Skip to main content

ThreatsDay: Ransomware Affiliate Betrayal and Malicious VS Code Themes

3 min read Runtime Rebel Intel
Primary source: thehackernews.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Security professionals face diverse emerging threats spanning supply chain compromise, ransomware affiliate betrayal, and advanced phishing lures.
  • Affected systems: Development environments using Visual Studio Marketplace, Windows hosts targeted by Python malware, and medical devices lacking post-quantum cryptography support.
  • Remediation: Audit installed extensions and integrated development environment plugins against known malicious indicators while reinforcing email and endpoint defenses.

Advertisement

Recent intelligence highlights an array of complex threats crossing multiple vectors, ranging from developer tool compromises to high-profile ransomware affiliate disputes. According to The Hacker News, adversaries continue to exploit both technical vulnerabilities and human factors to achieve their objectives.

Developer Tool Supply Chain Risks

Supply chain vectors remain an attractive entry point for malicious actors targeting software developers. Security researchers at Socket discovered suspicious Visual Studio Code themes, including Coca-Cola Christmas and Aurora Borealis Studio Theme, available on the Visual Studio Marketplace. These extensions share ties to earlier malicious packages designed to deploy obfuscated downloaders.

Further analysis identified cluster-linked extension identities within Open VSX. Investigations into the Cosmic Nebula Themes build revealed a loader that decrypts and executes embedded JavaScript. This malware checks host environments to avoid Russian-language and Russian-timezone systems, utilizing Solana transaction memos as a dead drop resolver to locate follow-on infrastructure. The execution model shares identical indicators with previously documented GlassWorm activity.

Advanced Malware and Phishing Campaigns

Beyond development tools, traditional delivery mechanisms continue to evolve. Recent campaigns leveraging financial-document lures distributed via WhatsApp have delivered sophisticated remote access trojans. Analysis by Morphisec detailed how these multi-stage intrusions utilize signed drivers to terminate security processes through Bring Your Own Vulnerable Driver (BYOVD) techniques, alongside process injection methods that avoid traditional detection mechanisms.

Simultaneously, underground marketplaces such as Infected Marketplace continue to inventory and sell compromised Windows host access following phishing campaigns utilizing frameworks like BraZetsu.

Ransomware Dynamics and Affiliate Betrayal

Intriguing operational dynamics have emerged within cybercrime syndicates. CloudSEK reported an incident involving a Gentlemen ransomware affiliate named Azazel, who double-crossed the ransomware-as-a-service (RaaS) operator by establishing an independent leak site named Leakned. The affiliate published victim data and retained extortion proceeds directly, demonstrating that trust issues frequently plague criminal enterprises.

In separate law enforcement developments, an alleged core member of the Qilin ransomware group was arrested in Japan and extradited to Germany to face charges related to enterprise encryption and extortion.

Healthcare Sector Exposure

Forescout published findings regarding Internet of Medical Things (IoMT) devices and operational technology within healthcare environments. The analysis indicates that the vast majority of medical hardware cannot support post-quantum cryptography standards or modern protocol requirements such as TLS 1.3. This leaves sensitive healthcare data exposed to harvest-now, decrypt-later attacks.

Recommendations for Defenders

Security teams should prioritise the following measures to mitigate these evolving threats:

  • Audit all integrated development environment extensions and remove unverified themes or plugins.
  • Monitor endpoint telemetry for unexpected process injection techniques and driver-loading anomalies.
  • Restrict administrative privileges and enforce strict credential hygiene across all enterprise assets.

Related: Threat Actors Prefer Repeatable Playbooks Over Novel Exploits, ThreatsDay: AI Zero-Day Chains, ATM Jackpotting, and Cache Key Injection

Advertisement

Advertisement