcaf0"]);
let ToolNames = dynamic(["msp360","screenconnect","windverify","windowssecurity_pin","windowssecurity_password",
  "windowspasskey","schider","defenderdt","defendercontrol","mousehidergui","hidemouse",
  "webbrowserpassview","webbrowserbookmarksview"]);
let ProcHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where SHA256 in (BadHashes)
   or FileName has_any (ToolNames)
   or ProcessCommandLine has_any ("webbrowserpassview","/stext","webbrowserbookmarksview")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, FolderPath, InitiatingProcessFileName;
let NetHits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl in ("xemphimlau.com","funnull01.vip","cre-ads.com","ue8im.com")
   or RemoteIP == "23.225.52.67"
   or RemoteUrl has_any ("funnull","cre-ads")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort;
union ProcHits, NetHits
| sort by TimeGenerated desc
PowerShell
# RMM-Abuse & Credential-Theft IOC Hunt — OTX 2026-09-30
# Run elevated on endpoints or via your RMM/SCCM/Intune across the fleet

$badHashes = @(
  "1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8",
  "499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a",
  "6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc",
  "a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657"
)
$toolNames = @("msp360*","screenconnect*","windverify*","windowssecurity_pin*","windowssecurity_password*",
  "windowspasskey*","schider*","defenderdt*","defendercontrol*","mousehidergui*","hidemouse*",
  "webbrowserpassview*","webbrowserbookmarksview*","windowsupdate.exe")
$searchPaths = @("$env:ProgramFiles","${env:ProgramFiles(x86)}","C:\Users","C:\ProgramData","C:\Temp")
$findings = @()

# 1. Hunt for tool binaries and hash matches in user-writable / non-system paths
foreach ($path in $searchPaths) {
  foreach ($name in $toolNames) {
    Get-ChildItem -Path $path -Filter $name -Recurse -ErrorAction SilentlyContinue | ForEach-Object {
      $h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
      $findings += [PSCustomObject]@{
        Type = if ($badHashes -contains $h) {"HASH_MATCH"} else {"TOOL_BINARY"}
        Path = $_.FullName; SHA256 = $h; Host = $env:COMPUTERNAME }
    }
  }
}

# 2. Persistence: RMM agents as services & Run keys
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match "msp360|screenconnect|connectwise" } | ForEach-Object {
  $findings += [PSCustomObject]@{ Type="RMM_SERVICE"; Path=$_.PathName; SHA256=""; Host=$env:COMPUTERNAME } }
foreach ($rk in @("HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run","HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run")) {
  Get-ItemProperty $rk -ErrorAction SilentlyContinue | Get-Member -MemberType NoteProperty | ForEach-Object {
    $val = (Get-ItemProperty $rk -Name $_.Name -ErrorAction SilentlyContinue).($_.Name)
    if ($val -match "msp360|screenconnect|windverify|windowssecurity|hidemouse|schider") {
      $findings += [PSCustomObject]@{ Type="RUN_KEY"; Path="$rk :: $($_.Name) = $val"; SHA256=""; Host=$env:COMPUTERNAME } } } }

# 3. Defender tampering state
$mp = Get-MpComputerStatus -ErrorAction SilentlyContinue
if ($mp -and (-not $mp.RealTimeProtectionEnabled -or -not $mp.AntivirusEnabled)) {
  $findings += [PSCustomObject]@{ Type="DEFENDER_TAMPERED"; Path="RealTimeProtection=$($mp.RealTimeProtectionEnabled) AV=$($mp.AntivirusEnabled)"; SHA256=""; Host=$env:COMPUTERNAME } }

# 4. Network: FUNNULL / iOS-spyware infrastructure
foreach ($conn in (Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue)) {
  if ($conn.RemoteAddress -eq "23.225.52.67") {
    $proc = (Get-Process -Id $conn.OwningProcess -ErrorAction SilentlyContinue).ProcessName
    $findings += [PSCustomObject]@{ Type="NET_IOC"; Path="$proc -> $($conn.RemoteAddress):$($conn.RemotePort)"; SHA256=""; Host=$env:COMPUTERNAME } } }
$dns = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -match "funnull|cre-ads|xemphimlau|ue8im" }
$dns | ForEach-Object { $findings += [PSCustomObject]@{ Type="DNS_IOC"; Path=$_.Entry; SHA256=""; Host=$env:COMPUTERNAME } }

$findings | Format-Table -AutoSize
$findings | Export-Csv -Path ".\rmm_hunt_$($env:COMPUTERNAME).csv" -NoTypeInformation
Write-Host "[+] Hunt complete: $($findings.Count) findings on $env:COMPUTERNAME"

Response Priorities

Immediate (0–4h):

  • Block xemphimlau.com, funnull01.vip, cre-ads.com, im.ue8im.com, and 23.225.52.67 at DNS, proxy, and egress firewall; push the four SHA256 hashes to your EDR blocklist.
  • Run the KQL and PowerShell hunts fleet-wide; isolate any host with HASH_MATCH, RMM_SERVICE, or DEFENDER_TAMPERED findings.
  • Audit your Composer/PHP build pipelines for dependencies from the five malicious Packagist vendor namespaces; pin and re-pull from clean mirrors.

24 hours:

  • Both campaigns are credential-theft operations — force password resets for any user on an affected host, revoke all sessions and refresh tokens (browser-stored sessions were a primary target), and re-enroll MFA where TOTP secrets may have resided in-browser.
  • For any iOS device that browsed Vietnamese streaming/comic sites while unpatched, assume seed-phrase compromise: rotate cryptocurrency wallets to new seeds generated on a clean device.
  • Pull 90 days of proxy/DNS history for the FUNNULL domains to scope retroactive exposure.

1 week:

  • Push iOS updates addressing CVE-2025-31277 / CVE-2025-43529 / CVE-2026-43655 via MDM with an enforcement deadline; block unpatched devices from corporate resources.
  • Implement an RMM allowlist policy: block installation/execution of any remote management tool not on the approved IT list (AppLocker/WDAC rules for MSP360, ScreenConnect, and the ~20 common RMM binaries actors substitute).
  • Enable tamper protection enforcement and Defender alerting on RealTimeProtectionEnabled state changes; deploy the Sigma rules above to production.
  • Add dependency-integrity checks (e.g., Socket, lockfile verification) to CI/CD for Packagist and all public package registries.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.