Archive for SOCRadar

WP Botnet Master – How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet

Posted in Commentary with tags on July 24, 2026 by itnerd

Today, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.

On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.

The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.

One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.

Key Points:

  • threat actor operating as “KING” (@Real_King_Engine) sells a paid course, the ISAL Framework, that teaches students to stand up attack infrastructure, generate exploits with commercial AI assistants, deploy web shells, and run a credential-harvesting botnet at internet scale.
  • KING is a WPScan-credited vulnerability researcher with three published advisories and a Wordfence Intelligence researcher account carrying an approved bounty payout. These are real, verifiable identities – used as legal cover (“educational and defensive research only”) and as a credibility funnel to convert hobbyists into paying students.
  • The recovered botnet server does not belong to KING. It belongs to one of his students, a self-published developer who identifies publicly as Saeful Rochim (“dalung,” github.com/dalungid), tied to the recovered toolkit by a confirmed code-authorship fingerprint match.
  • The course teaches push-button, AI-assisted exploitation. In a paying student’s own words: “The system did everything automatically – I only drank soda.” Both Anthropic Claude and Google Gemini appear in the toolchain.
  • The output SOCRadar recovered: 272 million sites scanned, 2,118,764 administrator credentials harvested across 606,591 domains in 100 countries, and 137 active web shells across 24 countries.
  • As of the time of writing, the master command-and-control server (217.216.72.31) remained online and continued ingesting fresh target lists.

This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.

To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet 

SOCRadar launches wp2shell exposure checker 

Posted in Commentary with tags on July 22, 2026 by itnerd

SOCRadar has launched a free wp2shell checker to help organizations quickly determine whether their WordPress websites may be exposed to CVE-2026-63030, a critical remote code execution vulnerability affecting recent WordPress versions.

The tool allows users to enter a domain and assess potential exposure without manually reviewing WordPress versions or configurations—particularly useful for organizations managing large numbers of public-facing, subsidiary, staging or forgotten websites.

The checker is designed to help security teams:

  • Quickly identify potentially exposed WordPress assets
  • Verify whether automatic WordPress updates were successfully applied
  • Prioritize vulnerable or overlooked sites for remediation
  • Reduce the risk posed by unknown WordPress installations across the external attack surface

SOCRadar has also published a supporting technical analysis explaining how the wp2shell vulnerability chain can lead to unauthenticated remote code execution, which WordPress versions are affected and what defenders should look for in their logs.

You can access the checker and analysis here:
https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/

DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs

Posted in Commentary with tags on July 20, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) published an in-depth analysis of the latest ClickFake interview campaign, a North Korean social engineering operation targeting cryptocurrency and Web3 professionals with fake job interviews. 

In this campaign, operators pose as recruiters to walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. 

Key points include: 

  • Famous Chollima (aka Wagemole) is a North Korean-aligned threat actor that has been highly active through the Contagious Interview and the latest ClickFake Interview campaigns.
  • For ClickFake Interview the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix empowered fake skill assessments.
  • Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors.
  • The final payloads target both Windows, by deploying PylangGhost RAT, and macOS, by deploying GolangGhost RAT alongside a credential-harvesting SwiftUI application.
  • PylangGhost and GolangGhost consist of six interconnected modules: a main orchestrator, a configuration holder, an archive helper, a command launcher, a C2 component, and a stealer.
  • Both payload chains download the runtimes needed to run in victim environments: Python’s interpreter for PylangGhost and Golang’s compiler for GolangGhost.
  • In the latest variation of PylangGhost, the attackers also compiled their payloads as Python dynamic modules with Nuitka to further complicate detection and analysis.
  • Famous Chollima actors register multiple domains for their fake skill assessments, predominantly on Hostinger and NameCheap registrars, emphasizing speed and scale, rather than operational security and infrastructure resilience.

For full details, this study can be read here: https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/

FIFA World Cup Fraud Campaigns, an Analysis

Posted in Commentary with tags on July 17, 2026 by itnerd

The SOCRadar threat research unit (STRU) has published an in-depth analysis of fraud campaigns associated with the 2026 FIFA World Cup. With the final coming up this Sunday, SOCRadar has tracked the fraud ecosystem between April and July, spanning the counterfeit merchandise stores, FIFA portal impersonation, and ticketing/betting infrastructure. 

Interestingly, rather than peaking during the tournament’s biggest matches such as earlier this week’s semi-finals, fraud activity peaked before kickoff, as operators activated infrastructure that had been prepared weeks in advance. 

Key findings of this research include: 

  • The FIFA portal impersonation cluster, linked to the GHOST STADIUM phishing-kit lineage, now spans 850+ domains – nearly triple the 300+ publicly reported in May. STRU reconstructed the kit’s evolution through the developers’ own Chinese-language code comments, including a documented bug fix and an OPSEC migration between two generations – effectively the threat actor’s own development log.
  • 79% of domains observed at the activity peak were registered within the previous 30 days. Operators quietly bought infrastructure in May and activated it at the tournament’s opening.
  • The betting network hacked nothing. It legally purchased expired domains – a defunct US staffing agency, a French artisan site – for their retained SEO authority, a supply chain that is legal, frictionless, and largely beyond the reach of technical controls.
  • Counterfeit storefronts burned through domains in under five days and used deliberately modest 22-30% discounts, calibrated to look like a plausible promotion rather than a scam.
  • STRU also disproved three of its own most striking leads – a shared Telegram bot token, an identical registrant hash, a common template – all artifacts of shared infrastructure, not shared operators. A transparency point that sets the research apart from typical vendor reporting.
  • Defender takeaway with legs beyond the World Cup: for event-driven fraud, the critical monitoring window is before the event begins – directly applicable to the 2028 Olympics and every future major event.

For full details on SOCRadar’s findings, the research can be read here: https://socradar.io/blog/fifa-world-cup-2026-fraud-campaigns/

FortiBleed Unmasked: A Joint Operation by Lynx and INC Ransomware Groups 

Posted in Commentary with tags on July 6, 2026 by itnerd

After announcing last week that SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations, today the SOCRadar Threat Research Unit (STRU) published its complete report that reveals exactly how INC and Lynx used a measurable, tracked spend on AI credits, an entire swarm of autonomous agents pointed at one target with a deliberate model-selection strategy (cheap model for high-volume scanning, a frontier model reserved for deep code review), and active jailbreak research to defeat model safety controls.

Today’s complete report also puts an identity and a profile behind the coordinating operator and lays out the full internal hierarchy by role.  

Key points:

  • Attribution: STRU assesses with high confidence that FortiBleed is a joint operation run by affiliates of the Lynx and INC ransomware groups.
  • How they know: an OPSEC failure exposed the group’s own artifacts, including a single Windows workstation used to access both ransomware panels and negotiate ransoms. A second exposed INC directory shared victims with FortiBleed target lists, and Lynx is widely believed to be an evolved variant of INC.
  • The operator: an actor we track as TOXMAN (also TOXFOX, and Greenprawn100 on the Exploit[.]in forum), with Russian-language tooling and activity in the UTC +3 time zone.
  • Organized like a business: an internal tracking file mapped 20+ affiliates in defined roles, backed by 450+ operational servers.
  • Scale: roughly 11,250 FortiGate portals scanned across 150+ countries, leading to 409 administrative accesses and 12 organizations encrypted for ransom.
  • Heavy AI investment: about $4,554 spent on AI model credits, including 14 autonomous AI agents pointed at a single target, jailbreak use to bypass model safety controls, and a likely zero-day now in responsible disclosure.
  • Quiet by design: default admin credentials and a VPN-to-management pivot turn one firewall login into full domain compromise, and because the logins are real they rarely trip a perimeter alarm.
  • Who is targeted: opportunistic, small-to-mid-market firms, with managed service providers and manufacturers prized for lateral access into their customers.

For full details, please see the new report: FortiBleed Unmasked: A Joint Operation by Lynx and INC Ransomware Group. A pdf of the report can be found here.  

SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Increasing Exposure

Posted in Commentary with tags on July 1, 2026 by itnerd

SOCRadar’s Threat Research Unit (STRU) has linked the FortiBleed credential-harvesting campaign to two active ransomware-as-a-service operations, INC Ransom and Lynx, making the exposure much more significant (see post SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Increasing Exposure).

An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment for the first time.

Behind the credential leaks lies a coordinated operation run by the Lynx-INC ransomware group, and the actors are exploiting a previously undisclosed Nextcloud zero-day that our team is actively investigating.

The operators were found leveraging a Nextcloud zero-day to expand access. Investigation is ongoing – full technical details, affected versions, and IOCs will follow in our upcoming report.

Key findings:

  • FortiBleed has targeted 430,000+ FortiGate firewalls worldwide via a custom credential-sniffing tool
  • STRU identified 200+ additional operational servers beyond the original campaign
  • An operator with access to FortiBleed infrastructure was found logged into both INC Ransom and Lynx negotiation panels
  • Victim data from FortiBleed overlaps with victims already tracked by INC Ransom
  • An internal tracking document reveals an organized, ~20-person operation with a clear division of labor

What we now know

  • Ransomware operation: STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members.
  • Nextcloud zero-day: The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing.
  • Backdoored accounts: Persistent backdoor accounts were found on compromised devices (username: adminin).
  • Large-scale sniffing: Traffic sniffing was identified on ~19,000 Fortinet devices. Following SOCRadar’s notifications to affected parties, this number has dropped to ~11,000.
  • Infrastructure seizure: 500 servers were seized – including the server Lynx-INC used for ransom negotiations.
  • Decryption: Efforts to recover decryption keys are ongoing.


Recent timeline

  • 29 Jun 2026 – 9,426 newly identified FortiGate devices found in Lynx-INC’s internal tracking documents, with ransomware deployed against several targets.
  • 27 Jun 2026 – FortiBleed formally linked to the Lynx-INC ransomware group.
  • 26 Jun 2026 – IoC update: 42 operation servers and 13 files added.
  • 25 Jun 2026 – Citrix target list discovered: 29,000 IP addresses and 37 domains, indicating targeting is expanding beyond FortiGate.
  • 25 Jun 2026 – IoC update: 19 operation servers and 4 files added.

A detailed report – covering the Lynx-INC operation, the Nextcloud zero-day, and full indicators of compromise will be published later this week or early next week.

SOCRadar Launches Free FortiBleed Exposure Checker & Publishes Most Extensive Dataset on the Fortinet Credential Leak

Posted in Commentary with tags on June 17, 2026 by itnerd

The SOCRadar Threat Research Team, among the first to identify and analyze the FortiBleed leak, has opened its research to the public, having already alerted thousands of customers and national CERTs — and invites every government cybersecurity agency to coordinate on the data.

Over the past 24 hours the company’s Threat Research team has reconstructed the full attack chain behind the campaign, validated the exposed records, and proactively notified thousands of affected customers as well as the local and national CERTs it works with. With those stakeholders already informed, SOCRadar is now making its analysis available to everyone.

SOCRadar also announced the public release of its free FortiBleed Exposure Checker, a tool that lets any organization instantly verify whether its IP Addresses or Domains appear in the FortiBleed dataset — one of the largest known collections of compromised Fortinet credentials.

To view the extended dataset and use the free FortiBleed Exposure Checker, have a look at this link: FortiBleed Exposure Checker 

SOCRadar Discovers Active Fortinet Hacking Campaign – 30,000+ Firewall Credentials Exposed Corporate Networks Across 194 Countries

Posted in Commentary with tags on June 16, 2026 by itnerd

SOCRadar’s researchers have discovered a threat actor systematically compromising Fortinet firewalls and VPN gateways on a massive, global scale, silently building a verified database of working credentials across 194 countries with the US as the #2 target.

The attacker’s database contains login credentials for more than 30,791 devices belonging to companies, banks, telecom operators, hospitals, universities, government agencies, energy companies and multinational corporations with revenues in the tens of billions of dollars. Government entities alone account for 591 entries across 111 domains. Telecoms represent one of the most heavily targeted sectors with 5,616 entries.

The credentials are verified, working usernames and passwords, tested and confirmed by the attackers themselves using automated tools running around the clock. The credentials were leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. The attackers know this, and they are counting on it.

The operation is built around full automation. The attackers scan the internet for Fortinet devices, try a curated list of known passwords against each one, and record every successful login. Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself.

To view the research, please see FortiBleed: How 30,000 Fortinet Firewalls Exposed Corporate Networks Quietly 

SOCRadar Uncovers Large-Scale “RockyBelling” MaaS and PhaaS Operation 

Posted in Commentary with tags on June 15, 2026 by itnerd

The SOCRadar Threat Research team has uncovered an active Malware-as-a-Service (MaaS) and Phishing-as-a-Service (PhaaS) operation active since 2025 by developer “RockyBelling,” who supplies phishing kits, cloaking services, remote management tooling, and supporting infrastructure to nearly 200 operators conducting independent campaigns.

The report The Quarry: Tracing a Cybercriminal Operation analyzes the complete attack chain, including bulk email distribution, tax-themed phishing campaigns impersonating government agencies and major software providers, traffic cloaking through Adspect, deployment of remote monitoring and management (RMM) tools, Telegram-based victim monitoring, and post-compromise activities. It also examines infrastructure patterns, attribution findings, victimology, and operational techniques used to evade detection while scaling attacks across multiple regions and sectors.

Key Highlights:

  • Detailed analysis of a large-scale MaaS and PhaaS ecosystem operating since at least 2025
  • Attribution of the operation’s developer, infrastructure, and affiliate network
  • Breakdown of the complete attack lifecycle from phishing to post-exploitation
  • Examination of cloaking, traffic filtering, and anti-analysis techniques
  • Analysis of phishing lures impersonating government agencies and major brands
  • Insights into Telegram-based operations, infrastructure management, and affiliate activity
  • Victimology, geographic targeting, sector distribution, and observed TTPs
  • Indicators of Compromise (IoCs) and defensive recommendations for security teams

Have a look at the report The Quarry: Tracing a Cybercriminal Operation.

Handala Disrupted Israeli Radar Systems Says New Report

Posted in Commentary with tags on June 8, 2026 by itnerd

On the same day that Iran and Israel traded missile strikes in their most serious exchange since the April ceasefire, Iranian-linked hacker group Handala posted a series of messages on Telegram claiming it had launched crippling cyberattacks against Israeli military and civilian targets. The claims include “widespread and targeted signal disruption” of Israeli radar systems and a “cyber siege” on the Kfar Yona municipality in central Israel.

The messages opened with “In the name of God, the Breaker of Tyrants” in Arabic. Five minutes later came the main statement: “Today marks the beginning of the end. Handala invites you to witness the most devastating cyberattacks targeting the enemy’s military and vital infrastructure, and this is only the first warning.” The message threatened every country that supports Israel, saying “no land is too distant, no server is safe, and no network is out of reach.”

The group claimed that “at this very moment, the radar systems of the Zionist regime are experiencing widespread and targeted signal disruption by Handala’s team.” Handala then shifted to a governmental target, claiming the Kfar Yona Municipality was “under Handala’s cyber siege, drowning in a storm of digital paralysis and information chaos.”

In a new SOCRadar report published today, the company’s security researchers warn that the radar claim should be treated with caution as the evidence shared so far does not support it, including no proper details posted, and many other specifics shared in the SOCRadar report.

The details on the new SOCRadar report is here: Handala Claims It Disrupted Israeli Radar Systems: Here’s What We Actually Know