Article

EvilBit Threat Digest - EvilBit Threat Digest: Callbacks, Catfish, and the Proxy in Your Basement

Threat digest on attackers abusing trusted platforms like OAST, SaaS notifications, fake installers, and extension markets to turn user trust into an expanding attack surface.

EvilBit Threat Digest: Callbacks, Catfish, and the Proxy in Your Basement

This week’s vibe: attackers didn’t invent new physics; they just leaned harder on other people’s infrastructure. OAST callback services, “trusted” SaaS notifications, AI/extension marketplaces, and a very convincing fake 7‑Zip site all did their part to make defenders question reality and make incident responders question coffee.


Internet background radiation got teeth (GreyNoise OAST + Ivanti EPMM RCE)

GreyNoise’s latest OAST report is a good reminder that the internet isn’t “scanned”; it’s continuously pinged like a submarine hull, and anything that responds gets cataloged. They tracked 6,197 OAST sessions across 73 campaigns in a single week, with widespread Nuclei-style probing and clustering via TLS/JA fingerprints (GreyNoise Labs Weekly OAST Report).

The headline, though, is confirmed exploitation of Ivanti Endpoint Manager Mobile (EPMM) CVE‑2026‑1281, with activity tied to bulletproof hosting infrastructure. This isn’t theoretical “scan noise”; GreyNoise calls out functional exploitation attempts and even the suspicious endpoint pathing, including attention to /mifs/c/appstore/fob/ and payloads consistent with command injection behavior (they mention dig explicitly) (NVD: CVE-2026-1281, Ivanti advisory, Horizon3.ai writeup, CrowdSec tracking).

KryptoKat: The operational lesson here isn’t “block some domains.” It’s that OAST is now a routine part of exploitation pipelines: attackers validate egress, confirm command execution, then decide whether you’re worth the next stage. If your environment treats outbound DNS/HTTP as a moral right instead of a privilege, OAST turns your perimeter into a confession booth.

UncleSp1d3r: Also: bulletproof hosting keeps showing up like the same villain in a season of The X‑Files. Different monster-of-the-week, same sewer entrance.

Actionable takeaways (no magic, just hygiene):

  • Patch Ivanti EPMM to 12.8.0.0 (Ivanti’s guidance) and verify you didn’t just “patch forward” while leaving exposed orphan instances behind (Ivanti advisory).
  • Consider blocking known OAST callback zones GreyNoise highlighted (*.oast.pro, *.oast.live, *.oast.fun, *.oast.me, *.oast.site) where it won’t break business flows (GreyNoise Labs Weekly OAST Report).
  • Treat any public-facing enterprise admin surface in their target list (Commvault, Grafana, SysAid, Oracle EBS, Confluence, OFBiz, etc.) as “being actively auditioned for compromise,” even if exploitation isn’t confirmed for each one this week (GreyNoise Labs Weekly OAST Report).

Trojan installers are back, and they want your IP address (fake 7‑Zip → proxyware botnet)

A fake 7‑Zip download site, 7zip[.]com (not the real 7-zip.org), distributed a trojanized installer that enrolls Windows machines into a residential proxy network (“upStage Proxy”). Victims don’t just get infected; they get monetized as infrastructure, useful for fraud, credential stuffing, ad abuse, and general skulduggery routed through “legit-looking” home IPs (Luke Acha analysis, Malwarebytes coverage, BleepingComputer).

What makes this worth your time:

  • Persistence as a Windows service, plus firewall rule modification to keep the proxy reachable.
  • XOR-encoded C2/protocol behavior (documented in the deep dive), and a spread of domains/endpoints tied to the operation (Luke Acha analysis).
  • The “proxyware” angle changes incident severity: your host becomes a launchpad, and your abuse desk becomes a crime scene.

UncleSp1d3r: I love a good installer trojan. It’s the floppy-disk virus era, but now with TLS and a subscription model.

KryptoKat: If you run corporate Windows fleets, treat this like more than adware. Proxyware means reputational damage (your IP shows up in someone else’s attack), plus the usual “what else rode along” question.


CRESCENTHARVEST: dissident targeting with DLL sideloading and browser/Telegram theft

Acronis TRU dropped a detailed report on CRESCENTHARVEST, a cyberespionage campaign aimed at Farsi-speaking Iranian protest supporters and diaspora, using protest-themed lures and a two-module stealer/RAT setup. The theft targets are chillingly practical: browser creds/cookies/history, Telegram Desktop sessions, and keylogging, the kind of collection that can enable real-world harassment and intimidation (Acronis TRU, BankInfoSecurity, SecurityOnline).

Tradecraft notes that matter to defenders:

  • Initial access via RAR archives containing LNKs (because it’s 2026 and we still can’t have nice things).
  • DLL sideloading using software_reporter_tool.exe (a Google binary) as the signed loader anchor.
  • Event-based persistence via scheduled tasks triggered on Windows NetworkProfile events, subtle enough to dodge “run key only” hunting (Acronis TRU).

KryptoKat: Campaigns like this are why “just use Signal” isn’t a security strategy. Session theft turns secure messaging into theater, and the victims aren’t theoretical.


“Trusted platform” abuse, Part I: Jira Cloud as a phishing cannon (UPDATE angle)

We’ve been stuck in a loop lately: attackers don’t need your SMTP server if they can borrow someone else’s. Trend Micro details a campaign abusing Atlassian Jira Cloud notifications to deliver spam/phishing at scale, banking on the fact that Jira emails look routine in enterprise environments and sail past tired human suspicion (Trend Micro).

Fresh angle to watch: treat SaaS collaboration tooling as outbound comms infrastructure, not just apps. The question for blue teams isn’t “can users spot the phish?” but rather “who can create Jira instances/projects, and what guardrails exist before it turns into a mail relay?”


“Trusted platform” abuse, Part II: AI skill marketplaces and extension stores keep shipping trouble (UPDATE cluster)

Two separate stories, same underlying sin: plug-in ecosystems optimize for frictionless installs, and attackers optimize for that.

  • ClawHub skills are being used as lures, with payloads hosted on external sites to bypass marketplace scanning. The “skill” becomes the trust hook; the external site does the dirty work (OpenSourceMalware).
  • Annex documents a worm-like campaign in code extensions hitting finance/e-commerce targets, with obfuscation and legit services in the mix, a supply chain risk wearing a developer-friendly hoodie (Annex).

UncleSp1d3r: The most successful malware distribution UX is still: “Step 1: paste this command.”

KryptoKat: If your org allows arbitrary extensions/skills/plugins, you’re not managing software; you’re running a community theater where anyone can walk on stage.


Ransomware theater → real platform: 0APT grows up

Cyderes profiled 0APT, a group that started with loud claims and “big bad ransomware energy,” but now appears to have built a functioning RaaS platform with a working encryptor using a hybrid RSA/AES scheme (Rust-based). Even if victim counts were initially inflated, the trajectory matters: a bluff can become an on-ramp for affiliates and real-world damage (Cyderes).

UncleSp1d3r: Nothing says “we’re serious now” like shipping actual crypto code instead of PowerPoint.


Fraud season: Olympics merch scams (and the eternal Booking.com cosplay)

Malwarebytes tracked a set of fake Winter Olympics 2026 merch shops, cloning the official brand and aiming for payment card/PII theft. It’s not novel, but it’s timely, and it scales well because excitement is the best social-engineering accelerant (Malwarebytes).

Separately, Bridewell wrote up a Booking.com impersonation phishing campaign aimed at hotels/customers. Details in our feed were partially corroborated earlier, but the pattern is familiar enough that hospitality orgs should assume it’ll keep coming: fake portals, credential harvest, and follow-on fraud (Bridewell).


Patch & vuln ops: Nessus lit up Linux and ICS again

Three Tenable plugin update drops this week broadened coverage across Linux distributions and core components -- kernels, glibc, crypto libs, and a grab bag of enterprise packages. No single “internet is on fire” CVE here, but it’s the kind of cumulative risk that becomes an incident when paired with weak privilege boundaries or sloppy access controls (Tenable plugin updates).

Also worth calling out: the Feb 16 update included a cluster of Linux kernel CVEs (use-after-free, OOB read/write, races) and Siemens SIMATIC S7-1500 ecosystem mentions, a reminder that OT/ICS environments still inherit a lot of “normal” Linux risk, just with much worse patch windows (Tenable plugin updates, NVD: CVE-2025-39866).


Closing: The new perimeter is “whatever your users already trust”

KryptoKat: This week didn’t bring one cinematic exploit chain; it brought a dozen small betrayals of trust: SaaS notifications, installer lookalikes, marketplaces, callback infrastructure. The perimeter isn’t a firewall anymore. It’s a long list of assumptions.

UncleSp1d3r: If you need me, I’ll be in the corner muttering “download from the vendor” like it’s an ancient spell.


Patch list (for vuln ops triage)