Skip to content
Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Ravie LakshmananOct 08, 2026Hacking News / Cybersecurity News

The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence.

The rest of the week isn’t much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now.

What’s interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here’s what else turned up.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  1. Malicious VS Code themes exposed

    Socket said it discovered two suspicious VS Code themes still available on the Visual Studio Marketplace (Coca-Cola Christmas and Aurora Borealis Studio Theme) that claim to be color themes but share ties to Aurora Nocturne Night Theme, a previously removed malicious extension that concealed an obfuscated Windows downloader. Further analysis has uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes. An analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes has revealed that it contains a loader that decrypts and executes embedded JavaScript, avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos as a dead drop resolver to identify follow-on payload infrastructure. “That build contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity,” Socket researcher Kirill Boychenko said.

One strange thing about this week’s stories is how often the attackers look just as careless as the systems they’re breaking into. Some leave their tools exposed. Others steal from their own partners. It would be easier to laugh at that if basic security mistakes weren’t still giving them results. Being sloppy clearly doesn’t stop anyone from causing damage.

There’s also plenty here that won’t be fixed with a quick patch. Old design choices, trusted software turning hostile, and systems that aren’t ready for what’s coming next. The details are worth a closer look, especially the boring ones. Those tend to be where the trouble starts. That’s it for this week.

Source link