June 26, 2026
Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine
36 sources → 355 gathered → 355 triaged → 45 clustered → 45 written
A Rust-based macOS stealer dubbed Gaslight is the first publicly documented sample to embed prompt-injection payloads aimed at derailing AI-assisted malware analysis. On the threat-intel side, ESET published a deep teardown of Gamaredon’s 2025 arsenal, and a batch of fresh PoCs landed for Exchange, FFmpeg, GeoServer, and curl.
AI & Model Security
- Gaslight, a previously undocumented Rust macOS implant and infostealer, hides prompt-injection strings and fake debugging/error data in the binary to trick an analyst’s AI tooling into aborting or refusing analysis — a direct adversarial response to AI-augmented reverse engineering. BleepingComputer, The Hacker News
- Embrace The Red reproduced a TOCTOU race-condition attack against computer-use agents (building on Jun Kokatsu’s ChatGPT Operator finding), showing that “what you click is not what you get” — the agent can be steered to act on swapped content between verification and execution. Embrace The Red
- A new paper argues prompt injection succeeds because LLMs lean on learned role patterns rather than explicit role markers, pointing to genuine “role perception” as a prerequisite for robust defenses. Schneier on Security
New Tools & Releases
- KHAOS — a modern C2 framework that routes agent traffic through cloud services already trusted on enterprise networks, blending C2 into normal egress. GitHub
- Bitwarden C2 — a full command-and-control channel over
icons.bitwarden.net: commands inbound via PNG-metadata polyglots, results exfiltrated via DNS, all to a trusted Azure-hosted domain. thecontractor.io - CrystalSliver — swaps Sliver’s default reflective loader and post-ex execution path for Raphael Mudge’s Crystal Palace evasion kit. GitHub
- SiteManagementAx — a web-delivery extender for AdaptixC2 that hosts payloads over HTTP/HTTPS and generates one-liners across 17 delivery methods. GitHub
- AudioDG.exe DLL hijacking for LPE — executes as LOCAL SERVICE and escalates to SYSTEM via Scheduled Tasks, with a reboot-free restart primitive. GitHub
- exclusion-auditor — read-only NGAV/EDR exclusion risk and hygiene auditor (CrowdStrike-first, vendor-agnostic) for finding dangerous exclusion gaps; useful for purple-team coverage checks. GitHub
- A two-part write-up on Windows Defender evasion via direct syscalls and XOR-encrypted shellcode, with lab setup and working code. Part 1, Part 2
Vulnerabilities & Exploits
- CVE-2026-45504 — a Microsoft Exchange SSRF lets any low-privileged authenticated user read arbitrary files via malicious WOPI URLs; a Python PoC is public. HawkTrace, PoC
- CVE-2025-52465 (“GeoLocate”) in GeoServer is being exploited in the wild — admins can dump plaintext master passwords, enabling JSP webshell injection and (on Windows with UNC paths) NTLM credential leakage. partywave.site
- CVE-2026-8461 (“PixelSmash”) — a heap OOB write in FFmpeg’s MagicYUV decoder yields RCE via a crafted media file; a public exploit dropped. JFrog, PoC
- CVE-2026-38526 (CVSS 9.9) — Krayin CRM RCE via the TinyMCE upload endpoint (
/admin/tinymce/upload) to drop a PHP webshell; PoC published. PoC - curl shipped fixes for a large batch of CVEs including its oldest-ever reported bug (~24–25 years old), with HackerOne reports detailing several credential-leak and connection-reuse flaws — stale proxy passwords (CVE-2026-9079),
.netrcpassword mispairing (CVE-2026-8926), an SSH host-key mismatch silently accepted (CVE-2026-9547), STARTTLS session reuse enabling MITM (CVE-2026-8286), and ASan-validated UAF/Referer leaks (CVE-2026-9546). Aisle, SecurityWeek - CISA warns critical Ubiquiti UniFi OS flaws (CVE-2026-34908/-34909/-34910) are being exploited to create rogue admin accounts; patch unpatched controllers. SecurityWeek
Threat Intelligence
- ESET detailed Gamaredon’s 2025 evolution: six new PowerShell downloaders (PteroDee, PteroDum, PteroPaste, PteroOdd, PteroEffigy, PteroCache) plus the revived PteroSetup weaponizer, 35 spear-phishing campaigns against Ukrainian government/military, and heavy infrastructure laundering via Cloudflare Workers, Microsoft dev tunnels, Loophole, and dead drops on Telegram, Telegraph, Rentry, Dropbox, Supabase and Clever Cloud. WeLiveSecurity, whitepaper + IOCs
- China-aligned TA416 resumed espionage against EU/NATO diplomatic missions from mid-2025, running web-bug and malware-delivery waves and expanding to Middle East government targets after the Iran conflict. Proofpoint
- A new actor tracked as GhostShell has targeted Ukraine’s drone-defense sector since February 2026 with data-stealing, spying malware disguised as legitimate files. Hackread
- Cellebrite’s phone-extraction tooling kept being used by Russian authorities against a dissident after the firm said in 2021 it would stop serving the country, suggesting vendors struggle to claw back deployed gear from authoritarian customers. The Record
- ASIO disclosed that nation-state actors have pre-positioned in Australian critical infrastructure to “cripple it at a time of their choosing,” and is leaning on AI and offensive hacking capabilities in response. The Register
- Japan’s Ground Self-Defense Force unknowingly used counterfeit Chinese-made USB drives carrying malware for nearly a year, compromising 50+ systems before detection. CyberInsider
- A malicious Adblock for YouTube Chrome extension with 10M+ installs and a Featured badge was found capable of arbitrary JS injection, and a malicious Edge extension (Edgecution) abused Native Messaging to escape the browser sandbox and deploy a Python backdoor in a ransomware intrusion. The Hacker News, BleepingComputer
- Nextron began scanning Packagist and flagged a malicious PHP package,
dcat-auth-google-2fa@v1.0.2.0, with obfuscated credential exfiltration tor[.]keepex[.]xyzand a hardcoded 2FA bypass code. Nextron - The Bluekit phishing-as-a-service platform added browser-in-the-middle (BitM) capability and spun up ~70 new hostnames in a week, while Shopify’s Shop order-tracking app is being abused to inject fake receipts that lure victims into callback-phishing support numbers. BleepingComputer (Bluekit), BleepingComputer (Shop)
- Poland’s anti-cybercrime bureau arrested four members of a SIM-swapping crew that breached telecom partners and hijacked email accounts to drain crypto accounts, laundering tens of millions of złoty, with FBI/HSI support. BleepingComputer
Data Breaches
- A threat actor is advertising an alleged Robinhood database of 14.5M records claiming full PII, SSNs, driver’s-license and linked bank-account details, balances, password hashes and 2FA status — unverified, but among the most sensitive financial datasets touted this year. Daily Dark Web
- A separate actor published an alleged Hargreaves Lansdown dataset of 658K UK customer records (names, addresses, DOBs, contact details), claimed to be ~50% of the platform’s users. Daily Dark Web
Around the Region
- Finland’s National Bureau of Investigation warns of fraudsters posing as police on video calls, pressuring victims (especially immigrants) to show payment cards or hand over banking/personal data under threat of account closure or deportation. Yle
Topics
Vendors
Threat actors
CVEs