hackers – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 14 Sep 2025 22:57:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 hackers – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/ https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/#respond Sun, 14 Sep 2025 22:57:24 +0000 https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/

FBI cyber

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” reads the FBI’s FLASH advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”

UNC6040 was first disclosed by Google Threat Intelligence (Mandiant) in June, who warned that since late 2024, threat actors were using social engineering and vishing attacks to trick employees into connecting malicious Salesforce Data Loader OAuth apps to their company’s Salesforce accounts.

In some cases, the threat actors impersonated corporate IT support personnel, who used renamed versions of the application called “My Ticket Portal.”

Once connected, the threat actors used the OAuth application to mass-exfiltrate corporate Salesforce data, which was then used in extortion attempts by the ShinyHunters extortion group.

In these early data theft attacks, ShinyHunters told BleepingComputer that they primarily targeted the “Accounts” and “Contacts” database tables, which are both used to store data about a company’s customers.

These data theft attacks were widespread, impacting large and well-known companies, such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.

Later data theft attacks in August also targeted Salesforce customers, but this time utilized stolen Salesloft Drift OAuth and refresh tokens to breach customers’ Salesforce instances.

This activity is tracked as UNC6395 and is believed to have occurred between August 8th and 18th, with the threat actors using the tokens to target the company’s support case information that was stored in Salesforce.

The exfiltrated data was then analyzed to extract secrets, credentials, and authentication tokens shared in support cases, including AWS keys, passwords, and Snowflake tokens. These credentials could then be used to pivot to other cloud environments for additional data theft.

Salesloft worked with Salesforce to revoke all Drift tokens and required customers to reauthenticate to the platform.

It was later revealed that the threat actors also stole Drift Email tokens, which were used to access emails for a small number of Google Workspace accounts.

An investigation by Mandiant determined the attack originated in March, when Salesloft’s GitHub repositories were compromised, allowing attackers to ultimately steal the Drift OAuth tokens.

Like the previous attacks, these new Salesloft Drift data theft attacks impacted numerous companies,  including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and many more.

While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves “Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to “go dark” and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI’s E-Check background check system and Google’s Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/feed/ 0 58467
Hackers Drain WLFI Tokens Using Ethereum’s EIP-7702 Feature https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/ https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/#respond Mon, 08 Sep 2025 09:38:07 +0000 https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/

A security flaw is being used by attackers to steal WLFI tokens from Ethereum
ETH


$4,269.41

wallets.

According to a September 1 post on X by SlowMist’s Yu Xian, criminals are taking advantage of a new Ethereum feature, EIP-7702, to pull funds from user wallets once they have been compromised.

Ethereum’s May upgrade introduced EIP-7702, which allows regular wallets to behave like smart contract wallets for a short time.

Sidechains in Crypto Explained EASILY (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Xian explained that attackers first gain control of a victim’s private key. After that, they set up a delegate contract on the wallet address. This contract gives the attacker the ability to approve and process transactions.

Once the wallet receives a deposit, such as WLFI tokens, it is only a matter of seconds before the funds are withdrawn to the attacker’s own wallet.

In one example reported on August 31, an X user claimed their friend’s WLFI tokens were stolen after they sent ETH into the wallet. Xian confirmed that this looked like the “Classic EIP-7702 phishing exploit”.

Xian also explained that even when users try to transfer remaining tokens from the compromised wallet, the gas fees can be rerouted to the attacker.

To reduce the damage, Xian recommended canceling or overwriting the delegate contract associated with EIP-7702. He also advised moving any remaining tokens to a secure wallet as soon as possible.

Recently, Anthropic warned that its chatbot, Claude, is being misused by bad actors to support online criminal activity. How? Read the full story.


]]>
https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/feed/ 0 57363
Hackers Use Ethereum Smart Contracts to Mask Malware in NPM Packages https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/ https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/#respond Sat, 06 Sep 2025 22:44:13 +0000 https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/

Hackers have discovered a new method for spreading malicious software by using Ethereum
ETH


$4,272.56

smart contracts to conceal crucial aspects of their attacks.

According to a blog post by Lucija Valentić at ReversingLabs, two suspicious software packages were found on the Node Package Manager (NPM), a platform used to share JavaScript code.

These packages, named “colortoolsv2” and “mimelib2“, were uploaded in July and designed to look like regular tools.

What is a Crypto Mining Pool? Is it Worth it? (Beginner-Friendly)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The packages acted like simple downloaders. When someone installed one, it would reach out to the Ethereum blockchain and fetch data from a smart contract. That data contained the location of a second piece of malware, which would then be downloaded and installed.

This made it hard for security systems to flag the packages as harmful, since they did not include any direct links to malicious websites or files.

Valentić explained that while Ethereum contracts have been misused before, this setup was different. In this case, the smart contract did not hold the malware itself, but held the location where it could be found.

The campaign was not limited to NPM. It also involved a fake open-source project hosted on GitHub. Hackers created a fake cryptocurrency trading bot, complete with fake updates, detailed documentation, and several user accounts to make the project seem active and trustworthy.

On September 1, SlowMist’s Yu Xian reported that attackers stole WLFI tokens from Ethereum wallets. How? Read the full story.


]]>
https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/feed/ 0 57122
Hackers exploited Sitecore zero-day flaw to deploy backdoors https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/ https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/#respond Fri, 05 Sep 2025 13:31:37 +0000 https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/

Hacker

Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance malware.

The flaw, tracked under CVE-2025-53690, is a ViewState deserialization vulnerability caused by the inclusion of a sample ASP.NET machine key in pre-2017 Sitecore guides.

Some customers reused this key in production, allowing attackers with knowledge of the key to craft valid, but malicious ‘_VIEWSTATE’ payloads that tricked the server into deserializing and executing them, leading to remote code execution (RCE).

The flaw isn’t a bug in ASP.NET itself, but a misconfiguration vulnerability created by reusing publicly documented keys that were never meant for production.

Exploitation activity

Mandiant researchers, who discovered the malicious activity in the wild, report that threat actors have been leveraging the flaw in multi-stage attacks.

The attackers target the ‘/sitecore/blocked. aspx’ endpoint, which contains an unauthenticated ViewState field, and achieve RCE under the IIS NETWORK SERVICE account by leveraging CVE-2025-53690.

The malicious payload they drop is WeepSteel, a reconnaissance backdoor that gathers system, process, disk, and network information, disguising its exfiltration as standard ViewState responses.

WeepSteel's information collection
WeepSteel’s information collection
Source: Mandiant

Mandiant observed the execution of reconnaissance commands on compromised environments, including whoami, hostname, tasklist, ipconfig /all, and netstat -ano.

In the next stage of the attack, the hackers deployed Earthworm (a network tunneling and reverse SOCKS proxy), Dwagent (a remote access tool), and 7-Zip, which is used to create archives of the stolen data.

Subsequently, they escalated their privileges by creating local administrator accounts (‘asp$,’ ‘sawadmin’), cached (SAM and SYSTEM hives) credentials dumping, and attempted token impersonating via GoTokenTheft.

Persistence was secured by disabling password expiration for these accounts, giving them RDP access, and registering Dwagent as a SYSTEM service.

The attack lifecycle
The attack lifecycle
Source: Mandiant

Mitigating CVE-2025-53690

CVE-2025-53690 impacts Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud, up to version 9.0, when deployed using the sample ASP.NET machine key included in pre-2017 documentation.

XM Cloud, Content Hub, CDP, Personalize, OrderCloud, Storefront, Send, Discover, Search, and Commerce Server are not impacted.

Sitecore published a security bulletin in coordination with Mandiant’s report, warning that multi-instance deployments with static machine keys are also at risk.

The recommended actions for potentially impacted administrators are to immediately replace all static values in web.config with new, unique keys, and ensure the element inside web.config is encrypted.

In general, it is recommended to adopt regular static machine key rotation as an ongoing security measure.

More information on how to protect ASP.NET machine keys from unauthorized access can be found here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/feed/ 0 56895
WLFI Locks Out Hackers with Blacklist Ahead of Token Launch https://earlybirdsinvest.com/wlfi-locks-out-hackers-with-blacklist-ahead-of-token-launch/ https://earlybirdsinvest.com/wlfi-locks-out-hackers-with-blacklist-ahead-of-token-launch/#respond Thu, 04 Sep 2025 22:45:07 +0000 https://earlybirdsinvest.com/wlfi-locks-out-hackers-with-blacklist-ahead-of-token-launch/

World Liberty Financial (WLFI), a decentralized finance (DeFi) project linked to Donald Trump, has taken action to block suspicious activity before launching its token.

According to a post on X by the WLFI team, compromised wallets were added to an on-chain blacklist just ahead of the release.

This preventive step was handled by a designated wallet, which carried out several blacklist transactions on September 3.

What is a Bitcoin & How Does it work? (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

WLFI explained that the wallets were affected by user-side problems, such as private key leaks, and not due to any vulnerability in the platform itself.

One key focus of the blacklist was WLFI’s “Lockbox”, a vesting tool that holds user token allocations until they are unlocked. The team said the blacklist helped stop attempts to steal these locked tokens, and they shared two transaction links from Etherscan as evidence of the blacklist in use.

The project also stated that it is working with individuals whose accounts were affected to help them restore access.

The WLFI token officially launched on September 1 by unlocking 24.6 billion tokens and opening them up for trading. The high visibility of the event drew attention from scammers.

Fake smart contracts that mimicked the real project were created to mislead users. These clones, called “bundled clones” by analytics firm Bubblemaps, aim to trick people into transferring funds to the wrong addresses.

Additionally, Yu Xian, the founder of the security company SlowMist, reported a phishing scam targeting WLFI holders. What did he say? Read the full story.


]]>
https://earlybirdsinvest.com/wlfi-locks-out-hackers-with-blacklist-ahead-of-token-launch/feed/ 0 56793
Scam Alert: Uniswap V4's Bunni DEX Loses Millions to Hackers https://earlybirdsinvest.com/scam-alert-uniswap-v4s-bunni-dex-loses-millions-to-hackers/ https://earlybirdsinvest.com/scam-alert-uniswap-v4s-bunni-dex-loses-millions-to-hackers/#respond Tue, 02 Sep 2025 09:52:28 +0000 https://earlybirdsinvest.com/scam-alert-uniswap-v4s-bunni-dex-loses-millions-to-hackers/

Malicious actors in the cryptocurrency space remain a constant threat to the sector and are not moved by market conditions as they strike during bull and bearish market conditions. Within the last 24 hours, Uniswap V4’s Bunni decentralized exchange (DEX) has been attacked by hackers.

Hackers exploit Bunni DEX vulnerability

According to an update from PeckShieldAlert, a blockchain security firm that monitors the crypto space, hackers have exploited a vulnerability on Bunni DEX. This has led to the hackers stealing approximately $2.4 million worth of assets.

You Might Also Like

Title news

Critical details of who the attackers could be and the different crypto assets stolen have not been revealed. However, the theft, occurring in the midst of an ongoing bull market, is poised to affect investors who use the exchange.

As of press time, a message from Bunni on their official X handle acknowledged the “security exploit” and precautionary measures taken so far. According to the DEX, their team is currently investigating the incident and will provide details as soon as investigations are concluded.

It has, however, paused all smart contract functions on all networks while this is ongoing. Bunni has called for patience on the part of its users.

Are there security concerns over Uniswap V4 ecosystem?

The compromise on Bunni DEX by these hackers reemphasizes the need for exchanges to pay attention to safeguarding funds on their platform. This suggests that malicious actors are always scanning the crypto space and attempting to steal. Failure to secure protocols could lead to loss of funds.

You Might Also Like

Title news

Interestingly, in February 2025, Uniswap launched a new V4 protocol that included gas efficiency. Some users have wondered if it has also strengthened its security features to protect exchanges in its ecosystem.

U.Today has consistently reported on scam alerts and activities of hackers with emphasis on how to avoid falling victim to their exploits and safeguarding funds.

]]>
https://earlybirdsinvest.com/scam-alert-uniswap-v4s-bunni-dex-loses-millions-to-hackers/feed/ 0 56363
Storm-0501 hackers shift to ransomware attacks in the cloud https://earlybirdsinvest.com/storm-0501-hackers-shift-to-ransomware-attacks-in-the-cloud/ https://earlybirdsinvest.com/storm-0501-hackers-shift-to-ransomware-attacks-in-the-cloud/#respond Thu, 28 Aug 2025 12:15:15 +0000 https://earlybirdsinvest.com/storm-0501-hackers-shift-to-ransomware-attacks-in-the-cloud/

Hand holding key

Microsoft warns that a threat actor tracked as Storm-0501 has evolved its operations, shifting away from encrypting devices with ransomware to focusing on cloud-based encryption, data theft, and extortion.

The hackers now abuse native cloud features to exfiltrate data, wipe backups, and destroy storage accounts, thereby applying pressure and extorting victims without deploying traditional ransomware encryption tools.

Storm-0501 is a threat actor who has been active since at least 2021, deploying the Sabbath ransomware in attacks against organizations worldwide. Over time, the threat actor joined various ransomware-as-a-service (RaaS) platforms, where they used encryptors from Hive, BlackCat (ALPHV), Hunters International, LockBit, and, more recently, Embargo ransomware.

In September 2024, Microsoft detailed how Storm-0501 extended its operations into hybrid cloud environments, pivoting from compromising Active Directory to Entra ID tenants. During these attacks, the threat actors either created persistent backdoors through malicious federated domains or encrypted on-premises devices using ransomware, such as Embargo.

A new report by Microsoft today outlines a shift in tactics, with Storm-0501 no longer relying on on-premises encryption and instead conducting attacks purely in the cloud.

“Unlike traditional on-premises ransomware, where the threat actor typically deploys malware to encrypt critical files across endpoints within the compromised network and then negotiates for a decryption key, cloud-based ransomware introduces a fundamental shift,” reads the report by Microsoft Threat Intelligence.

“Leveraging cloud-native capabilities, Storm-0501 rapidly exfiltrates large volumes of data, destroys data and backups within the victim environment, and demands ransom—all without relying on traditional malware deployment.”

Cloud-based ransomware attacks

In recent attacks observed by Microsoft, the hackers compromised multiple Active Directory domains and Entra tenants by exploiting gaps in Microsoft Defender deployments.

Storm-0501 then used stolen Directory Synchronization Accounts (DSAs) to enumerate users, roles, and Azure resources with tools such as AzureHound. The attackers eventually discovered a Global Administrator account that lacked multifactor authentication, allowing them to reset its password and gain complete administrative control.

With these privileges, they established persistence by adding malicious federated domains under their control, enabling them to impersonate almost any user and bypass MFA protections in the domain.

Microsoft says they escalated their access further into Azure by abusing the Microsoft.Authorization/elevateAccess/action, which allowed them to ultimately assign themselves to Owner roles, effectively taking over the victim’s entire Azure environment.

Overview of Storm-0501 cloud-based ransomware attack chain
Overview of Storm-0501 cloud-based ransomware attack chain
Source: Microsoft

Once in control of the cloud environment, Storm-0501 began disabling defenses and stealing sensitive data from Azure Storage accounts. The threat actors also attempted to destroy storage snapshots, restore points, Recovery Services vaults, and storage accounts to prevent the target from recovering data for free.

When the threat actor couldn’t delete data from recovery services, they utilized cloud-based encryption by creating new Key Vaults and customer-managed keys, effectively encrypting the data with new keys and making it inaccessible to the company unless they pay a ransom.

After stealing data, destroying backups, or encrypting cloud data, Storm-0501 moved to the extortion phase, contacting victims through Microsoft Teams using compromised accounts to deliver ransom demands.

Microsoft’s report shares protection advice, Microsoft Defender XDR detections, and hunting queries that can help find and detect the tactics used by this threat actor.

As ransomware encryptors are increasingly blocked before they can encrypt devices, we may see other threat actors shift away from on-premise encryption to cloud-based data theft and encryption, which may be harder to detect and block.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/storm-0501-hackers-shift-to-ransomware-attacks-in-the-cloud/feed/ 0 55537
APT36 hackers abuse Linux .desktop files to install malware in new attacks https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/ https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/#respond Sun, 24 Aug 2025 11:11:13 +0000 https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/

Linux

The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India.

The activity, documented in reports by CYFIRMA and CloudSEK, aims at data exfiltration and persistent espionage access. APT 36 has previously used .desktop files to load malware in targeted espionage operations in South Asia.

The attacks were first spotted on August 1, 2025, and based on the latest evidence, are still ongoing.

Desktop file abuse

Although the attacks described in the two reports use different infrastructure and samples (based on hashes), the techniques, tactics and procedures (TTPs), attack chains, and apparent goals are the same.

Victims receive ZIP archives through phishing emails containing a malicious .desktop file disguised as a PDF document, and named accordingly.

Linux .desktop files are text-based application launchers that contain configuration options dictating how the desktop environment should display and run an application.

Users open the .desktop file thinking it’s a PDF, which causes a bash command hidden in the ‘Exec=” field to create a temporary filename in “/tmp/’ where it writes a hex-encoded payload fetched from the attacker’s server or Google Drive.

Then, it runs ‘chmod +x’ to make it executable and launches it in the background.

To lower suspicion for the victim, the script also launches Firefox to display a benign decoy PDF file hosted on Google Drive.

Sample of a decoy PDF used in the attacks
Sample of a decoy PDF used in the attacks
Source: CloudSEK

In addition to the manipulation of the ‘Exec=” field to run a sequence of shell commands, the attackers also added fields like “Terminal=false’ to hide the terminal window from the user, and ‘X-GNOME-Autostart-enabled=true’ to run the file at every login.

A malicious desktop file
A malicious desktop file
Source: CloudSEK

Typically, .desktop files on Linux are plain-text shortcut files, defining an icon, name, and command to execute when the user clicks it.

However, in APT36 attacks, the attackers abuse this launcher mechanism to turn it essentially into a malware dropper and persistence establishment system, similarly to how the ‘LNK’ shortcuts are abused on Windows.

Because .desktop files on Linux are typically text, not binaries, and as their abuse isn’t widely documented, security tools on the platform are unlikely to monitor them as potential threats.

The payload dropped by the malformed .desktop file in this case is a Go-based ELF executable that performs espionage functions.

Although packing and obfuscation made analysis challenging, the researchers found that it can be set to stay hidden, or attempt to set up its separate persistence using cron jobs and systemd services.

Communication with the C2 is made through a bi-directional WebSocket channel, allowing data exfiltration and remote command execution.

Overview of the attack
Overview of the attack
Source: CloudSEK

Both cybersecurity firms find this latest campaign to be a sign of the evolution of APT36’s tactics, which are turning more evasive and sophisticated.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/feed/ 0 54866
Murky Panda hackers exploit cloud trust to hack downstream customers https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/ https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/#respond Sat, 23 Aug 2025 03:02:33 +0000 https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/

Chinese hacker

A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers.

Murky Panda, also known as Silk Typhoon (Microsoft) and Hafnium, is known for targeting government, technology, academic, legal, and professional services organizations in North America.

The hacking group, under its numerous names, has been linked to numerous cyberespionage campaigns, including the wave of Microsoft Exchange breaches in 2021 that utilized the ProxyLogon vulnerability. More recent attacks, include those on the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and the Committee on Foreign Investment.

In March, Microsoft reported that Silk Typhoon had begun targeting remote management tools and cloud services in supply chain attacks to gain access to downstream customers’ networks.

Exploiting trusted cloud relationships

Murky Panda commonly gains initial access to corporate networks by exploiting internet-exposed devices and services, such as the CVE-2023-3519 flaw in Citrix NetScaler devices, ProxyLogin in Microsoft Exchange, and CVE-2025-0282 in Ivanti Pulse Connect VPN.

However, a new report by CrowdStrike demonstrates how the threat actors are also known to compromise cloud service providers to abuse the trust these companies have with their customers.

Because cloud providers are sometimes granted built-in administrative access to customer environments, attackers who compromise them can abuse this trust to pivot directly into downstream networks and data.

In one case, the hackers exploited zero-day vulnerabilities to break into a SaaS provider’s cloud environment. They then gained access to the provider’s application registration secret in Entra ID, which allowed them to authenticate as a service and log into downstream customer environments. Using this access, they were able to read customers’ emails and steal sensitive data.

In another attack, Murky Panda compromised a Microsoft cloud solution provider with delegated administrative privileges (DAP). By compromising an account in the Admin Agent group, the attackers gained Global Administrator rights across all downstream tenants. They then created backdoor accounts in customer environments and escalated privileges, enabling persistence and the ability to access email and application data.

CrowdStrike highlights that breaches via trusted-relationships are rare, they are less monitored than more common vectors such as credential theft. By exploiting these trust models, Murky Panda can more easily blend in with legitimate traffic and activity to maintain stealthy access for long periods.

In addition to their cloud-focused intrusions, Murky Panda also uses a variety of tools and custom malware to maintain access and evade detection.

The attackers commonly deploy the Neo-reGeorg open-source web shell and the China Chopper web shells, both widely associated with Chinese espionage actors, to establish persistence on compromised servers.

The group also has access to a custom Linux-based remote access trojan (RAT) called CloudedHope, which allows them to take control of infected devices and spread further in the network. 

Murky Panda also demonstrates strong operational security (OPSEC), including modifying timestamps and deleting logs to hinder forensic analysis.

The group is also known to use compromised small office and home office (SOHO) devices as proxy servers, allowing them to conduct attacks as if they were within a targeted country’s infrastructure. This allows their malicious traffic to blend in with normal traffic and evade detection.

Significant espionage threat

CrowdStrike warns that Murky Panda/Silk Typhoon is a sophisticated adversary with advanced skills and the ability to rapidly weaponize both zero-day and n-day vulnerabilities.

Their abuse of trusted cloud relationships poses a significant risk to organizations that utilize SaaS and cloud providers.

To defend against Murky Panda attacks, CrowdStrike recommends that organizations monitor for unusual Entra ID service principal sign-ins, enforce multi-factor authentication for cloud provider accounts, monitor Entra ID logs, and patch cloud-facing infrastructure promptly.

“MURKY PANDA poses a significant threat to government, technology, legal, and professional services entities in North America and to their suppliers with access to sensitive information,” concludes CrowdStrike.

“Organizations that rely heavily on cloud environments are innately vulnerable to trusted-relationship compromises in the cloud. China-nexus adversaries such as MURKY PANDA continue to leverage sophisticated tradecraft to facilitate their espionage operations, targeting numerous sectors globally.”

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/feed/ 0 54647
Crypto Hackers Capitalize on ETH Surge, Offloading $72M This Week https://earlybirdsinvest.com/crypto-hackers-capitalize-on-eth-surge-offloading-72m-this-week/ https://earlybirdsinvest.com/crypto-hackers-capitalize-on-eth-surge-offloading-72m-this-week/#respond Fri, 15 Aug 2025 14:51:40 +0000 https://earlybirdsinvest.com/crypto-hackers-capitalize-on-eth-surge-offloading-72m-this-week/

Ether’s (ETH) recent rally to $4,780 has delivered a wealth of profits to several high-profile hackers, who have capitalized on the surge by offloading their ill-gotten gains.

In three separate case, on-chain data, revealed by X account EmberCN, shows hackers strategically liquidated their ETH holdings for tens of millions in profit.

The Radiant Capital exploiter, who the protocol alleges is a North Korean entity, drained around $53 million in assets from the DeFi protocol last October. They converted much of their haul into 21,957 ETH at roughly $2,414 per coin, only to sell 9,631 ETH for $44 million worth of stablecoins this week.

They still control 12,326 ETH alongside the stablecoin proceeds, for a combined $101 million, around $48.3 million more than the value of the original stolen assets.

A similar playbook emerged from the Infini exploit in February. That attacker siphoned $49.5 million in USDC and bought 17,696 ETH at $2,798 each.

While laundering 5,000 ETH through Tornado Cash, they also sold 3,540 ETH for $13 million worth of stablecoins at an average $3,762. The ETH rally has swelled the value of their remaining stash, netting an extra $25.15 million on top of the initial theft.

The third case was an unidentified exploiter who stole 17,412 ETH from THORChain and Chainflip in March sold those holdings for $33.9 million DAI at $1,947.

In June, they re-entered the market, buying 4,957 ETH at $2,495 before selling them early Friday for $22.13 million worth of stablecoins at $4,464, profiting $9.76 million in the process.

The three hacks all played part in a rampant 18 months for hackers, with investors losing $3.1 billion in in the first half of 2025 and $1.49 billion in 2024.

]]>
https://earlybirdsinvest.com/crypto-hackers-capitalize-on-eth-surge-offloading-72m-this-week/feed/ 0 53341