Article

EvilBit Threat Digest - EvilBit Threat Digest: Trust Falls, But Make It Internet-Scale

Threat actors abuse legitimate platforms and invitation-based access, turning hosts into attack surfaces.

Security this week had a unifying theme: attackers stopped “breaking in” and started “being invited.” AI skill marketplaces, code extension repos, Jira Cloud notifications, a lookalike 7‑Zip domain, even OAST callback infrastructure, everything is a signed visitor badge with a knife taped to the back.

UncleSp1d3r and KryptoKat here. One of us is thinking about exploit paths; the other is thinking about the pager rotation. Both of us are thinking about how much of the modern internet runs on vibes.


The Internet’s Background Radiation Got Louder (and More Targeted)

GreyNoise’s latest weekly OAST report is basically a seismograph for opportunistic exploitation: 6,197 OAST sessions, 79 IPs, 73 campaigns in a single week. Most of it automated, some of it clearly pointed at known enterprise soft spots. The headline: confirmed exploitation of Ivanti EPMM CVE‑2026‑1281, showing up with bulletproof hosting behind it (not your garden‑variety “scan-and-pray” VPS fleet).
Source: GreyNoise Labs Weekly OAST Report - Week Ending 2026-02-13

KryptoKat: OAST isn’t “just scanning.” It’s feedback. It tells an operator “this target executed my payload” without needing direct access. GreyNoise calling out Nuclei-style scanning clusters plus fingerprinting (JA3/JA4T) is a reminder that defenders can (and should) treat these patterns as early warning, not trivia.

What to do Monday morning (not “someday”):

UncleSp1d3r: If you’re wondering why OAST-based exploit kits are so popular: it’s “WarGames” for grownups. Type in a move, wait for the modem to scream back. Only now the modem is your DNS logs.


“Legit” Platforms as Payload Delivery: Your Brand Is Their Stealth

Trojanized installer -> proxy botnet (because of course)

A lookalike domain (7zip[.]com) served a trojanized 7‑Zip installer that drops upStage Proxy, turning victim Windows machines into residential proxy nodes. Persistence comes via a Windows service, plus firewall rule changes to keep the proxy reachable and a C2 protocol that’s XOR-encoded. This isn’t “steal a password and leave.” It’s convert the host into infrastructure.
Sources: Luke Acha: upStage Proxy, Malwarebytes coverage, BleepingComputer

Blue-team takeaway: Treat any endpoint that executed an installer from the wrong domain as compromised, not “maybe risky.” Proxyware is an incident-class problem because it launders someone else’s activity through your IP space.


Jira Cloud: phishing with a corporate letterhead

Trend Micro documents a campaign abusing Atlassian Jira Cloud to send spam/phishing at government and corporate targets, leaning on Jira’s “normal notification” look and the baseline trust many orgs grant to SaaS platform email flows. The payloads skew toward scams (investment/casino), but the real lesson is reusable: SaaS notifications are now an attack surface.
Source: Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities

KryptoKat: Your secure email gateway can’t “detonate” a link’s social context. It sees Jira. Your users see Jira. Your attackers see Jira and your users. Audit who can create instances/projects, and don’t let SaaS tooling become an unmonitored mail cannon.


AI marketplace supply chain: “skills” that walk you to malware

OpenSourceMalware details malicious ClawHub skills that avoid in-market scanning by using external websites as the real delivery mechanism. The skills become the lure, the documentation becomes the “run this command,” and the payload lives elsewhere. It’s supply chain by social geometry: the marketplace is just the trust anchor.
Source: Malicious ClawHub Skills Use External Websites to Hide in Plain Sight

UncleSp1d3r: This is the oldest trick on the internet wearing a new hoodie. The “package manager install” meme never died; it just learned the phrase “AI workflow.”


Code extension worms: the repo is the beachhead

Annex reports a worm-like malware campaign targeting Open VSX / VS Code extensions, aimed at finance and e-commerce environments, with obfuscation and C2/exfil over seemingly normal web traffic. Supply chain risk here isn’t hypothetical; extensions execute where developers and operators live.
Source: Worms lurking in code extensions

Defender move: Don’t treat extensions as “preferences.” Treat them like software deployment: provenance, publisher controls, and periodic review.


Targeted Ops: When the Payload Has a Passport Stamp

CRESCENTHARVEST: protest lures, DLL sideloading, and real-world danger

Acronis TRU details CRESCENTHARVEST, targeting Farsi-speaking Iranian protest supporters and diaspora with lures (RARs containing LNK files) leading to a dual-module RAT/stealer. Notable tradecraft includes DLL sideloading using software_reporter_tool.exe (a signed Google binary) plus persistence that leverages Windows NetworkProfile EventID 10000 triggers. Theft includes browser creds/cookies, Telegram session material, and keystrokes.
Sources: Acronis TRU report, BankInfoSecurity

KryptoKat: This is the kind of campaign where “credential theft” is only the first-order effect. For at-risk communities, compromise can translate into coercion offline. Treat it with the urgency you’d assign to physical safety.

Operational nuggets defenders can actually use from the TRU writeup:

  • Hunt oddities like keylog artifacts (example path cited): C:\Windows\System32\spool\Drivers\color\daT.txt
  • Watch for scheduled tasks tied to network profile changes
  • Network blocks/hunts around their listed infra (domain/IP)
    Source: Acronis TRU report

APT28 “MacroMaze”: low-rent tooling, high-rent outcomes

LAB52 tracks Operation MacroMaze, attributed to APT28, leaning into “basic” tooling (batch, VBScript, HTML) and legitimate infrastructure, including browser-based exfil to services like webhook.site. The sophistication isn’t in the malware’s mystique; it’s in the operational discipline: evasion tricks, living inside expected traffic, and making forensic timelines feel like trying to read Snow Crash in a mirror.
Source: Operation MacroMaze

UncleSp1d3r: If your detection strategy is “alert on weird binaries,” APT28 just shrugged and opened the browser.


LuciDoor + MarsSnake: telecom targeting in CIS

Positive Technologies details UnsolicitedBooker activity targeting telecoms in CIS countries, using LuciDoor and MarsSnake for persistence and data movement, with deep IOC/technique mapping and overlap analysis with other China-aligned clusters in the “Panda” ecosystem (their words, not ours).
Source: Poisonous Mars: LuciDoor/MarsSnake

KryptoKat: Telecom intrusions are never “just telecom.” They’re adjacency: identity, interception potential, and the soft underbelly of everyone else’s MFA and reset flows.


macOS Isn’t “Safe,” It’s Just “Different”: DigitStealer’s Infrastructure Tells on It

DigitStealer is back in the conversation, not because the malware is brand new, but because infrastructure pattern analysis makes it easier to hunt. The operator’s C2 posture is unusually uniform (same ASN patterns, consistent hosting behavior), and the malware itself leans on JXA/osascript behavior that’s huntable when you stop pretending macOS endpoints don’t need telemetry. Targets include crypto wallets and Ledger Live, plus browser and Keychain data.
Sources: Cyber and Ramen infrastructure tracking, Jamf Threat Labs background, Cyber Press writeup

UncleSp1d3r: The operator polling every ~10 seconds is the digital equivalent of a thief rattling your doorknob all night. Annoying, loud, and (if you’re logging) useful.


Crimeware Business Updates: RaaS and the Art of the Bluff

Cyderes covers 0APT, a group that started with loud claims and thin proof, and appears to be maturing into an actual RaaS platform with functional encryption (hybrid RSA/AES) and a Rust-based stack. The operational warning here is simple: some crews do level up after a shaky debut.
Source: 0APT Bluff Campaign Evolves Into Potential Threat

KryptoKat: Treat “immature actor” as a time-bound statement, not a comfort blanket.


Scam Season: Sports Fans and Hospitality Staff in the Crosshairs

UncleSp1d3r: Every major event comes with commemorative merch, and commemorative fraud.


Patch Gravity (Linux/OT Edition): Nessus Updates Worth Your Attention

Tenable’s plugin updates this week read like a reminder that Linux patching isn’t one thing; it’s a swarm of kernel issues, core libraries, and distro-specific packaging timelines, plus an OT cameo via Siemens.

KryptoKat: If you run mixed enterprise + OT, don’t miss the process lesson: validate patches fast, but validate them somewhere that won’t turn your PLCs into interpretive dance.


Closing: The Permission Economy Is the Real Perimeter

We keep building higher walls, then handing out more badges. Marketplaces, SaaS notifications, “just download it here,” webhook services, extension ecosystems: none of these are bugs. They’re features. And features are what attackers ride when they want to look ordinary.

If your controls assume “malicious equals unusual,” you’ll keep losing to threats that are boringly normal.