Archive for CloudSEK

Guest Post: Exposed Server Reveals Aurora Ransomware Affiliate’s Attacks on 20+ Organisations, AI-Assisted Planning and Crypto Trail

Posted in Commentary with tags on August 27, 2026 by itnerd

An exposed server belonging to an Aurora ransomware affiliate has revealed months of attack activity against more than 20 organisations across nine countries, giving researchers an unusually detailed view of how a ransomware operator moves from network compromise to data theft, encryption, extortion and payment laundering.

The exposed directory contained the operator’s Linux home directory, shell history, credential material, attack tooling, victim data, AI-assisted planning sessions and the Aurora ransomware encryptor itself, a CloudSEK investigation has revealed.

Working with TRM Labs, CloudSEK also traced a ransom payment on-chain. TRM Labs’ wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims, with the funds ultimately converging through shared laundering infrastructure.

The findings provide a rare attacker-side view of a ransomware operation, showing not only the tools and techniques used to compromise organisations but also how the attacker planned intrusions, deployed ransomware and handled the financial proceeds.

20+ organisations compromised, 17 reached at domain or interactive level

The operator was active across the exposed dataset between April and July 2026 and compromised more than 20 organisations in nine countries.

CloudSEK found that the attacker achieved domain-level or interactive access at 17 organisations. Four of the organisations recorded in the attacker’s files were subsequently listed on Aurora’s public leak site, connecting the activity observed inside the operator’s infrastructure with later public extortion.

The victim set covered multiple industries, including manufacturing and industrial organisations, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases, the attacker obtained highly privileged access or sensitive material, including domain administrator credentials, Kerberos tickets, VPN credentials, Group Policy information, backup-system credentials and other authentication data.

Most of the affected organisations identified in the dataset have not appeared on public ransomware leak sites. CloudSEK initiated coordinated notification with relevant national CERTs and/or affected organisations before publication for victims that had not already been publicly identified.

AI coding assistant used to plan real-world attacks

One of the most significant findings was the operator’s use of Cursor, an AI-powered coding assistant, during attack planning.

Recovered sessions showed the attacker using Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history showed sustained back-and-forth use of the AI tool during victim engagements.

The finding offers direct visibility into how readily available AI tools are being incorporated into cybercriminal workflows, not merely for generating code, but for planning and working through attack paths against enterprise environments.

A repeatable playbook for compromising enterprise networks

The exposed directory allowed CloudSEK researchers to reconstruct a repeatable attack methodology used across multiple targets.

The operator repeatedly performed Active Directory and SMB discovery, retrieved password policies and carried out Kerberoasting and AS-REP Roasting. For privilege escalation, the attacker relied on several techniques depending on the environment, including a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6 and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was also stored in the exposed environment. Much of it consisted of public proof-of-concept code, while some tooling had been modified and a FortiOS toolkit had been rebuilt as an independent framework.

The operator maintained custom NetExec modules, including tools designed to collect browser credentials across multiple browsers and identify ESXi infrastructure.

CloudSEK assesses with high confidence that the individual was operating directly as an Aurora ransomware affiliate rather than functioning solely as an initial-access broker. The activity continued beyond obtaining access into credential theft, domain compromise, exfiltration, ransomware staging and extortion.

Aurora ransomware built in Zig targets Windows, Linux and ESXi

The exposed environment also contained multiple versions of the Aurora encryptor for Windows and Linux/ESXi systems.

Both versions were written in Zig, a relatively uncommon programming language in ransomware development. The Windows and Linux variants appear to have been built from the same Zig codebase and compiled for different operating systems.

The encryptor supports several options designed to speed up or customise encryption, including partial-file encryption, multithreading and file-size restrictions.

The Linux/ESXi version contains functionality specifically designed for virtual infrastructure. Before encryption begins, the ransomware enumerates running virtual machines and force-terminates them. It also handles ransom-note delivery differently: instead of simply dropping a note as a file, it can modify the ESXi host’s SSH login banner so that the ransom message appears when administrators connect to the server.

The report includes indicators of compromise and a detection rule designed to identify this behaviour.

Following the ransom payment trail

The exposed files also provided researchers with visibility into the financial side of the operation. The wallet address the operator provided for payment was found to hold 7 BTC at the time of analysis, a balance more consistent with accumulated proceeds from several victims than a single payment, and itself a strong indicator that this operator’s activity generates significant revenue.

A key recovered from the Aurora encryptor allowed CloudSEK to access records from a completed ransom negotiation. The victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and examined how the funds moved after payment.

The wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims. While each payment began on a separate path, several later converged at shared consolidation points before moving towards cash-out infrastructure.

Researchers also observed differing splits across the payments analysed, including 35/65, 21/79, 46/54 and 40/60, with no single ratio consistently repeated. The finding suggests that, across the transactions examined, the division of proceeds between participants was not based on a single fixed percentage.

Most of the traced funds passed through two dominant consolidation clusters before reaching cash-out addresses. One payment followed a different route through a peeling chain, where funds were gradually moved across a sequence of transactions rather than through the main consolidation hubs.

The financial activity observed in the investigation suggests that Aurora-linked ransomware activity may extend beyond the victims visible on public leak sites. 

Russian-speaking operator, CIS targets absent from observed dataset

CloudSEK assesses with high confidence that the operator is Russian-speaking.

The assessment is based on material created directly by the attacker, including Cursor conversations, module documentation and session notes written in Russian.

Researchers also found that no CIS-allocated IP ranges or CIS-country domains appeared in three months of the operator’s target lists, scans or success logs.

CloudSEK’s assessment relates to the operator’s language and the targeting behaviour visible in the recovered dataset and does not establish the individual’s nationality or physical location.

Why the investigation matters

Ransomware investigations typically begin after an organisation has already been compromised, forcing defenders and researchers to reconstruct an attack from the victim’s environment.

In this case, the exposed directory provided visibility from the other side.

Researchers were able to examine the attacker’s working environment, understand how organisations were enumerated, follow privilege-escalation attempts, review stolen credentials and attack tools, observe the use of AI during operational planning, analyse the ransomware itself and follow a victim payment into cryptocurrency laundering infrastructure.

Taken together, the findings provide an unusually detailed picture of the operational lifecycle of a modern ransomware affiliate, from enterprise intrusion and data theft to encryption, extortion and the movement of ransom proceeds.

The full report also includes technical indicators of compromise, attacker infrastructure, malware hashes, detection rules and detailed mitigation recommendations to help organisations identify and defend against similar activity.

For more information, read the full report.

2,500+ Organisations and 434,000 CI/CD Pipelines Potentially Exposed in the Largest AI Supply Chain Breach of 2026

Posted in Commentary with tags on August 11, 2026 by itnerd

More than 2,500 companies and approximately 434,000 CI/CD pipelines worldwide were potentially exposed in what is believed to be the largest supply-chain attack targeting AI infrastructure in 2026.

In March 2026, threat actor group Team PCP compromised LiteLLM, a widely used open-source AI gateway. CloudSEK Threat Intelligence subsequently reconstructed the victim exposure and is now sharing details of impacted organisations to help security teams identify potential exposure and take remedial action.

The affected LiteLLM packages were reportedly available through PyPI for only around 40 minutes. However, automated CI/CD environments can download and execute dependencies rapidly, allowing even a short-lived compromise to create prolonged security risk.

Among the information potentially accessible from affected environments were AWS, Google Cloud and Microsoft Azure credentials, SSH keys, Kubernetes tokens, CI/CD secrets, repository credentials, environment variables and LLM/API keys.

CloudSEK’s exposure dataset includes high-confidence matches associated with major global organisations including NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales and London Stock Exchange Group, among others.

CloudSEK stresses that an exposure match does not automatically confirm successful compromise, data theft or malicious use of credentials. Organisations identified in the dataset should validate their exposure and investigate relevant systems.

The Threat May Outlive the Original Attack

The significance of the incident extends beyond the malicious package itself.

Once credentials are copied from an affected environment, removing the compromised software does not invalidate those credentials. According to CloudSEK’s analysis, stolen access can potentially be reused, sold or weaponized even after the malicious package has been removed, creating the possibility of downstream attacks weeks or months later.

The FBI also issued FLASH-20260702-01 on July 2, 2026, covering cybercriminal group TeamPCP, further highlighting the continuing security concern surrounding the campaign.

CloudSEK is sharing the exposure research openly so affected organisations can identify possible exposure, rotate credentials, investigate suspicious activity and harden their environments before compromised access is reused.

AI Infrastructure Is Becoming a High-Value Target

The LiteLLM incident also reflects a broader shift in cyberattacks.

AI gateways, MCP servers, agentic systems, vector databases and other AI infrastructure increasingly sit between sensitive corporate data, identities, cloud services and systems capable of taking action.

This makes AI infrastructure an attractive target for attackers seeking access beyond a single application. CloudSEK assesses that future attacks are increasingly likely to target the AI layer precisely because of how deeply it is connected to enterprise environments.

CloudSEK AIVigil: Continuous AI Attack Surface Monitoring

The growing attack surface around enterprise AI is the security problem CloudSEK AIVigil is designed to address.

AIVigil continuously discovers and monitors exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows and shadow AI. It combines CloudSEK’s cyber threat intelligence with AI exposure monitoring to help security teams identify exposed assets, credentials and attack paths before they develop into wider enterprise incidents.

Check Your Exposure

Organisations can use CloudSEK’s free exposure-checking tool to determine whether credentials associated with their environment appear in the identified dataset:

Free Exposure Checker:  https://exposure.cloudsek.com/ai-supply-chain-incident 

Full Research Report: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines 

Full List Of Exposed Companies: TeamPCP CI/CD Secret Exposure — Check if your organisation is affected | CloudSEK

UPDATE: Rohit Valia, CEO of cybersecurity company Tumeryk, provided the following comments: 

“Incidents like the recent LiteLLM supply chain compromise show that a single unrevoked token in an open source build chain can result in an ecosystem-wide exposure. Open source innovation is essential to the pace of AI development, but enterprises need more than the raw project — they need it hardened, tested, and accountable. It also needs to be put through rigorous security validation before it reaches production. Sanctioned shouldn’t just mean ‘permitted’ — it should mean proven.”

UPDATE #2: Seemant Sehgal, Founder & CEO, BreachLock adds this:

   “The malicious packages were live for 40 minutes, but the window mattered to defenders long after it mattered to the attacker. Any system that pulled 1.82.7 or 1.82.8 during those 40 minutes ran malware on every subsequent Python startup, meaning credentials harvested from those environments have been sitting in attacker hands since before most teams knew there was an incident.

   “Cloud keys, SSH keys, AI provider tokens, and package-publishing credentials from 434,000 CI/CD pipelines enable access, and access can be used quietly for a long time before anyone sees the effect. The initial scanner compromise fed LiteLLM’s CI pipeline, which pushed malware to PyPI. The affected organizations were two steps removed from the original breach, with every link in the chain working exactly as designed.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “One of the biggest takeaways from this latest LLM attack, especially when viewed alongside the recent wave of malicious NPM packages, is that sophisticated attackers are increasingly focused on the software supply chain. They’re looking for opportunities to compromise the tools and components that everyone trusts because that gives them an enormous amount of reach.

   “What concerns me most about this attack isn’t just its scope, although the scope is certainly significant. It’s how difficult it would be for many organizations to detect. These attacks often operate outside the visibility of traditional security controls.

   “In many ways, this reminds me of the early days of internet worms like Conficker, SQL Slammer, Blaster, and Nachi. Those threats spread incredibly fast, and because they were so loud, the entire security industry mobilized to detect them, contain them, and ultimately build better defenses.

   “I think we’re seeing something similar with supply chain attacks today. Right now, attackers are going big. They’re compromising widely used packages and trying to maximize their impact. My concern is what happens after this phase. History tells us that attackers eventually become more disciplined. Instead of going after everything, they’ll become more selective, targeting the specific packages, libraries, and dependencies that give them access to the organizations they actually want to compromise.

   “That’s why I see these attacks as a harbinger of what’s coming next. They’re already difficult to detect because they exist outside the normal visibility of EDR platforms, firewalls, and traditional intrusion detection and prevention systems. As attackers become more targeted and more subtle, that detection problem is only going to get harder for defenders.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Forty minutes was the theft. Five months later, the FBI is still warning that the stolen credentials will be weaponized.

   “I’ve been tracking TeamPCP’s campaign since they hit Aqua Security’s Trivy scanner in March. LiteLLM’s CI pipeline pulled Trivy from apt without pinning a version. One poisoned build later, the attackers had LiteLLM’s PyPI publishing credentials and pushed two malicious versions that ran code at Python startup, no import needed, bypassing the install-script protections most teams count on.

   “2,500 organizations and 434,000 pipelines from that window. Automated build systems explain the math. They pull dependencies in seconds, cached layers spread them further, and a poisoned package rides the distribution network into every downstream consumer before anyone notices.

   “TeamPCP has used this playbook all year. Trivy, LiteLLM, Microsoft’s durabletask-python twice, always re-entering through credentials that survived the previous cleanup. SANDCLOCK grabbed cloud keys, Kubernetes tokens, SSH keys, AI provider credentials, everything the runner could reach. Those stolen credentials often valid until someone actively revokes them.

   “Organizations with a Software Bill of Materials (SBOM) knew within hours whether LiteLLM 1.82.7 or 1.82.8 was anywhere in their stack. A mandated delay on dependency updates, even an hour, would have cleared the entire 40-minute window before either version installed. Pin CI dependencies to verified hashes, scope runner credentials to the minimum each job needs, and if you ran either version, rotate every secret that runner could reach.”

France Recorded Over 145 Million Data Exposures in Two Years as Dark Web Activity Targeting the Country Quadrupled

Posted in Commentary with tags on July 23, 2026 by itnerd

France-linked underground cyber activity has increased more than fourfold over the past two years, with stolen credentials, personal data, ransomware advisories and hacktivist claims rising sharply across dark web forums and cybercriminal channels.

Monthly activity climbed from fewer than 300 items in mid-2024 to more than 1,400 at its peak in January 2026. It remained above 1,000 items per month through spring 2026, pointing to a sustained expansion of the underground market for French data rather than a short-lived spike caused by a single breach.

These findings are part of a new CloudSEK report, France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends,” which analysed approximately 17,800 France-related threat intelligence items recorded over 24 months.

The report shows that stolen credentials and infostealer logs account for a significant share of the increase, while government organisations, financial services, technology companies and telecom providers remain among the most exposed sectors.

It also highlights a parallel rise in ransomware activity targeting smaller organisations and municipalities, alongside sustained pro-Russian hacktivist campaigns against French ministries, aviation entities, drone manufacturers and other policy-linked organisations.

Stolen credentials are driving the underground market

The increase is being fuelled primarily by the mass harvesting and circulation of passwords, authentication data and personal information, rather than only by large corporate breaches.

The research identified:

  • 4,447 account credential exposures
  • 4,360 credential collections
  • 4,011 combined datasets
  • 3,565 breached-record listings
  • 977 authentication-token exposures

This pattern reflects the growing use of infostealer malware, which extracts credentials, browser data, cookies and authentication tokens from infected systems. The stolen information is then packaged into combolists, sold on underground forums or distributed freely to support fraud and account takeover. 

CloudSEK researchers found that this low-cost, high-volume model is making stolen access easier to acquire and reuse across multiple platforms.

French personal data is being traded at low cost

In one case, approximately two million records allegedly belonging to French women were advertised for $399. In another, nearly 489,000 French records were distributed through a forum-based access mechanism rather than offered through a conventional sale.

The research also identified fabricated databases advertised in the names of trusted French institutions, including ANTS, the national secure-documents agency, and CPAM, the national health insurance system.

Such activity can enable phishing, impersonation and fraud even when the institution named in the listing has not suffered a confirmed breach.

Government organisations face the highest exposure

CloudSEK research shows that government recorded the highest level of France-related exposure over the two years, with 1,652 items.

It was followed by:

  • Financial services: 1,594
  • Technology: 1,491
  • Telecommunications: 1,480
  • Email-related exposure: 1,427
  • Retail: 1,197
  • E-commerce: 1,089

The prominence of government reflects a combination of leaked credentials, ransomware pressure on municipalities and politically motivated targeting of ministries and public agencies. 

Ransomware pressure is concentrated on smaller organisations

The research recorded 213 France-tagged ransomware advisories over the past six months. Some victims were posted more than once, meaning the total should not be interpreted as the number of unique organisations attacked.

Even after accounting for repeated listings, the data shows that municipalities and smaller organisations remain recurring targets, particularly where security teams and incident-response capabilities are limited.

Groups including Qilin and MedusaLocker were linked to claims involving French local authorities. Repeated listings of the same victim suggest that ransomware operators may use staged disclosures to prolong pressure during extortion attempts.

Pro-Russian hacktivism adds a geopolitical threat

The report identified 742 France-related hacktivism items over six months, with the activity dominated by the pro-Russian group NoName057(16). 

The group claimed distributed denial-of-service attacks and unauthorized access involving French ministries, civil aviation bodies, drone manufacturers and private organisations.

Several of these campaigns were explicitly framed as retaliation for France’s support for Ukraine and its position on sanctions against Russia.

CloudSEK assesses that this activity represents a continuing operational risk for organisations associated with government, defence, aerospace and public policy, rather than an isolated wave of disruption.

Regulatory consequences are becoming more serious

The rise in underground cyber activity is taking place alongside stricter enforcement of data-protection and security obligations in France. Recent CNIL actions have focused on failures such as inadequate authentication, excessive access permissions and insufficient protection of personal data.

These weaknesses closely mirror the patterns identified in the report, particularly credential exposure, weak access controls and third-party risk.

For affected organisations, the impact of a breach can therefore extend beyond operational disruption to include regulatory penalties, mandatory remediation and reputational damage.

Tomorrowland 2026 Becomes a Scam Magnet for Fake Ticket Portals, Warns CloudSEK

Posted in Commentary with tags on July 14, 2026 by itnerd

CloudSEK’s threat intelligence researchers have uncovered a set of fake and unauthorised websites exploiting the global demand for Tomorrowland Belgium 2026, one of the world’s largest electronic music festivals. The scams and brand-abuse pages target fans searching for sold-out tickets, last-minute travel options, accommodation and festival-related packages.

Tomorrowland Belgium 2026 will be held across two weekends, from 17 to 19 July and 24 to 26 July, at De Schorre in Boom, Belgium. The festival attracts around 400,000 attendees from more than 200 countries, making it a high-value target for scammers who rely on urgency, scarcity and fear of missing out to push victims into quick decisions.

CloudSEK’s research found that searches using Tomorrowland-related terms such as DreamVille, Global Journey and Full Madness surfaced around a dozen live impersonation sites. These included fake ticket shops, lookalike booking pages, travel-package lures and accommodation-focused pages using Tomorrowland branding.

One of the clearest examples identified by CloudSEK was a fake ticket shop titled “Discover Adscendo | TOMORROWLAND Belgium 2026.” It copied the look and feel of a festival ticketing page, used a live countdown timer to pressure users and mixed real Tomorrowland details with false claims to appear credible.

The site used accurate references such as the De Schorre venue, Boom location, festival dates, DreamVille camping and Tomorrowland’s cashless “Pearls” ecosystem. It also used official-sounding anti-scalping and ticket-personalisation language. However, the page falsely claimed that buyers had to complete “biometric registration” to receive “legal personalized barcodes.”

The fake funnel was designed to collect full identity data, phone numbers, email addresses, delivery addresses and payment details. It also used the pretext of shipping a “limited-edition Tomorrowland Treasure Box” to justify collecting home addresses. According to CloudSEK, the language around “no electronic tickets or entry QR codes” was used to reduce suspicion when victims did not receive a digital ticket.

CloudSEK also found that the fake payment page displayed a €179 Day Pass inside a so-called “Regulatory Payment Portal.” The page used invented security and compliance language, including “structural card alignment,” “secure order tokens” and “secure gateway by Stripe.” The payment link led to a genuine Stripe checkout page, but the merchant shown was INEK HOUSE SL, not Tomorrowland or any festival-related entity. 

A second recovered storefront, billetterie-tomorrowland[.]com, targeted French-speaking users. The site used a Shopify storefront template and sold two products, a Day Pass and a Comfort Day Pass. The page included standard e-commerce elements such as discount-code fields, shipping options, cart pages and app store footer buttons, making it look like an ordinary online shop. The checkout was in French and routed the buyer to PayPal. CloudSEK noted that the PayPal page itself was genuine, but the receiving payee was not Tomorrowland or a festival entity.

Beyond ticketing, CloudSEK also identified a Tomorrowland and Airbnb-branded accommodation aggregator hosted on Cloudflare Pages. The page, tomorrowland-airbnb.pages.dev, displayed 40 Airbnb-style listings and 56 hotel listings, pinned to the real Weekend 2 dates. It used badges such as “Best Value,” star ratings, review counts, location details and travel-time estimates to Boom.

CloudSEK assessed that this accommodation page did not directly collect card details or process payments. Its buttons redirected users to genuine Airbnb and hotel-booking listings, suggesting likely affiliate monetisation rather than direct financial theft. However, the page used Tomorrowland and Airbnb names and styling without authorisation, creating user confusion and brand-abuse risk. 

The report also highlights localised Tomorrowland-themed lures in different European languages. A French-language fake ticket shop targeted French-speaking users, festreisen[.]com used German-language festival travel branding, and jedemenatomorrowland[.]cz used Czech-language travel-package messaging. This indicates that scammers are not only relying on generic English-language scams, but are adapting campaigns for specific regional audiences.

CloudSEK said the impact on festival-goers can be significant. Victims may pay for tickets or accommodation that do not exist, lose money through hard-to-reverse payment methods, expose personal and payment data, receive invalid tickets and discover the fraud only after reaching the venue. The same data can also be used later for phishing, fake refund offers and repeat event scams.

CloudSEK Advisory for Festival-Goers

CloudSEK advises fans to buy tickets only through Tomorrowland’s official ticketing, authorised resale and Global Journey platforms. Users should manually type the official website address instead of clicking links from ads, social media posts, emails or messages.

Festival-goers should treat requests for “biometric registration,” bank transfers, cryptocurrency, gift cards or urgent off-platform payments as red flags. They should also check the domain carefully, especially for doubled letters, misspellings, unusual extensions or festival-themed third-party pages.

For accommodation, CloudSEK recommends booking directly through trusted platforms and avoiding festival-branded intermediary pages that redirect to hotels or rentals without clear authorisation. Paying by credit card, where possible, can also improve the chances of recovery if a transaction turns out to be fraudulent.

The report is here: Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today | CloudSEK

CloudSEK and Tech Mahindra Announce Partnership to Enable Predictive, Regulation-Ready Cybersecurity at Scale

Posted in Commentary with tags on July 9, 2026 by itnerd

CloudSEK today announced a partnership with Tech Mahindra a leading global provider of technology consulting and digital solutions to enterprises across industries. 

The partnership will deliver AI-driven threat intelligence, attack surface monitoring, AI attack surface monitoring, and digital risk protection solutions globally.

Evolving cybersecurity regulations are driving enterprises to strengthen risk visibility, accelerate incident response, and enhance compliance readiness.

Regulatory and national cybersecurity frameworks such as NIS2 and DORA in Europe, CERT-In mandates, CIRCIA and SEC cyber-disclosure rules in the US, DPDP Act in India, and similar initiatives across the Middle East are increasing expectations around continuous monitoring, third-party risk oversight, and timely breach detection and reporting. 

In response, organizations are rapidly adopting intelligence-led, real-time cybersecurity approaches that enable proactive risk identification, faster decision-making, and improved resilience, making integrated, AI-driven threat intelligence and digital risk protection capabilities essential to meeting both security and compliance objectives. 

By combining CloudSEK’s AI-native predictive cyber intelligence platform with Tech Mahindra’s global cybersecurity services capabilities, the partnership offers a faster and more operationally scalable approach to regulatory compliance. CloudSEK’s ability to continuously monitor external and AI-driven attack surfaces, correlate threats, and identify real attack paths enables early risk detection and prioritization. Integrated with Tech Mahindra’s advisory, implementation, and managed security services, this enables enterprises to accelerate compliance execution, reduce response timelines, and operationalize regulatory requirements more efficiently across complex and dynamic digital environments.

The partnership is focused on enabling telcos and large enterprises across industries worldwide to respond to rapidly tightening cybersecurity regulations that demand immediate action. By combining CloudSEK’s AI-driven predictive threat intelligence with Tech Mahindra’s global delivery and managed security capabilities, the collaboration provides a scalable, real-time solution to help enterprises act now reducing compliance risk, improving response speed, and strengthening resilience across critical digital infrastructures.

1.8 Million Credential Attacks Target Business Phone Systems as CloudSEK Records 15 Million SIP Events

Posted in Commentary with tags on June 23, 2026 by itnerd

Internet-facing business telephone systems are being targeted through sustained and automated attacks designed to steal credentials and generate fraudulent international calls, CloudSEK researchers have found.

During an 18-day observation period, a controlled Session Initiation Protocol, or SIP, honeypot recorded more than 15.18 million telemetry events, representing approximately 3.79 million SIP requests from 323 source IP addresses.

The campaign included 1,869,521 authentication attempts against 29,433 telephone extensions and 89,465 attempted calls, indicating a coordinated attack pipeline moving from reconnaissance and password spraying to suspected financial fraud.

CloudSEK researchers recovered a live attacker dictionary containing 277,632 unique passwords and 1.49 million extension-password combinations. The plaintext password used could be determined in 96.09% of all credential attempts.

The findings show that attackers were not relying only on weak passwords. The dictionary also contained medium- and high-complexity credentials, suggesting the use of device defaults, previously exposed passwords and attacker-curated wordlists.

UK Numbers Dominated Suspected Toll-Fraud Activity

Of the 89,465 attempted calls, 47,273 targeted United Kingdom numbers, primarily across a limited set of rural and Northern Ireland ranges.

The activity was consistent with International Revenue Share Fraud, in which criminals attempt to use compromised or misconfigured business phone systems to call revenue-generating numbers, leaving the victim organisation responsible for the charges.

Attackers repeatedly dialled the same destinations using different international and outbound prefixes to identify a format permitted by the PBX. One UK number was attempted using more than 80 prefix variations.

Credential Replays Point to a Wider Operation

Researchers also identified 45,580 authentication attempts containing credentials or authentication realms harvested from other systems.

These included references to Asterisk, Intelbras, Grandstream and STARFACE systems, as well as external and private IP addresses associated with other PBX environments.

The findings indicate that some attackers may be maintaining a broader collection of scanned or compromised phone systems and reusing harvested authentication material across multiple targets.

Attacks Originated Primarily from Hosting Infrastructure

CloudSEK found that 99.8% of source-attributed traffic originated from datacenter or hosting ranges, while 93.5% of attacker IP addresses were already listed by third-party intelligence services as known sources of abuse.

The campaign operated continuously throughout the day, indicating unattended automation. Attackers also spoofed legitimate device identities, including FreePBX, Cisco, Polycom and Avaya, to make malicious traffic appear genuine.

The study was conducted using a controlled honeypot that recorded attack activity but did not accept credentials or complete any calls.

Click here to read the entire report: THE 5060 SIEGE – Industrialized Attacks Against the SIP Telephony Ecosystem

Operation Escaneo: Inside a Cyber Campaign Targeting Mexico’s Government and Financial Sector 

Posted in Commentary with tags on June 17, 2026 by itnerd

Mexican government agencies, financial institutions and critical infrastructure are being targeted through a sophisticated intrusion campaign capable of exploiting perimeter devices, stealing credentials and maintaining long-term access inside compromised networks.

CloudSEK researchers have uncovered the attacker’s exposed staging server, providing a rare view into the infrastructure, tools and tactics behind Operation Escaneo.

The investigation revealed:

  • A custom reconnaissance platform called Kimera
  • Exploits targeting Fortinet, Ivanti, Cisco, SAP, Oracle and Windows systems
  • Evidence of more than 1.3 million PII records being extracted
  • Exfiltration of a 407 MB Active Directory dataset
  • Webshells, reverse tunnels and compromised routers used for persistent access
  • CloudSEK’s analysis identifies significant operational and tactical links between the campaign and MexicanMafia, also known as PanchoVilla.
     

The report shows how the campaign progresses from mass reconnaissance and exploitation to lateral movement, credential theft, data exfiltration and long-term persistence—posing a serious risk to public-sector and financial networks across the region.

Full report: https://www.cloudsek.com/blog/operation-escaneo-mexican-government-financial-institutions-cyberattack

BlueKit’s P2P phishing infrastructure makes detection and takedowns harder says CloudSEK

Posted in Commentary with tags on June 17, 2026 by itnerd

Phishing platforms are no longer stopping at stolen passwords. CloudSEK researchers have uncovered how BlueKit is evolving into a full-scale criminal SaaS platform that can hijack active sessions, enrol attacker-controlled passkeys, change passwords and lock victims out of their accounts almost immediately.

The most significant finding is BlueKit’s migration to a peer-to-peer phishing-page rendering architecture, designed to conceal its backend infrastructure from browser developer tools and conventional network analysis. This makes reverse-IP tracking, infrastructure fingerprinting, automated scanning and traditional IOC-based detection considerably more difficult.

CloudSEK’s investigation also identified:

  • 87 ready-made phishing kits targeting banks, cloud platforms, cryptocurrency exchanges, enterprise services and global consumer brands
  • Automated post-compromise workflows for Google, Microsoft and Amazon accounts
  • Session-cookie theft that can undermine conventional MFA protections
  • A Google Ads workflow capable of adding an attacker as an account administrator
  • Ledger and Trezor templates designed to steal cryptocurrency wallet recovery phrases
  • BlueKit’s complete 29-table database schema, including victim records, operator accounts, reseller infrastructure and cryptocurrency payment data
  • A reseller and white-label model that allows other cybercriminal groups to rebrand and distribute the platform

While BlueKit has been previously documented, CloudSEK’s research provides a deeper view into its evolving architecture, internal database, commercial ecosystem and automated account-takeover capabilities.

Full report: https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas

npm Supply Chain Worm Uses Tor C2 to Steal Developer Credentials

Posted in Commentary with tags on May 14, 2026 by itnerd

CloudSEK’s TRIAD team has uncovered a sophisticated npm supply chain attack involving a typosquatted package named crypto-javascri, designed to mimic the widely used crypto-js library.

The package was published on npm on May 11 and carried a Rust-based binary that harvested npm and GitHub credentials from developer machines. Once executed, it used compromised maintainer accounts to silently republish trojanized versions of legitimate packages, turning a single infected developer environment into a wider supply chain risk.

What makes this campaign significant is its use of a weaponized Arti Tor client for command-and-control. This allows the malware to operate through Tor hidden services, making it harder for defenders to block infrastructure using conventional IP, domain, or certificate-based controls.

CloudSEK found that the malware targets Linux developer systems and CI/CD environments, establishes persistence through systemd user services, and includes credential theft, crypto-wallet targeting, cryptomining indicators, and privilege escalation capability.

The broader impact is serious: one compromised developer machine or CI/CD environment could allow attackers to push malicious updates under trusted maintainer identities, exposing downstream users who install what appears to be a routine package update.

The full report is here: https://www.cloudsek.com/blog/inside-a-tor-backed-supply-chain-worm 

Iranian Cyber Group APT35 Had Already Mapped Every Country Bombed in Operation Epic Fury

Posted in Commentary with tags on April 9, 2026 by itnerd

CloudSEK, a cybersecurity intelligence company, today published a threat intelligence report showing how Iranian state-sponsored hacking group APT35 (also known as Charming Kitten) had already broken into the digital infrastructure of every country Iran attacked with ballistic missiles and drones starting February 28, 2026, during Operation Epic Fury.

The report, titled “The Kitten Had the Map All Along,” is based on the KittenBusters intelligence leak and documents a pattern of cyber infiltration that APT35 carried out across Jordan, the UAE, Saudi Arabia, Kuwait, Bahrain, Qatar, and Israel in the years before the strikes began.

According to CloudSEK’s analysis, every Gulf country subsequently struck by Iran had previously appeared in documented APT35 targeting, reconnaissance, or compromise activity.

CloudSEK assesses that the alignment between cyber reconnaissance and later kinetic targeting is too consistent to dismiss as a coincidence. 

While the company stops short of claiming conclusive proof of a formal intelligence-to-strike handoff, the report argues that the most likely explanation is that cyber operations helped prepare the battlefield by mapping targets, collecting internal data, and maintaining pre-positioned access across multiple countries before the conflict escalated.

The report identifies APT35, also known as Charming Kitten, Phosphorus, Magic Hound, and Mint Sandstorm, as the central actor in this activity. CloudSEK links the group to the IRGC Intelligence Organisation, Unit 1500, Department 40, and says newly examined leaked material indicates the group maintained visibility into government, aviation, energy, legal, financial, and civilian infrastructure across the region in the years leading up to the current crisis.

Key Findings from the Report

CloudSEK’s research says that Jordan, the UAE, Saudi Arabia, Kuwait, Bahrain, Qatar, and Israel all appeared in prior APT35 cyber activity before becoming part of the regional strike pattern.

Among the report’s most significant findings:

  • Jordan was one of the most extensively documented targets, with evidence pointing to prior compromise of the Ministry of Justice and targeting of civil aviation-related infrastructure
  • UAE-linked infrastructure, including aviation-related systems and government assets, appears in the leaked data reviewed by CloudSEK
  • Saudi government and energy-related entities were previously profiled, with the report pointing to compromised policy-related documents and access tied to sectors of strategic importance
  • Kuwait, Bahrain, and Qatar were identified as targets of reconnaissance and operational interest before being drawn into the current conflict environment
  • Israel remained a primary focus, with the report citing prior targeting of industrial systems, modems, civilian digital infrastructure, and influence operations.
     

The report also says the leaked material provides unusually rare insight into the malware, infrastructure, financial records, and operating patterns of APT35. According to CloudSEK, that includes exposed source code for malware families such as BellaCiao and Sagheb RAT, as well as blockchain-verifiable payment trails and infrastructure records that help unify multiple previously distinct personas under one broader operational umbrella.

CloudSEK further assesses that personas historically tracked separately, including Moses-Staff and Al-Qassam Cyber Fighters, may in fact be financially and operationally linked to the same broader APT35 ecosystem.

Cyber Operations Running in Parallel

Beyond historic targeting, CloudSEK warns that the cyber dimension of the conflict is already active.

The report highlights ongoing or likely cyber operations by multiple Iran-linked or Iran-aligned actors, including:

  • Handala Hack, linked in the report to attacks and threats involving Israeli and Jordanian targets
  • Cyber Islamic Resistance, associated with destructive and disruptive operations against military and logistics-related entities
  • APT35 / Department 40, which CloudSEK says may already be positioned for follow-on disruptive or destructive activity
  • APT33 / Elfin, historically associated with attacks on the Saudi energy sector
  • CyberAv3ngers, known for prior targeting of internet-exposed industrial control systems
     

CloudSEK says the immediate risk is not limited to military assets. The company warns that aviation systems, airport operations, ports, financial networks, logistics platforms, telecom, government communications, and industrial control environments may all face heightened exposure as the conflict continues.

Why This Matters

CloudSEK’s central warning is that cyber activity in this conflict should not be viewed as reactive noise or opportunistic hacktivism alone. Instead, the report suggests that pre-conflict cyber collection may have played a strategic role in identifying, understanding, and preparing regional targets well before missiles were launched.

That has serious implications for defenders.

If the report’s assessment is correct, organizations across the Gulf and adjacent geographies may be facing adversaries that already understand their networks, their supply chains, their exposed infrastructure, and in some cases their internal communications or operational dependencies.

Immediate Recommendations

CloudSEK is urging organizations, especially those operating in the GCC, Israel, Jordan, and adjacent sectors supporting regional infrastructure, to take immediate defensive steps, including:

  • Patching exposed internet-facing systems linked to known exploited vulnerabilities
  • Auditing Exchange, VPN, and web-facing infrastructure for compromise
  • Hunting for webshells, suspicious tunneling tools, and malware indicators tied to APT35 activity
  • Rotating privileged credentials and auditing administrative access
  • Reviewing aviation, energy, telecom, logistics, and industrial environments for abnormal activity
  • Blocking known indicators of compromise and validating detection coverage against the malware families referenced in the report
     

Caveat and Analytical Position

CloudSEK notes that while several parts of the dataset reviewed in the report are assessed with high confidence, some elements remain only partially independently verified. The company has therefore framed its conclusions carefully: the evidence strongly supports a pattern of pre-positioning and reconnaissance aligned with later regional strikes, but not every operational detail can yet be confirmed with complete certainty.

Even with that caution, CloudSEK says the risk environment is already severe.

The report concludes that the current period should be treated as critical and active, with the likelihood of further Iranian cyber retaliation remaining elevated in the days and weeks ahead.

 For More Details, Read The Full Report Here