CTO at NCSC Summary: week ending December 14th
“One of the most promising aspects of cyber deception is its potential to impose cost on adversaries." - NCSC
Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do.
Operationally this week the reports that a Small numbers of Notepad++ users reporting security woes which led to a vulnerability fix. Along with the continued cleanup globally post React etc..
In the high-level this week:
Cyber deception trials: what we’ve learned so far - NCSC UK publishes - “One of the most promising aspects of cyber deception is its potential to impose cost on adversaries. By forcing attackers to spend time and resources navigating false environments, chasing fake credentials, or second-guessing their access, cyber deception can slow down attacks and increase the likelihood of detection.”
Cyber Essentials Supply Chain Playbook - NCSC UK publishes - “The Cyber Essentials Supply Chain Playbook we have developed with the NCSC is designed to help organisations manage their supply chains more effectively, ensuring their operations are protected every step of the way.”
Updating our guidance on security certificates, TLS and IPsec - NCSC UK announces - “Today, the NCSC has published updated guidance on deploying and managing security certificates, taking into account trends and practice in the international certificates ecosystem.”
Provisioning and managing certificates in the Web PKI - NCSC UK publishes - “This guidance helps architects, designers and engineers to make appropriate choices when obtaining and managing certificates to authenticate their online services to users.”
Prompt injection is not SQL injection (it may be worse) - NCSC UK publishes - “This blog argues that comparing SQL injection with prompt injection is dangerous, and that the latter needs to be approached differently to mitigate the risks associated with it.”
UK clamps down on China-based companies for reckless and irresponsible activity in cyberspace - Foreign, Commonwealth & Development Office announce - “Two tech companies based in China have been sanctioned for reckless and indiscriminate cyberattacks”
New UK action against foreign information warfare - Foreign, Commonwealth & Development Office policy - “We are stepping up cooperation with European partners on hybrid and information threats, including through the UK-EU Security and Defence Partnership, and through deep cooperation between teams in the UK, in France, Germany, Poland and Brussels, to deliver a pan-European response to a pan-European threat.”
Research on mapping the AI and software cyber security services market - Department for Science, Innovation and Technology - “The Department for Science, Innovation and Technology (DSIT) has commissioned research to map the landscape of AI and software cyber security services in the UK. This project aims to better understand the skills, services, and tools available to support organisations in the UK in meeting the requirements of the Global Standard for AI Cyber Security and the Software Security Code of Practice.”
UK MPs face rise in phishing attacks on messaging apps - The Guardian reports - “MPs, peers and officials are being asked to step up their cybersecurity after a continued rise in attacks that have involved messages pretending to be from the app’s support team, asking a user to enter an access code, click a link or scan a QR code.”
FS-ISAC UK Becomes Steward of the UK’s Financial Sector Cyber Collaboration Centre (FSCCC) - FS-ISAC announces - “This collaborative effort is the result of a shared commitment and dedication among all partners to strengthen cybersecurity and safeguard the overall integrity of the UK’s financial system, including the Authorities, the National Cyber Security Centre (NCSC), the National Crime Agency (NCA), the Bank of England and the UK Finance Sector’s Cross Market Operational Resilience Group (CMORG),”
ICC Office of the Prosecutor launches Policy on Cyber-Enabled Crimes under the Rome Statute to address international crimes in the digital era - International Criminal Court positions - “The Policy is significant for setting out the OTP’s understanding of how the existing ICC legal framework applies to conduct in cyberspace which may constitute crimes within the ICC’s jurisdiction.”
Rep. Pfluger Introduces Bill to Protect America’s Critical Infrastructure - Congressman August Pfluger introduces - “As cyberattacks in the United States grow more sophisticated and widespread, we must ensure the Trump administration and all future administrations have a strong framework to hold bad actors accountable and safeguard our national security. Protecting America’s critical infrastructure from malicious cyberattacks is essential, and this bill does exactly that,”
Trump Administration Turning to Private Firms in Cyber Offensive - Bloomberg reports - “The draft, described to Bloomberg News by multiple people, says the federal government should unleash private businesses as it moves to impose consequences on foreign adversaries who breach critical infrastructure and telecommunications networks, or who cripple businesses with ransomware attacks. The draft didn’t provide many details on how the administration would use the companies.”
Defense bill addresses secure phones, AI training, cyber troop mental health - Cyber Scoop reports - “The legislation states that the secretary of defense “shall ensure” that wireless mobile phones the department provides to its senior leaders and others working on sensitive national security missions meets a list of cybersecurity requirements, such as data encryption”
Germany accuses Russia of 2024 cyber attack and election disinformation campaign - BBC reports - “A foreign ministry spokesman said Russian military intelligence was behind a “cyber-attack against German air traffic control in August 2024”.
68% Of Phishing Websites Are Protected by CloudFlare - Sicuranext quantify - “When we looked at the 12,635 unique IPs hosting these IOCs, a clear pattern emerged. The threat landscape has forked:
51.54% direct hosting – Think disposable infrastructure. Spin it up fast, burn it down faster. Perfect for smishing blasts and hit-and-run campaigns.
48.46% CDN/proxy-protected: The long game. These setups are built to survive, leveraging CDNs (92% Cloudflare, naturally) for origin obfuscation and anti-takedown resilience.” - but it doesn’t quantify the speed of takedowns when reported so isn’t the complete picture..
Ukraine and The Netherlands Launch Inaugural Cyber Dialogue to Bolster Joint Defence - State Service for Special Communications and Information Protection for Ukraine reports - “The Dutch side expressed significant interest in the SSSCIP’s project to establish a network of Regional Cyber Defense Centers. The possibility of consultations on the technical aspects of their operation and coordination with the national CERT-UA was also discussed.”
Why Singapore remains cautious over naming state actors in cyber-attacks - Yahoo! news interviews - “Countries that consider themselves neutral or non-aligned may prefer technical attribution over political attribution of malicious cyber activities. Technical attribution is based on factual data gathered during investigations and point to the perpetrator operating these activities. Political attribution may not always use factual data and usually pins the blame on a nation-state believed to be behind the perpetrator. While technical attribution demonstrates an act of defence, political attribution could be perceived as escalatory.”
Military Objective or Civilian Object? The Italian National Cybersecurity Agency’s Status in Case of Armed Conflict - Lieber Institute considers - “From an IHL perspective, the ACN occupies a nuanced position within Italy’s national cybersecurity architecture. Its civilian mandate in resilience and infrastructure protection generally places it outside the scope of lawful military targeting. However, if the Agency’s structures or systems were to effectively contribute to military operations, they could be considered legitimate military objectives. Any attacks, whether cyber or kinetic, must comply with the IHL principles of distinction, proportionality, and precautions in attack, and must focus strictly on functions directly supporting military action”
Reporting on/from China
China ‘systematically’ using UK research to gain a military edge - The Times reports - “It reveals that more than 5,000 researchers affiliated with UK organisations, including laboratories and institutes, have been involved in scientific papers alongside individuals from dozens of research organisations connected to the PLA since 2020.”
From Innovation to Weaponisation: How China Exploits the UK Open Scientific System - Strider Intel publishes
Chinese-linked hackers use back door for potential ‘sabotage,’ US and Canada say - Reuters reports - “The Chinese-linked hacking operations are the latest example of Chinese hackers targeting critical infrastructure, infiltrating sensitive networks and “embedding themselves to enable long-term access, disruption, and potential sabotage,” Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency, said”
Creative digital resistance on China’s Virtual Wailing Wall - University of Hong Kong and University of Copenhagen publish - “Findings suggest that the Wailing Wall has been redefined as a space for creative resistance, where users at the grassroots level continue to engage in implicit yet persistent opposition despite strict online censorship. More importantly, individuals have developed a subtle yet politicized form of everyday resistance as alternative participation, embedding their dissent within personal narratives to navigate digital restrictions in China’s online space.”
AI
ETSI EN 303 223 – Baseline Cyber Security Requirements for AI Models and Systems - National Standards Bodies from across Europe comprising of European governments, industry and academia voted in favour of approving the publication of the ETSI Technical Standard for Baseline Cyber Security Requirements for AI Systems and Models, upgrading it from a Technical Specification (TS) to a European Standard (EN) - this is based on NCSC UK’s guidance..
Governor Ron DeSantis Announces Proposal for Citizen Bill of Rights for Artificial Intelligence - Governor Ron DeSantis announces - “The Artificial Intelligence proposal will establish an AI Bill of Rights to provide consumers with protections.”
Countering China’s Challenge To American AI Leadership - Subcommittee on East Asia, The Pacific, and International Cybersecurity Policy publish
Prompt injection is not SQL injection (it may be worse) - NCSC UK publishes - “This blog argues that comparing SQL injection with prompt injection is dangerous, and that the latter needs to be approached differently to mitigate the risks associated with it.”
AI Malware: Hype vs. Reality - TJ Nelson underlines with a reality stick - “Most “AI malware” observed so far falls into the AI malware Maturity Model (AIM3) Levels 1-3 (Experimenting through Optimizing), rather than fully automated campaigns.” … “Public reporting shows no confirmed examples of truly embedded, Bring-Your-Own-AI (BYOAI) malware running its own local model on victim hosts.”
Frontier Model Performance on Offensive-Security Tasks: Emerging Evidence of a Capability Shift - Irregular asserts - “If models can achieve high performance on narrowly scoped offensive-security tasks, why have we not seen a plethora of large-scale, fully automated compromises of real-world systems? A central distinction lies between solving a well-bounded puzzle and operating effectively within an open-ended, uncertain environment.” - the well grizzled of you will likely agree..
Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing - Stanford University and Carnegie Mellon University research - “Despite these differences, all participants shared a common pattern: automated tool output analysis followed by manual validation. Top performers (P1, P2) balanced automated scanning with thorough manual analysis. Weaker performers relied too heavily on automated tools without validating their results, leading to missed opportunities. Overall, ARTEMIS configurations behave similarly to human penetration testers” - we can take from this that existing kill chain disruption approaches will continue to be effective in the AI enabled world
AI Hackers Are Coming Dangerously Close to Beating Humans - The Wall Street Journal reports - “The AI bot trounced all except one of the 10 professional network penetration testers the Stanford researchers had hired to poke and prod, but not actually break into, their engineering network.”
Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks - Carnegie Mellon University, Columbia University and Johns Hopkins University research and warns - “All frontier agent systems perform terribly in terms of security. Compared with the FUNCPASS, the average SECPAS S only around 10%. The best functionally performing approach, SWEAG ENT integrated with Claude 4 Sonnet resolved 61% of the tasks, yet 82.8% of these functionally correct solutions are insecure. OP ENHA ND S with Claude shows the highest SECPA S S score of 12.5%. Considering its FU NCPAS S score, this still means that 74.7% of the correct solutions are insecure. This indicates that, if the vibe coding users accept the solution after it passes the functionality test cases, around 80% of the time, the solution will leave secure vulnerabilities in the repositories.”
WildCode: An Empirical Analysis of Code Generated by ChatGPT - Sheridan College, Queen’s University, Université du Québec en Outaouais and Concordia University research - “Our findings highlight several concerning trends. First, code quality, particularly in terms of security, remains a significant issue. Second, our analysis of user intent shows that security is rarely prioritized in user queries. Even when users encounter buggy or vulnerable code, they seldom raise security concerns or request secure alternatives.Together, these contributions underscore the urgent need for security-aware LLMs, better user prompting strategies, and proactive safeguards within generative coding tools.”
Cybersecurity AI: The World’s Top AI Agent for Security Capture-the-Flag (CTF) - Alias Robotics asserts - “This paper presents comprehensive evidence of AI capability across the 2025 CTF circuit and argues that the security community must urgently transition from Jeopardy-style contests to Attack & Defense formats that genuinely test adaptive reasoning and resilience—capabilities that remain uniquely human, for now.”
Cyber proliferation
FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order - Federal Trade Commission announces - “The order, finalized in late 2021, settling the FTC’s allegations bans Support King and Zuckerman from offering, promoting, selling, or advertising any surveillance app, service, or business.”
Bounty Hunting
Justice Department Announces Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups - US Department of Justice announce - “The Justice Department announced two indictments in the Central District of California charging Ukrainian national Victoria Eduardovna Dubranova, 33, also known as Vika, Tory, and SovaSonya, for her role in conducting cyberattacks and computer intrusions against critical infrastructure and other victims around the world, in support of Russia’s geopolitical interests.”
Police Find SMS Blaster Hoard in Cambodia - CommsRisk reports - “The Malaysian had stored telecoms scam equipment in a lock-up property in the Khan Chamkar Mon district of Phnom Penh. Numerous photographs taken within this lock-up suggest around 15 separate SMS blasters were stored there, awaiting delivery to drivers.”
The Rabbit Hole: FBI’s Most Wanted Faces Charges in Virginia - Court Watch reports - “Ahmad Al Agha, one of the purported leaders of the hacker group, Syrian Electronic Army, appeared in federal court last month after being pursued by the law enforcement for eleven years.”
Maryland man sentenced for N. Korea IT worker scheme involving US government contracts - The Record reports - “A 40-year-old Maryland man has been sentenced to 15 months in prison for his role in a scheme where he allowed North Korean nationals to use his identity to work in software development roles at several U.S. government agencies, including the Federal Aviation Administration (FAA).”
Three Ukrainians detained in Warsaw with arsenal of suspicious hacking devices in car - TVP reports - “Three Ukrainian men found with an arsenal of hacking equipment were arrested in Poland, amid concerns they could be plotting to orchestrate cyberattacks on the country’s IT infrastructure.”
Summary of domestic securities account takeover cases arrested on suspicion of market manipulation - Hatena reports - “The men began illegally accessing securities accounts around March 6th, and began selling stocks in the victim accounts from the 12th onwards. They then deposited 30 million yen into a bank account linked to the same accounts, preparing approximately 100 million yen as purchasing funds. Then, on the afternoon of the 17th, they simultaneously placed buy orders from accounts in the company’s name, purchasing approximately 700,000 shares.”
The National Police arrest a cybercriminal for stealing and selling some 64,000,000 private personal data. - Spanish National Police announce - “National Police officers have arrested a 19-year-old man in Igualada (Barcelona) for his alleged involvement in computer crimes, unauthorized access and disclosure of secrets, and violations of privacy.”
Market Incentives
Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK - Information Commissioner’s Office announces - “We have fined password manager provider LastPass UK Ltd £1.2 million following a 2022 data breach that compromised the personal information of up to 1.6 million of its UK users.”
Senior Manager for Government Contractor Charged in Cybersecurity Fraud Scheme - US Department of Justice announces - “A federal grand jury in the District of Columbia returned an indictment yesterday charging a former senior manager at a Virginia-based government contractor with major government fraud, wire fraud, and obstructing federal audits for allegedly carrying out a multi-year scheme to mislead federal agencies about the security of a cloud-based platform used by the U.S. Army and other government customers.”
Why bug bounty schemes have not led to secure software - Computer Weekly interviews Katie Moussouris - “All governments have pretty much held off on holding software companies responsible and legally liable, because they wanted to encourage the growth of their industry,” she says. “But that has to change at a certain point, like automobiles were not highly regulated, and then seatbelts were required by law.”
2025 Cyber Claims Reports - Coalition Inc releases - “Claims severity in the US was lower ($108,000) than the global average in 2024. Severity in Canada was nearly double the global average ($226,000), while the UK was significantly lower ($35,000).”
Reflections this week are twofold…
The first is that cognitive effects on AI systems are underexplored in the context of cyber defence. As we are learning in the context of human operators there is on the face of it opportunity to distract, degrade and dissuade autonomous/agentic AI systems also.
The second is today’s AI systems appear to be following similar kill chains to humans. There is no magic here which is a cause of optimism…
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA) and an Avengers assemble ensemble including the UK’s National Cyber Security Centre issue this alert. Nothing alleged about this one..
This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet Primary Mitigations to Reduce Cyber Threats to Operational Technology and European Cybercrime Centre’s (EC3) Operation Eastwood, in which CISA, Federal Bureau of Investigation (FBI), Department of Energy (DOE), Environmental Protection Agency (EPA), and EC3 shared information about cyber incidents affecting the operational technology (OT) and industrial control systems (ICS) of critical infrastructure entities in the United States and globally.
..
Over the past several years, the authoring organizations have observed pro-Russia hacktivist groups conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. The escalation of the Russia-Ukraine conflict in 2022 significantly increased the number of these proRussia groups. Consisting of individuals who support Russia’s agenda but lack direct governmental ties, most of these groups target Ukrainian and allied infrastructure. However, among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support.
https://www.ic3.gov/CSA/2025/251209.pdf
APT-C-53 (Gamaredon) uses CVE-2025-8088 to conduct phishing attacks
360 Threat Intelligence Center in China reports on an alleged Russian campaign which has echoes of other reporting. Nothing overly novel other than the weaponization of the vulnerability.
APT-C-53 (Gamaredon), also known as Primitive Bear, Winterflounder, and BlueAlpha, is a Russian government-backed Advanced Persistent Threat (APT) group active since 2013. This group has long targeted key Ukrainian government and military entities, with its earliest attacks dating back to 2013. Its primary objectives are intelligence gathering and espionage. The group remains highly active, and despite repeated disclosures of its attacks by security vendors in recent years, APT-C-53 has not ceased its operations; in fact, its activities seem to be escalating
..
The initial access vector was a specially crafted RAR archive delivered via spear-phishing emails. This attack exploited a directory traversal vulnerability, CVE-2025-8088.
The vulnerability’s technical principle lies in the fact that archivers allow files to contain Alternate Data Streams (ADS), which can be used to carry arbitrary malicious payloads.
https://mp.weixin.qq.com/s/zerWPti8aO8ymhOT1Ij-ig
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics
Daniel Lunghi, Ian Kenefick and Feike Hacquebord detail an interesting campaign for several reasons. The first is the alleged Russian links, the second is the mixed-motivation and third is the use of a western cyber security brand to target potential supply chains.
In November 2025, spear-phishing emails featuring a Trend Micro-themed social engineering lure were sent to various industry verticals – including defense, energy, chemical, cybersecurity (including Trend and a subsidiary), and ICT companies – where a decoy website mimicked Trend’s corporate style.
The campaign utilized a multi-stage approach, tailoring every stage to the specific target machine and delivering intermediate payloads to a select number of targets.
We can relate the November 2025 campaign with high confidence to another campaign in October 2025, which used HR complaints and research participation as a social engineering lure.
Several elements of the campaign align with the intrusion set known as Void Rabisu, associated with a hybrid-motivation actor group aligned with Russian interests. However, until a more definitive link to Void Rabisu is established, the two campaigns will be tracked separately under the temporary intrusion set SHADOW-VOID-042.
https://www.trendmicro.com/en_us/research/25/l/SHADOW-VOID-042.html
Russian Cyber Army. Who is it?
Molfar Intelligence Institute details who they alleged are involved in this ‘hacktivist’ endeavour..
Russian Cyber Army / Noname057(16) are two groups that have operated in parallel since late 2022. Noname057(16) developed a project—malicious software called Ddosia
[We] identified several Russian hackers allegedly connected to Russian state structures and received funding from them. Some of these individuals are Ukrainian.
Reporting on China
Silver Fox’s Russian Ruse: ValleyRAT Hits China via Fake Microsoft Teams Attack
Realia Quest highlight why attribution can be challenged. Especially if you are an alleged Chinese operation employing false flags.
The Chinese advanced persistent threat (APT) group “Silver Fox” has used false flags, such as Cyrillic characters, to impersonate a Russian threat group while launching a Microsoft Teams search engine optimization (SEO) poisoning campaign targeting organizations in China.
Silver Fox is deploying “ValleyRAT” malware to achieve two objectives: conducting state-sponsored espionage for sensitive intelligence and engaging in financial fraud and theft to fund its operations.
https://reliaquest.com/blog/threat-spotlight-silver-foxs-russian-ruse-fake-microsoft-teams-attack/
Malicious Apprentice | How Two Hackers Went From Cisco Academy to Cisco CVEs
Dakota Cary alleges links between Salt Typhoon and two individuals who went on vendor training. Not really a surprise, if true, that individuals familiar with a platform may have an edge in analyzing and attacking.
Salt Typhoon, first reported in September 2024, compromised over 80 telecommunications companies globally, facilitating an expansive intelligence collection effort that included intercepting unencrypted calls and texts, and breaching lawful intercept (CALEA) systems.
The operation is tied to Yuyang (余洋) and Qiu Daibing (邱代兵), co-owners of companies named in the cybersecurity advisory and who worked closely to file patents and orchestrate the attacks.
The hackers’ history traces back to the 2012 Cisco Network Academy Cup, where they excelled as students from a poorly-regarded university.
The episode suggests that offensive capabilities against foreign IT products likely emerge when companies begin supplying local training and that there is a potential risk of such education initiatives inadvertently boosting foreign offensive research.
In markets where foreign firms are given a fair shake at competition these initiatives still make sense. As China seeks to delete American-made IT from its tech stacks, these initiatives may present more risk than reward.
Reporting on North Korea
North Korean hackers are pushing fake “Microsoft Teams Update” to macOS
Moonlock Lab flag this alleged North Korean operation which is targeting macOS with a social engineering campaign.
We detected an ongoing campaign, which is consistent with DPTK recruitment/crypto-targeting ops, today in France.
..
The loader is written in AppleScript and branded as a “Microsoft Teams Live SDK update”. To look trustworthy, it first opens a legitimate Microsoft Teams page in the background (the “What’s new” or documentation page) so a user sees something normal in their browser
https://twitter-thread.com/t/1996304740410347890
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks
Sysdig Threat Research Team detail an alleged North Korean campaign which is interesting for two reasons. The first is they quickly moved to exploit the React vulnerability and secondly the use of EtherRAT for command & control..
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application. Unlike the cryptocurrency miners and credential stealers documented in early React2Shell exploitation, this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and downloads its own Node.js runtime from nodejs.org.
https://www.sysdig.com/blog/etherrat-dprk-uses-novel-ethereum-implant-in-react2shell-attacks
Look Inside a Compromised North Korean APT Machine Linked to The Biggest Heist in History
Hudson Rock is obtaining stealer logs from attacker infrastructure and allegedly found a North Korean actor has been compromised.
[We] analyzed a unique infection from a LummaC2 infostealer log. The victim wasn’t a corporate employee or an unsuspecting consumer. The victim was a high-level North Korean threat actor operating a sophisticated malware development rig.
While our analysis suggests the operator of this machine is likely part of a separate subgroup within the DPRK cyber-offensive apparatus, the use of identical credentials connects this developer rig directly to the infrastructure used in one of the largest financial cyber-attacks in history.
https://www.hudsonrock.com/blog/5692
https://www.hudsonrock.com/northkorean
Reporting on Iran
Charming Kitten Leak Continues: Payroll Data and a Stolen IAEA Document
Nariman Gharib continues to analyze and document the alleged Iranian data dump associated apparently with Charming Kitten.
Now, additional materials from the same network access reveal three significant findings: complete salary records for both male and female operative teams, expanded footage of the Kashef surveillance platform, and a classified 2004 document showing Iran obtained confidential IAEA inspection materials, with a direct connection to an individual previously identified as a Department 40 assassination target.
…
The leaked materials include payslips and financial records documenting compensation for operatives in both the Sisters Team (Aqiq) and Brothers Team (Pelak1). These documents provide unprecedented visibility into how Iran compensates its state-sponsored hacking personnel.
https://blog.narimangharib.com/posts/2025%2F12%2F1765296445744?lang=en
Reporting on Other Actors
Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
Unit 42 show that even marginal groups are maturing with their operational security sophistication in this alleged Hamas-affiliated operation.
We share details of a long-running, elusive espionage campaign targeting governmental and diplomatic entities throughout the Middle East. We discovered that the group has created new versions of their previously documented custom loader, delivering a new malware suite that we have named AshTag. The group has also updated their command and control (C2) architecture to evade analysis and blend in with legitimate internet traffic.
Ashen Lepus remained persistently active throughout the Israel-Hamas conflict, distinguishing it from other affiliated groups whose activities decreased over the same period. Ashen Lepus continued with its campaign even after the October 2025 Gaza ceasefire, deploying newly developed malware variants and engaging in hands-on activity within victim environments.
https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
Insikt Group detail the operations of this criminal actor who employs various social engineering techniques in order to gain initial access. It is interesting that the recommendation is to block the least painful bit of the pyramid of pain..
Insikt Group uncovered four distinct activity clusters leveraging GrayBravo’s CastleLoader, each exhibiting unique tactics, techniques, and procedures (TTPs) and victim profiles, reinforcing the assessment that GrayBravo operates a malware-as-a-service (MaaS) ecosystem, as previously hypothesized.
One cluster, tracked as TAG-160, impersonates logistics firms and deploys phishing lures combined with the ClickFix technique to distribute CastleLoader, while spoofing legitimate emails and abusing freight-matching platforms to engage targets.
Cluster 2, tracked as TAG-161, impersonates Booking.com and uses ClickFix techniques to deliver CastleLoader and Matanbuchus, relying on threat actor-controlled infrastructure and employing previously unseen phishing email management tooling.
For example, one cluster, tracked as TAG-160, impersonates global logistics firms, using phishing lures and the ClickFix technique to distribute CastleLoader while spoofing legitimate emails and exploiting freight-matching platforms to target victims. Another cluster, tracked as TAG-161, impersonates Booking.com, also employing ClickFix to deliver CastleLoader and Matanbuchus and novel phishing email management tools. Further investigation through historical panel analysis linked the online persona “Sparja”, a user active on Exploit Forums, to potential GrayBravo-associated activities, based on the alias’s distinctiveness and related discussion topics.
ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants
Luke Jennings details a new social engineering technique in order to obtain access tokens..
ConsentFix. This attack shares a lot of similarities with ClickFix/FileFix, AiTM phishing, and OAuth Consent Phishing. You can think of this as a browser-native ClickFix attack that phishes an OAuth token on a target app by getting the victim to copy and paste a URL containing OAuth key material into a phishing page.
The campaign we detected looks to be specifically targeting Microsoft accounts by abusing the Azure CLI OAuth app. Essentially, the attacker tricks the victim into logging into Azure CLI, by generating an OAuth authorization code — visible in a localhost URL — and then pasting that URL (including the code) into an attacker-controlled page.
https://pushsecurity.com/blog/consentfix
The Webshell Underground: Student Hacker Selling PHP Backdoors To Asia-Based Threat Actors To Pay for School
Howler Cell Research Team show what the at scale end of the cyber criminal spectrum looks like.
We’ve identified one hacker as a student based in Bangladesh. Our team is in contact with the hacker, who claims he is selling access to the sites to pay for his education. This reflects a growing trend in cybercrime where freelancers quietly fuel a thriving underground economy reminiscent of some of the actors tied to Scattered Spider.
The student-hacker at the center of the operation uses a PHP-based webshell known as ‘Beima PHP’ that is currently completely undetectable by modern security tools, including VirusTotal. The tool enables attackers to achieve full remote code execution over infected servers, extract sensitive data, and incorporate infected machines into a botnet.
The Government and education sectors are the primary targets of this campaign, accounting for 76% of the compromised websites for sale. The price for these websites is $200, while others sell for $3-$4. Considering the median salary in Bangladesh ($220 USD), makes it a very lucrative operation for freelancers. Transactions are conducted on Telegram.
Sharpening the knife: GOLD BLADE’s strategic evolution
Morgan Demboski provide insights into the victimology of this alleged criminal group who appear adaptable and potentially who enjoy a summer holiday.
GOLD BLADE’s ability to cycle through delivery methods and refine its techniques over time reflects a professionalized operation that treats intrusions as a core service requiring routine updates to maintain effectiveness. However, the group does not neatly fit into a conventional threat category. While it is financially motivated, GOLD BLADE’s discreet extortion strategy, long-running campaigns, and evolving tradecraft differentiate it from many other cybercriminal groups. At the same time, there is no evidence of the group being state-sponsored or politically motivated. There is also little known about where the threat actors are based. Though some third-parties report that GOLD BLADE is a Russian-speaking group, Sophos analysts have not found sufficient evidence to confirm or deny that assessment at this time.
..
Analysis of STAC6565 victimology suggests that GOLD BLADE has narrowed its targeting to focus almost exclusively on organizations based in North America. Nearly 80% of GOLD BLADE attacks linked to the STAC6565 campaign targeted Canada-based organizations.
https://news.sophos.com/en-us/2025/12/05/sharpening-the-knife-gold-blades-strategic-evolution/
Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits
Check Point Research (CPR) highlight that criminal actors, in some instances, do know their technical trade..
By analyzing the publicly leaked builder and development structure (Visual Studio solutions and project files, without source code), we were able to accurately correlate artifacts and reverse engineer the functionality of all “main” plugins. The analysis reveals the advanced skills of the developers behind ValleyRAT, demonstrating deep knowledge of Windows kernel and user-mode internals, and consistent coding patterns suggesting a small, specialized team.
The “Driver Plugin” contains an embedded kernel-mode rootkit that, in some cases, retains valid signatures and remains loadable on fully updated Windows 11 systems, bypassing built-in protection features. Through detailed reverse engineering, previously unknown capabilities were uncovered, including stealthy driver installation, user-mode shellcode injection via APCs, and forceful deletion of AV/EDR drivers.
https://research.checkpoint.com/2025/cracking-valleyrat-from-builder-secrets-to-kernel-rootkits/
Discovery
How we find and understand the latent compromises within our environments.
CLRaptor: Hunting reflected assemblies with Velociraptor
Matthew Green is back with a powerup which if they light up in production will is high signal and worthy of an investigation.
Two Velociraptor capabilities I have built:
A reflected assembly hunting artifact that consumes CLR ETW and surfaces in-memory / reflection-loaded assemblies at scale.
An artifact to identify CLR processes and detect patched or downgraded instances to overcome visibility gaps.
https://labs.infoguard.ch/posts/clraptor_hunting_for_assemblies/
Uncovering Hidden Forensic Evidence in Windows: The Mystery of AutoLogger-Diagtrack-Listener.etl
Faisal Qureshi highlights a source of forensic insight…
While analyzing a disk image of a compromised Windows Server 2016 system, FGIR was able to identify historical evidence of deleted malware and tools used by the threat actor, inside an obscure ETL file called AutoLogger-Diagtrack-Listener.etl. ETL files are generated by the Windows ETW (Event Tracing for Windows) infrastructure.
Make Attackers Cry: Outsmart Them With Deception
Defence
How we proactively defend our environments.
Guidance for Managing UEFI Secure Boot
Colleagues at the National Security Agency release this guide on how to ensure secure boot actually works as you might expect.
Recent vulnerabilities involving Secure Boot (e.g., PKFail , BlackLotu, BootHole, and similar unnamed have demonstrated the need to scrutinize the configuration of Secure Boot on enterprise devices. This document details instructions for system owners to query Secure Boot configuration, compare observed results to industry norms, and recognize and recover from misconfigurations. Organizations that neglect Secure Boot configuration may be at a greater risk of exposure to bootkits and other persistence techniques.
Checking the configuration of Secure Boot is also an important component of Supply Chain Risk Management (SCRM). Secure Boot is responsible for enforcing security policy at boot time based on a set of certificates and hashes placed within its data stores by system and operating system (OS) vendors. As the industry transitions away from 2011 signing certificates—that are nearing expiration—to new 2023 equivalents, there is even more need for organizations to scrutinize their Secure Boot configurations to ensure they are accurate and secure
https://media.defense.gov/2025/Dec/11/2003841096/-1/-1/0/CSI_UEFI_SECURE_BOOT.PDF
PowerShell 5.1: Preventing script execution from web content
Microsoft announce…
Windows PowerShell 5.1 now displays a security confirmation prompt when using the Invoke-WebRequest command to fetch web pages without special parameters. This prompt warns that scripts in the page could run during parsing and advises using the safer -UseBasicParsing parameter to avoid any script execution. Users must choose to continue or cancel the operation. This change helps protect against malicious web content by requiring user consent before potentially risky actions.
A Descriptive Model for Modelling Attacker Decision-Making in Cyber-Deception
B.R. Turnera, O. Guidettic, N.M. Kariea , R. Ryana and Y. Yana introduce a model which they plan to apply into CTF situations.
This paper introduces a descriptive model that accounts for the psychological and strategic elements that affect an attacker’s decision-making process. The model defines five core components: belief (B), scepticism (S), deception fidelity (D), reconnaissance (R), and experience (E) which interact to describe how adversaries evaluate deception and determine whether to proceed with engagement. The model offers a systematic approach to analysing engagement decisions in cyber-deception scenarios by structuring these elements within a flexible framework.
https://arxiv.org/abs/2512.03641
Sysmon Config Creation for The LOLRMM Framework
Shot Gunner releases this amazing Sysmon config to help detecting the use of remote monitoring and management tooling.
A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11
https://www.dodgethissecurity.com/2025/11/30/sysmon-config-creation-for-the-lolrmm-framework/
https://github.com/shotgunner101/Sysmon-LOLRMM
KustoHawk 🦅
Bert-Jan releases this power tool for incident responders in a Microsoft eco-system. Useful to inform the timelines of activity.
KustoHawk is a incident triage and response tool for Microsoft Defender XDR and Sentinel environments. The script collects common indicators of compromise and returns a complete picture of the activities performed by an device of account. The tool leverages Graph API to run the hunting queries across your unified XDR environment.
https://github.com/Bert-JanP/KustoHawk/
Bridging the Gap: A Look at rpi-image-gen & rpi-sb-provisioner
The Good Penguin shows how to do scaled hardware security with Raspberry Pi as a platform.
Production devices require enabled hardware security features before deployment. However, manually preparing each device is time-consuming and prone to human-error. rpi-sb-provisioner automates this entire workflow, taking a blank device to a fully provisioned state in minutes.
Designed to run on a dedicated device (they recommend a Pi 5), it supports three provisioning security levels:
naked – Just installs the OS to the disk (no encryption, no secure boot)
fde-only – Encrypted storage + device-unique keys (no secure boot)
secure-boot – Full secure boot enforcement + Encrypted storage + device-unique keys
The tool simplifies the complex process of fuse management, filesystem encryption, and OS installation.
https://www.thegoodpenguin.co.uk/blog/bridging-the-gap-a-look-at-rpi-image-gen-rpi-sb-provisioner/
Incident Writeups & Disclosures
How they got in and what they did.
Nothing overly of note this week beyond the plethora of reporting overwise covered.
Vulnerability
Our attack surface.
SVG Filters - Clickjacking 2.0
Lyra details a technique which will have application in social engineering led attacks.
I’ve discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration.
..
So the attack scenario with the QR code is that you’d read pixels from a frame, process them to extract the data you want, encode them into a URL and render it as a QR code.
Then, you prompt the user to scan the QR code for whatever reason (eg anti-bot check). To them, the URL will seem like just a normal URL with a tracking ID or something in it.
Once the user opens the URL, your server gets the request and receives the data from the URL.
https://lyra.horse/blog/2025/12/svg-clickjacking/
The Fragile Lock: Novel Bypasses For SAML Authentication
Zakhar Fedotkin once again highlights why parser inconsistencies are one of the bain of software security..
This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusion, and a new class of Void Canonicalization attacks. These techniques allow an attacker to completely bypass XML Signature validation while still presenting a perfectly valid SAML document to the application.
https://portswigger.net/research/the-fragile-lock
Offense
Attack capability, techniques and trade-craft.
Stillepost - Or: How to Proxy your C2s HTTP-Traffic through Chromium
dis0rder0x00 releases tooling to implement a C2 channel which EDR vendors and host detection engineers will want to ensure they have coverage of.
a proof-of-concept demonstrating how an implant can route its HTTP traffic through a Chromium-based browser by leveraging the Chrome DevTools Protocol. This approach turns the browser into an application-layer proxy without requiring any direct outbound network activity from the implant itself.
https://x90x90.dev/posts/stillepost/
https://github.com/dis0rder0x00/stillepost
Linux Process Injection via Seccomp User Notifications
Kyle Avery shows a rather novel injection technique on Linux which detection teams will want to ensure coverage of.
This post demonstrates the use of seccomp user notifications to inject a shared library into a Linux process. I haven’t seen this combination documented as a process injection technique before, and it has some benefits over alternatives. In summary, seccomp user notifications enable user-space injection from parent to child without any
LD_*environment variables or privileged capabilities, regardless of theptrace_scopeconfiguration. However, seccomp user notifications have some notable limitations:
https://github.com/outflanknl/seccomp-notify-injection
https://www.outflank.nl/blog/2025/12/09/seccomp-notify-injection/
Backdooring Managed Identities via Azure API Management
Cody Burkard details what he considers an architectural issue which has yet to be resolved. This will be consideration in post compromise scenarios..
Self-Hosted API Management(APIM) Gateways offer the ability to utilize Managed Identities in policies
APIM expose an undocumented “configuration” API for self-hosted gateways to collect configurations, such as policies and managed identity tokens
Managed Identity certificates, including private keys, are exposed in plaintext via the undocumented configuration API. This allows attackers to steal these internal certificates, and gain persistent access to Azure.
This issue was reported to Microsoft in 2024. Microsoft sets severity as “low”, because:
“the malicious party requires access to authentication information (In this case gateway key)”
and because
“Self-hosted gateway tokens are only valid for 30 days”
“Entra ID Apps are up to customers”
https://dazesecurity.io/blog/apimMIVuln
CLR Unhooking Tool
HwBp releases tooling which once again show why userland hooking techniques benefit from true signal and integrity approaches.
Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory .NET assembly loads. This tool unhooks that function.
https://github.com/hwbp/CLR-Unhook
EvilMist
Maldevel releases this Entra reconnaissance tooling which teams will want to develop detections for.
EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. EvilMist aims to streamline cloud-focused red-team workflows and improve the overall security posture of cloud infrastructures
Comprehensive Azure Entra ID (Azure AD) user enumeration and security assessment tool, available in both PowerShell and Python versions.
https://github.com/Logisek/EvilMist
SessionHop
elp4tr0n releases this tooling which defensive teams will want to ensure they have coverage of due to the lateral movement opportunities.
SessionHop is a C# tool that utilizes the
IHxHelpPaneServerCOM object, configured to run as an Interactive User, to hijack specified user sessions. By creating a session moniker and utilizing the COM object’sExecuteinterface, operators can run arbitrary files within another user’s session. This session hijacking technique is an alternative to remote process injection or dumping lsass, and may come in handy when operators need to keylog, screenshot, or access LDAP as the affected user.
https://github.com/3lp4tr0n/SessionHop/
Exploitation
What is being exploited..
Array Networks Array AG Series vulnerable to command injection
Japan CERT (JPCERT) detail the exploitation of this vulnerability..
The DesktopDirect function of the Array AG series provided by Array Networks contains a command injection vulnerability. An attacker exploiting this vulnerability could execute arbitrary commands. At the time of publishing this information, no CVE number has been assigned to this vulnerability. Array
Networks released a version that addresses this vulnerability in May 2025. However, JPCERT/CC has confirmed that attacks exploiting this vulnerability have occurred in Japan since August 2025, resulting in damage such as the installation of webshells on affected products.
https://www.jpcert.or.jp/at/2025/at250024.html
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers
OGhidra
Lawrence Livermore National Laboratory show the value of national labs…
OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using conversational queries and automate complex reverse engineering workflows.
https://github.com/LLNL/OGhidra
PCIe link encryption establishment via platform firmware services
Dan Williams at Intel issues this pull request for the Linux kernel which introduces the functionality described in the title.
PCIe link encryption is made possible by the soup of acronyms mentioned in the shortlog below. Link Integrity and Data Encryption (IDE) is a protocol for installing keys in the transmitter and receiver at each end of a link. That protocol is transported over Data Object Exchange (DOE) mailboxes using PCI configuration requests.
https://lore.kernel.org/lkml/69339e215b09f_1e0210057@dwillia2-mobl4.notmuch/
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week
The mathematical machinery of causal inference: from data to decision advantage - “Quantitative intelligence analysis often leans on pattern recognition; in adversary-shaped settings, such correlations can be engineered. Building on Judea Pearl’s structural causal models – originally developed for natural data-generating processes – this study makes identification, not estimation, the gate to credible claims.”
Artificial intelligence
ETSI EN 303 223 – Baseline Cyber Security Requirements for AI Models and Systems
Building an Open-Source AI-Powered Auto-Exploiter with a 1.7B Parameter Model: No Paid APIs Required
ASTRIDE: A Security Threat Modeling Platform for Agentic-AI Applications
Gated Attention for Large Language Models: Non-linearity, Sparsity, and Attention-Sink-Free
Books
Events
AWS re:Invent 2025 Security Talks - videos from last week
2026 UK Deterrence Alliance Conference - Call for Papers - King’s College London
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.


