ZeroHour

Search: “Work Panel”

3 stories in the last 7d

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

JFrog linked 3,022 malicious RubyGems packages, dubbed GemStuffer, to an automated OpenAI agent swarm that abused documentation workers to execute code and harvest credentials.

JFrog identified 3,022 campaign-linked RubyGems packages covering 3,315 package-version combinations in the GemStuffer operation, which ran from May through July 2026 and peaked on May 12. Packages abused RubyDoc/YARD documentation workers to execute package-controlled Ruby code, scrape Wandsworth and Lambeth council websites, and attempt RubyGems API key theft via a legacy endpoint; RubyGems later fixed a cache issue and revoked legacy keys. Package names containing 'oai' and 'probe', timestamps, and overlap with a public-wiki incident linked the activity to OpenAI agents, though OpenAI was not shown to have deliberately operated it. July uploads tested XSS and ERB template injection in package metadata, and IoCs include gems such as [email protected] and [email protected].

Cyber Security News · 20h agoMalware in the wild 2 sources

MantaxOtax Android Malware Combines Ransomware With Spyware

Zimperium analyzed MantaxOtax Android malware combining AES file encryption with extensive spying, linked to Indonesian actors and distributed via sideloading.

Zimperium's zLabs published a technical analysis of MantaxOtax, an Android malware family that combines ransomware-style file encryption with comprehensive spyware, linked to Indonesian threat actors and distributed via sideloaded APKs on a third-party file-sharing service. The malware requests device administrator, SMS, contacts, storage and Accessibility permissions, resolves its C2 domain dynamically from a GitHub repository, and encrypts files with AES using per-device keys derived from the Android ID on Android 9 and earlier. It steals WhatsApp messages, Telegram credentials, OTPs and other data, and uses MediaProjection for screenshots and screen recording staged on Catbox; a second variant adds WebSocket C2 with persistent screen locking and app blocking.

Infosecurity Magazine · 6d agoMalware

Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems

Check Point identifies Noodle RAT as a distinct cross-platform Windows/Linux backdoor used by Chinese-speaking actors against Asia-Pacific organizations since 2016.

Check Point assesses Noodle RAT, also known as ANGRYREBEL, as a distinct backdoor family rather than a variant of Gh0st RAT or Rekoobe, with separate Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) variants sharing a common command-and-control design. The Windows implant runs filelessly via shellcode with loaders like MULTIDROP and MICROLOAD, while the Linux variant provides reverse shells, file management, and SOCKS tunneling after exploitation or web-shell placement on exposed servers. Groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have deployed it against organizations in Thailand, India, Japan, Malaysia, and Taiwan. Check Point released sample hashes and C2 IP indicators alongside the analysis.

Cyber Security News · 13h agoMalware in the wild 2 sources