This week's ThreatsDay roundup is a useful reminder that operational security failures are not exclusive to defenders. A ransomware affiliate — a partner in an encryption-for-extortion operation — decided to pocket the profits rather than split them with the core crew. Separately, an attacker left an entire server exposed to the internet, complete with intrusion tooling and forensic traces of their own activity. And in the stories that should genuinely worry your SOC: a remote access trojan (RAT) distributed via WhatsApp, and malicious code discovered in developer packages and browser extensions.
None of these items arrive with a single CVE to patch. That is precisely why they matter. The through-line this week is trust abuse — trust between criminals, trust in messaging platforms, trust in open-source packages, and trust in browser extensions. Defenders cannot patch trust. They can only instrument, hunt, and verify. This post breaks down each thread and gives you concrete detections and hardening steps for the ones with real enterprise impact.
Technical Analysis
1. The Ransomware Affiliate Who Kept the Money
Ransomware-as-a-Service (RaaS) operations run on a revenue-split model: affiliates conduct intrusion and deployment, the core group provides the encryptor, infrastructure, and negotiation portal, and proceeds are divided — typically 70–90% to the affiliate. This week, an affiliate simply kept the entire ransom payment, cutting out the operators.
Why should a defender care about criminal payroll disputes? Three reasons:
- Leak exposure. When affiliates and operators turn on each other, the retaliation of choice is doxxing — leaking chat logs, victim lists, builder configs, and sometimes decryptors. We have seen this pattern repeatedly (Conti in 2022, BlackCat/ALPHV's exit scam in 2024). If your organization appears in a leak from a fractured RaaS group, you may learn about an intrusion from a paste site before you learn it from your EDR.
- Double-extortion risk increases. A scammed operator may re-extort victims whose data they still hold, even if the victim already paid the affiliate. Paying once no longer maps to dealing with one adversary.
- Negotiation intelligence degrades. If you are mid-negotiation, the party on the other side of the chat may not control the decryptor or the data. Incident response plans that treat "the ransomware group" as a monolith need updating.
Defensive action: Subscribe to ransomware leak-site monitoring (in-house or via your MDR provider), and treat any appearance of your organization's name in leak channels as a presumed breach triggering IR triage — not a reputational issue for comms to handle alone.
2. WhatsApp-Delivered RAT
Messaging-platform malware delivery continues to mature. The WhatsApp RAT campaign this week follows the established pattern: social engineering lures (often a document, "invoice," or "photo" that is actually an executable or a malicious link) delivered through a channel users implicitly trust, leading to installation of a remote access trojan capable of credential theft, session hijacking, and surveillance.
From a defender's perspective, the critical technical points:
- The lure arrives via an encrypted channel. Your network-layer controls (secure email gateway, web proxy categorization) see little to nothing of the initial social engineering. Detection must shift to the endpoint.
- Initial payloads frequently masquerade as documents with double extensions (
invoice.pdf.exe) or are wrapped in archives. On mobile, sideloaded APKs are the vector; on desktop, WhatsApp Web session theft or executable droppers in the Downloads folder are common. - Post-installation behavior is the detection surface: persistence via Run keys or scheduled tasks, access to browser credential stores and session cookies (including WhatsApp Web session tokens), and C2 over common ports with low-and-slow beaconing.
Exploitation status: this is an active delivery campaign, not a theoretical technique. Treat any executable content arriving via messaging apps on corporate-managed devices as hostile by default.
3. The Exposed Attacker Server
An attacker left a server publicly exposed containing their toolset and operational traces. This is the offensive-side equivalent of an open S3 bucket, and it is a gift to defenders — when someone is watching.
Exposed adversary infrastructure typically yields:
- Tooling hashes and configurations that can be converted directly into blocklist entries and YARA/Sigma content.
- Victimology data — logs or staging directories that reveal who has been compromised, sometimes including organizations that do not yet know it.
- Attribution material — reused credentials, SSH keys, timezone artifacts, and operational mistakes.
Defensive action: If you consume threat intel feeds, ensure they include open-directory and exposed-infrastructure reporting. If you run your own collection, services like Shodan/Censys queries for known panel signatures and tool fingerprints remain high-value, low-cost sources. When an exposed server tied to intrusion activity surfaces, prioritize: (1) extracting IOCs, (2) retro-hunting your telemetry for those IOCs over a minimum 90-day window, and (3) checking whether your organization or your suppliers appear in any victim artifacts.
4. Malicious Developer Packages and Extensions
The most enterprise-relevant thread this week: malicious code in developer packages (npm/PyPI-style ecosystems) and browser extensions. This is the supply-chain soft underbelly of every engineering organization.
The attack mechanics are well-established and remain effective:
- Install-time execution. Malicious packages abuse lifecycle hooks — npm
preinstall/postinstallscripts, Pythonsetup.pyexecution — to run code the moment a developer installs the package. The developer's machine, which typically holds source code, cloud credentials, SSH keys, and CI/CD tokens, is the target. - Typosquatting and dependency confusion remain the primary distribution vectors: names one character off popular packages, or internal package names claimed on public registries.
- Browser extensions with broad permissions (
read and change all your data on websites you visit) are bought, updated maliciously, or published as trojanized clones of legitimate tools. On a developer's browser, that means session tokens for GitHub, cloud consoles, and SaaS admin panels.
Why this is urgent in 2026: developer workstations are increasingly the shortest path to production. A single poisoned package install can yield cloud keys that bypass every network control you have. There is no CVE for this — the vulnerability is the trust model of open-source ecosystems.
Detection & Response
The detections below target the two threads with concrete endpoint telemetry: RAT-style persistence and credential-store access, and install-time execution from package managers. They are written to be high-signal; deploy in audit mode first if your environment has heavy developer tooling usage.
Sigma Rules
---
title: Package Manager Lifecycle Script Spawning Shell or Script Interpreter
id: 3f8a1b72-5c4d-4e9a-b6f1-2a7c9d0e1f34
status: experimental
description: Detects npm, pip, or similar package manager processes spawning command shells or script interpreters, consistent with malicious preinstall/postinstall lifecycle hooks observed in supply-chain package compromise campaigns.
references:
- https://attack.mitre.org/techniques/T1195/002/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.initial_access
- attack.t1195.002
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.cmd'
- '\npm.exe'
- '\pip.exe'
- '\python.exe'
- '\yarn.cmd'
- '\pnpm.cmd'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\curl.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate native module compilation and build tooling (node-gyp) - baseline per developer team and tune by build server
title_note: Deploy in audit mode first in environments with heavy Node.js build usage
level: high
---
title: Unsigned Binary Persistence via Run Key from User-Writable Path
id: 8c2e5d41-7a3b-4f6c-9e2d-5b8a1c3f6d90
status: experimental
description: Detects registry Run/RunOnce persistence entries pointing to executables in user-writable locations such as AppData, a hallmark persistence pattern for RATs delivered via messaging application lures.
references:
- https://attack.mitre.org/techniques/T1060/
- https://attack.mitre.org/techniques/T1547/001/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
selection_key:
TargetObject|contains:
- '\CurrentVersion\Run'
- '\CurrentVersion\RunOnce'
selection_path:
Details|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
- '\Downloads\'
filter_legitimate:
Details|contains:
- '\AppData\Roaming\Microsoft\Teams\'
- '\AppData\Local\Microsoft\Teams\'
- 'OneDrive.exe'
- 'Spotify.exe'
- 'slack.exe'
- 'Discord.exe'
condition: selection_key and selection_path and not filter_legitimate
falsepositives:
- User-installed applications that self-update from AppData (tune the filter list to your software inventory)
level: high
---
title: Browser Credential Store Access by Non-Browser Process
id: 61d4f2a8-9b3c-4e57-a1d8-7c5e2f9a3b16
status: experimental
description: Detects non-browser processes accessing Chromium or Firefox credential and session storage files, consistent with RAT stealer functionality including session token theft for messaging web clients.
references:
- https://attack.mitre.org/techniques/T1555/003/
- https://attack.mitre.org/techniques/T1539/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.credential_access
- attack.t1555.003
- attack.t1539
logsource:
category: file_access
product: windows
detection:
selection_target:
TargetObject|endswith:
- '\Login Data'
- '\Cookies'
- '\Local State'
- '\logins.json'
- '\key4.db'
selection_path:
TargetObject|contains:
- '\Google\Chrome\'
- '\Microsoft\Edge\'
- '\BraveSoftware\'
- '\Mozilla\Firefox\'
filter_browser:
SourceImage|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
- '\firefox.exe'
- '\MsMpEng.exe'
- '\explorer.exe'
condition: selection_target and selection_path and not filter_browser
falsepositives:
- EDR/AV products scanning browser directories (add your security tooling to the filter)
- Enterprise password managers with browser integration
level: high
KQL — Microsoft Sentinel / Defender Hunt
This query hunts for package-manager-spawned script execution combined with network egress — the behavioral fingerprint of a malicious install hook pulling a second-stage payload. It correlates process lineage with outbound connections within a short window on developer workstations.
let lookback = 7d;
let suspiciousChildren = dynamic(["powershell.exe", "pwsh.exe", "cmd.exe", "wscript.exe", "cscript.exe", "mshta.exe", "curl.exe", "certutil.exe", "bitsadmin.exe", "rundll32.exe"]);
let pkgManagers = dynamic(["node.exe", "npm.cmd", "npm.exe", "pip.exe", "python.exe", "yarn.cmd", "pnpm.cmd"]);
let procEvents = DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessFileName in~ (pkgManagers)
| where FileName in~ (suspiciousChildren)
| project DeviceName, DeviceId, ProcessTime=TimeGenerated, ChildProcess=FileName, ChildCmd=ProcessCommandLine, ParentProcess=InitiatingProcessFileName, ParentCmd=InitiatingProcessCommandLine, AccountName, SHA256;
procEvents
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemotePort in (443, 80, 8443, 8080)
| project DeviceId, NetTime=TimeGenerated, NetProcess=InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort
) on DeviceId
| where NetTime between (ProcessTime .. ProcessTime + 5m)
| where NetProcess in~ (suspiciousChildren)
| extend SuspiciousCmd = ChildCmd has_any ("-enc", "-e ", "FromBase64String", "IEX", "Invoke-Expression", "DownloadString", "WebClient", "bit.ly", "pastebin")
| project ProcessTime, DeviceName, AccountName, ParentProcess, ChildProcess, ChildCmd, RemoteUrl, RemoteIP, SuspiciousCmd, SHA256
| order by SuspiciousCmd desc, ProcessTime desc
Notes on tuning: the SuspiciousCmd flag surfaces the highest-confidence hits (encoded PowerShell, download cradles) to the top. In environments with heavy legitimate Node/Python build activity, scope the query to non-build-server devices first, or add an exclusion for your known CI/CD agent accounts. The 5-minute join window keeps noise from long-lived build processes manageable.
Velociraptor VQL — Endpoint Hunt
This artifact hunts RAT-style persistence: recently created Run-key entries pointing at user-writable paths, enriched with file metadata and authenticode signature status so an analyst can triage quickly across a fleet.
-- Hunt for suspicious Run-key persistence pointing at user-writable paths
-- with file existence and signature enrichment for triage
SELECT Key.FullPath AS RegKey,
Key.Name AS ValueName,
Key.Data.String AS CommandValue,
parse_file(filename=parse_string_with_regex(string=Key.Data.String,
regex='([A-Za-z]:\\[^"]+?\.(exe|dll|bat|ps1|vbs|js))').g[1]) AS TargetFile,
Authenticode(File=parse_string_with_regex(string=Key.Data.String,
regex='([A-Za-z]:\\[^"]+?\.(exe|dll|bat|ps1|vbs|js))').g[1]) AS Signature
FROM read_reg_key(glob='HKEY_USERS\\*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run*\\**')
WHERE CommandValue =~ '(?i)appdata|users\\\\public|downloads|temp'
AND NOT CommandValue =~ '(?i)onedrive|teams|spotify|slack|discord|steam'
Run this fleet-wide and sort by unsigned or invalidly signed targets. Any unsigned executable persisting from AppData\Roaming or Downloads on a non-developer endpoint warrants immediate host isolation and triage. Extend the regex if your environment commonly sees .msi or .jar persistence.
Remediation & Audit Script
The following PowerShell script audits a Windows host for the specific risk classes in this week's stories: suspicious Run-key persistence in user-writable paths, recently modified executables in download/temp locations (a RAT triage starting point), installed browser extensions across Chrome and Edge, and globally installed npm packages with lifecycle scripts. Run it per-host or wrap it in your RMM/Intune for fleet sweep. It is read-only — it reports, it does not remediate, so it is safe to run broadly.
# Security Arsenal - Weekly Threat Audit (ThreatsDay: RAT, malicious packages, extensions)
# Read-only audit. Outputs JSON report to C:\Windows\Temp\threat_audit.json
$report = [ordered]@{ Host = $env:COMPUTERNAME; Timestamp = (Get-Date -Format o) }
# --- 1. Run-key persistence pointing at user-writable paths ---
$runKeys = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run'
)
$suspiciousPersistence = foreach ($key in $runKeys) {
if (Test-Path $key) {
(Get-ItemProperty $key).PSObject.Properties | Where-Object {
$_.Value -match '(?i)appdata|users\\public|downloads|\\temp\\' -and
$_.Value -notmatch '(?i)onedrive|teams|spotify|slack|discord' -and
$_.Name -notmatch '^PS'
} | ForEach-Object {
$exePath = ($_.Value -split '"')[1]; if (-not $exePath) { $exePath = ($_.Value -split ' ')[0] }
$sig = $null
if ($exePath -and (Test-Path $exePath -ErrorAction SilentlyContinue)) {
$sig = (Get-AuthenticodeSignature $exePath).Status.ToString()
}
[PSCustomObject]@{ Key = $key; Name = $_.Name; Value = $_.Value; Signature = $sig }
}
}
}
$report.SuspiciousPersistence = @($suspiciousPersistence)
# --- 2. Recently created executables in Downloads/Temp (RAT triage) ---
$recentCutoff = (Get-Date).AddDays(-7)
$recentExecs = Get-ChildItem -Path "$env:USERPROFILE\Downloads", "$env:TEMP", "$env:LOCALAPPDATA\Temp" -Recurse -Include *.exe,*.dll,*.scr,*.bat,*.ps1,*.js,*.vbs -ErrorAction SilentlyContinue |
Where-Object { $_.CreationTime -gt $recentCutoff } |
Select-Object FullName, CreationTime, Length, @{N='Signature';E={(Get-AuthenticodeSignature $_.FullName).Status.ToString()}}
$report.RecentExecutables = @($recentExecs)
# --- 3. Browser extensions (Chrome & Edge) ---
$extPaths = @(
"$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Extensions",
"$env:LOCALAPPDATA\Microsoft\Edge\User Data\Default\Extensions"
)
$extensions = foreach ($p in $extPaths) {
if (Test-Path $p) {
Get-ChildItem $p -Directory -ErrorAction SilentlyContinue | ForEach-Object {
$manifest = Get-ChildItem $_.FullName -Recurse -Filter manifest.json -ErrorAction SilentlyContinue | Select-Object -First 1
$name = $_.Name
if ($manifest) {
try { $m = Get-Content $manifest.FullName -Raw | ConvertFrom-Json; if ($m.name -and $m.name -notmatch '^__MSG') { $name = $m.name } } catch {}
}
[PSCustomObject]@{ Browser = ($p -split '\\')[3]; ExtensionId = $_.Name; Name = $name }
}
}
}
$report.BrowserExtensions = @($extensions)
# --- 4. Global npm packages with lifecycle scripts ---
$npmRoot = & npm root -g 2>$null
$npmRisky = @()
if ($npmRoot -and (Test-Path $npmRoot)) {
$npmRisky = Get-ChildItem $npmRoot -Directory -ErrorAction SilentlyContinue | ForEach-Object {
$pkg = Join-Path $_.FullName 'package.json'
if (Test-Path $pkg) {
try {
$j = Get-Content $pkg -Raw | ConvertFrom-Json
if ($j.scripts -and ($j.scripts.preinstall -or $j.scripts.postinstall -or $j.scripts.install)) {
[PSCustomObject]@{ Package = $j.name; Version = $j.version; LifecycleScripts = ($j.scripts.PSObject.Properties.Name -join ',') }
}
} catch {}
}
}
}
$report.NpmLifecyclePackages = @($npmRisky)
$report | ConvertTo-Json -Depth 5 | Out-File "C:\Windows\Temp\threat_audit.json" -Encoding utf8
Write-Host "[+] Audit complete. Findings written to C:\Windows\Temp\threat_audit.json"
Write-Host "[+] Persistence entries flagged: $($report.SuspiciousPersistence.Count)"
Write-Host "[+] Recent executables flagged: $($report.RecentExecutables.Count)"
Write-Host "[+] Browser extensions found: $($report.BrowserExtensions.Count)"
Write-Host "[+] npm packages with lifecycle scripts: $($report.NpmLifecyclePackages.Count)"
Triage guidance: any NotSigned or HashMismatch signature status in sections 1–2 on a non-developer host is an isolation-and-investigate trigger. For browser extensions, cross-reference IDs against your approved list — anything not on the list with broad host permissions should be removed via policy. For npm lifecycle packages, verify against your dependency tree; unexpected packages with postinstall hooks are your highest-priority supply-chain leads.
Remediation
There is no single patch for this week's themes, so remediation is layered:
Ransomware affiliate fallout / leak exposure
- Enroll in leak-site and dark-web monitoring for your organization's name, domains, and executive identities. Treat any hit as a presumed-compromise IR trigger with a defined 4-hour triage SLA.
- Re-verify your offline, immutable backup posture (3-2-1 with at least one copy offline/immutable) and run a restore test this quarter if you have not. Affiliate disputes make decryptor reliability even less trustworthy than usual — assume payment never yields recovery.
- Update IR playbooks and retainer scope to cover re-extortion by a different faction of the same group after payment.
WhatsApp / messaging-delivered RAT
- Enforce application control (WDAC or AppLocker) blocking execution from user-writable paths —
Downloads,AppData\Local\Temp, and user profile roots — with managed exceptions for approved software. - Deploy attack surface reduction rules: block Office child processes, block executable content from email and archive handlers, and block credential theft from LSASS. On mobile fleets under management, block sideloading entirely via MDM.
- Train specifically on messaging-app lures: double-extension files, "voice message" links, and QR-code session hijacking. This channel bypasses your email gateway training muscle.
Developer package and extension supply chain
- Disable lifecycle script execution by default in developer environments:
npm config set ignore-scripts true(org-wide via.npmrc), and vet any package that legitimately requires build scripts through an allowlist process. - Pin dependencies with lockfiles and integrity hashes (
package-lock.json,pip-toolshashes), and proxy all package pulls through an internal registry (Artifactory/Nexus/GitHub Packages) with malware scanning enabled. - Publish and register your internal package namespace on public registries to kill dependency-confusion attacks at the root.
- Manage browser extensions centrally: Chrome/Edge enterprise policies with an explicit allowlist, blocking all unapproved extensions on any device with access to source code, CI/CD, or cloud consoles.
- Rotate developer credentials (cloud keys, SSH, tokens) on any host where a suspicious package install is confirmed — assume credential theft, not just code execution.
Exposed attacker infrastructure (threat intel leverage)
- When exposed adversary tooling is reported, operationalize it within 24 hours: extract hashes, domains, IPs, and config artifacts; push to blocklists; and retro-hunt a minimum of 90 days of telemetry.
- Check victim artifacts for your organization and your critical suppliers — third-party compromise discovery is the most undervalued output of these exposures.
Category
soc-mdr
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.