Breaking
Cyber CrimeDeveloping Story

Ransomware Crews Face Betrayal From Within

A Gentlemen affiliate pocketed extortion profits on a private leak site, as a week of supply chain and phishing threats piled up.

··4 hours ago·8 min read
Vertical columns of glowing green digital code against a dark black background
Photo by Markus Spiske on Unsplash

Trust is proving just as fragile inside ransomware operations as it is on the networks they target. A Russian-speaking affiliate of the Gentlemen ransomware-as-a-service program ran his own extortion business on the side, publishing victim data and keeping the proceeds rather than passing them up the chain. The same week brought compromised developer packages, a WhatsApp-delivered remote access trojan, and a phishing campaign built to fool both people and the AI assistants reading their mail.

An Affiliate Turns On His Own

According to an analysis by CloudSEK, the affiliate — tracked as Azazel — robbed two dozen victims across six countries. He then turned on the gang that supplied his ransomware, publishing the stolen data on a private leak site and pocketing the profits.

CloudSEK described the operation as a betrayal on two fronts. Azazel "built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims," the firm said.

— CloudSEK

The arrangement is unusual because affiliates typically operate under the branding and infrastructure of the program that provides their payload. Running a parallel leak site under a separate brand gave Azazel a way to monetize victims directly, without the operator taking a cut.

WhatsApp Lure Drops a Windows RAT

A financial-document lure named "Statement.exe," reportedly spread through WhatsApp, has been tied to a multi-stage Windows intrusion that ends with a WebSocket remote access trojan tracked as VulcanRAT207, according to Morphisec.

The loader screened the host and attempted to elevate privileges before injecting a downloader into the LocalSystem Task Scheduler process. The chain pulled down a deployment bundle and used a signed driver, GoFly64.sys, to terminate selected Baidu security processes through a bring-your-own-vulnerable-driver technique. It then established a Vulkan DLL side-loading task and launched the RAT, using PoolParty Variant 7 to place the downloader in the Task Scheduler process without relying on CreateRemoteThread.

Once running, the malware can collect system metadata, open an interactive shell, terminate security processes, inject into other processes, replace clipboard text, enumerate local accounts, and terminate itself.

Malicious Code Buried in Developer Tools

Two VS Code themes still listed on the Visual Studio Marketplace — Coca-Cola Christmas and Aurora Borealis Studio Theme — were flagged by Socket as sharing ties to Aurora Nocturne Night Theme, a previously removed malicious extension that hid an obfuscated Windows downloader.

Socket's follow-up analysis uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of the two themes plus Cosmic Nebula Themes. The Visual Studio Marketplace build of Cosmic Nebula Themes contains a loader that decrypts and runs embedded JavaScript, skips systems set to Russian language or timezone, and uses Solana transaction memos as a dead drop resolver to locate follow-on payload infrastructure.

"That build contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity," Socket researcher Kirill Boychenko said.

— Kirill Boychenko, Socket researcher

The npm package @subql/common version 5.8.3 was also compromised, according to StepSecurity, with a hidden payload that collects credentials and supports remote shell access. The code runs during installation and again when the package is imported, targeting developer workstations and CI environments including GitHub Actions runners and accessible cloud services.

A separate RubyGems account named reqthrottle_3474 published 42 malicious gems, most aimed at cryptocurrency developers. SafeDep found the gems stay quiet in CI or a sandbox, then wait 20 to 40 minutes on a developer machine before acting: eleven open a reverse shell to 45.138.12[.]177 on port 8089 or 8090, while thirty-one download wgkit.tar.gz from the same address on port 8092 and run wg_install.sh.

SafeDep also flagged nine npm packages from the account dirtyblanket, all published within 33 minutes on September 29, 2026, that embed a self-spreading Linux worm. The worm installs a backdoor called systemd-fontd disguised as a systemd font service and carries the open-source CHAOS remote access tool. Over Tor it hands the operator a shell, file access, and screenshots. It also uses every SSH private key on the machine to log into hosts listed in known_hosts, runs itself there, and adds itself to the Arch User Repository packages those keys can push to. The same npm tokens let it publish new versions of the developer's own packages to spread further.

Phishing That Targets People and Their AI

Huntress detailed a campaign that abused legitimate Power BI domains to make phishing emails more convincing and slip past security controls. The messages led victims to a fake reference document on the Power BI domains, which prompted them to click "Download Reference." That opened a new tab to an attacker-controlled site, which fingerprinted the victim before triggering a rogue ScreenConnect installer download. The webpages delayed the automatic download, then after a few seconds a script programmatically activated a hidden download link. Huntress said the campaign was first observed on September 10, 2026.

Barracuda analyzed a separate campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection hidden in the very same message. Humans were targeted with the attachments, while AI assistants were targeted with prompt injections meant to influence or override user behavior. The research, Barracuda said, "shows how attackers are combining tactics to manipulate both human users and their email AI assistants in the same phishing email." The company did not disclose the campaign's scale.

A File Upload Flaw Opens the Door

A file upload vulnerability in a web-based recreation management platform used by local municipalities and parks was weaponized to compromise three servers, Huntress reported. The attacker added a new account, used it to upload web shells, and ultimately stole payment data.

User-agent strings pointed to a threat actor based in China, and Huntress suspected AI-generated scripts were used throughout the kill chain — from a high volume of failed initial access probes to PowerShell scripts carrying extensive comments in their embedded instructions. The early attempts were noisy and clumsy, possibly driven by an AI-generated automation script. The attacker finally got in with a more manual approach: creating an account on the platform and finding a flaw in the upload function.

A Suspect Extradited, and an Insider Jailed

An alleged member of the Qilin ransomware group was arrested in Japan and extradited to Germany. The suspect, a 28-year-old Russian national, was detained in Osaka in May and handed to German authorities on October 2, 2026. German investigators believe he is a core member of the gang and want him over a September 2024 hack of a logistics company, where data was encrypted and more than $160,000 in cryptocurrency was extorted.

In a separate case, Daniel Rhyne, 59, a former core infrastructure engineer at an industrial company headquartered in Somerset County, New Jersey, was sentenced to 32 months in prison for locking thousands of systems and servers on his employer's network in a failed data extortion campaign. Rhyne was charged in September 2024 with one count of extortion related to a threat to damage a protected computer, one count of intentional damage to a protected computer, and one count of wire fraud. He pleaded guilty earlier this April.

Healthcare Devices Lag on Quantum Readiness

An analysis from Forescout covering over 2.5 million devices across more than 50 healthcare delivery organizations found that most medical devices cannot be upgraded to post-quantum cryptography, leaving sensitive data exposed to future quantum-enabled attacks.

Only 6% of Internet of Medical Things devices and 16% of medical operational technology devices use SSH implementations capable of supporting a PQC transition, compared with 50% of IT devices. Across exposed healthcare systems, only 31% support TLS 1.3, the only TLS version capable of supporting standardized post-quantum cryptography, Forescout said.

"Healthcare data – including medical histories, diagnostic images, lab results, and prescription records – remains valuable for a lifetime, making the sector especially vulnerable to harvest-now, decrypt-later (HNDL) attacks," the firm said.

— Forescout

  • 2.5 million devices covered in Forescout's healthcare analysis
  • More than 50 healthcare delivery organizations examined
  • 6% of IoMT devices use SSH implementations capable of supporting a PQC transition
  • 16% of medical OT devices meet that bar, versus 50% of IT devices
  • 31% of exposed healthcare systems support TLS 1.3
  • 42 malicious gems published from one RubyGems account
  • 33 minutes was the span in which nine worm-bearing npm packages appeared on September 29, 2026
  • $160,000+ in cryptocurrency extorted in the September 2024 logistics hack tied to the extradited Qilin suspect

A Data Broker in Your Inbox

Meta's personal AI agent, Muse, has been observed building dossiers on its users and the people around them. An analysis of Muse's internal instructions by TIME found it updates those dossiers every hour, covering the user and the people they mention in chats, messages, and emails — including people who don't use Muse at all.

In response, Meta said, "Muse remembers what matters most to you, including information about others that you choose to share, so it can be a helpful personal assistant."

— Meta

Security Failures on Both Sides

An open directory exposed a threat actor's server, complete with tools and traces of an intrusion — a reminder that operational security slips happen on the offensive side too. Combined with the affiliate double-cross, one theme runs through the week: the crooks have trust problems of their own.

What stands out is the gap between effort and results. Some of these attacks involved several stages, careful timing, and plenty of tricks. Others got surprisingly far because of a bad design choice or something nobody bothered to check. Both approaches appear to be working well enough.

What This Means for Defenders

The throughline across these incidents is that the tooling most organizations already trust — marketplace extensions, npm and RubyGems packages, Microsoft Power BI, WhatsApp, even an email AI assistant — is being used as the delivery mechanism. None of these required a novel exploit. They required a developer to install a package, a recipient to click a link, or an assistant to read a message.

That suggests patching and perimeter controls alone won't catch what arrives inside trusted channels. The supply chain cases in particular point to a need for review of what build systems and package managers pull in automatically, since several of the payloads here executed at install time or the moment a package was imported. The healthcare findings add a longer-horizon problem: if the vast majority of medical devices can't move to post-quantum cryptography, data captured now could remain readable later, which is exactly the scenario harvest-now, decrypt-later attacks are built around.

For individual readers, the practical takeaway is narrower. Password-protected attachments and "download reference" prompts that open a second tab deserve more suspicion than they typically get, and the same message that fools a person may now be written to fool the assistant reading alongside them.

#ransomware#supply chain#phishing#malware#post-quantum

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories