Full Report
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that
Analysis Summary
# Morning News Roll-up October 08, 2026
## Overview
The latest threat intelligence highlights a significant trend in supply chain compromises through developer ecosystems and the continued evolution of remote access tools. Key incidents involve malicious VS Code extensions linked to known threat actors, the mapping of specialized access-broker infrastructure, and financial-themed malware delivery via messaging platforms.
## Top Stories
### Malicious VS Code Themes Linked to GlassWorm
- Summary: Researchers discovered several malicious VS Code themes (e.g., "Coca-Cola Christmas" and "Aurora Borealis Studio Theme") on the Visual Studio Marketplace and Open VSX. These extensions contain loaders that execute embedded JavaScript, utilize Solana transaction memos as dead drop resolvers for C2 infrastructure, and specifically avoid infecting Russian-language systems.
- Source: hxxps://socket[.]dev/blog/glassworm-vscode-themes
### BraZetsu Access Broker Infrastructure Mapping
- Summary: An analysis of the BraZetsu Python-based malware framework revealed a tightly coupled infrastructure where C2 and control panel hostnames share the same apex domain and VPS. The malware is used by access brokers to feed the "Infected Marketplace," selling compromised Windows host access for cryptocurrency.
- Source: hxxps://hunt[.]io/blog/brazetsu-access-broker-infrastructure
### VulcanRAT207.A Delivered via WhatsApp
- Summary: A new campaign uses a financial lure ("Statement.exe") sent via WhatsApp to deploy VulcanRAT207. The attack employs a multi-stage chain including a signed GoFly driver to perform Bring Your Own Vulnerable Driver (BYOVD) attacks, terminating local security processes to ensure persistence.
- Source: hxxps://www[.]morphisec[.]com/blog/copy-of-how-to-stop-ransomware-before-execution/
# Main Topic
Supply chain attacks via developer marketplaces and multi-stage malware delivery targeting enterprise credentials and remote access.
## Key Points
- **Marketplace Poisoning:** Attackers are successfully bypassing Visual Studio Marketplace security by disguising malware as harmless UI themes.
- **Dead Drop Resolvers:** Use of the Solana blockchain (transaction memos) to host C2 addresses provides a resilient and difficult-to-block infrastructure for GlassWorm actors.
- **BYOVD Escalation:** Increasing use of signed but vulnerable drivers (like GoFly64.sys) to bypass EDR/Antivirus by terminating their processes at the kernel level.
- **Access Broker Economy:** The BraZetsu infrastructure highlights a professionalized pipeline from initial infection to automated sales on underground marketplaces.
## Threat Actors
- **GlassWorm:** A threat group linked to supply chain attacks on developer tools; uses obfuscated loaders and blockchain-based C2 resolvers.
- **BraZetsu Affiliates:** Access brokers focusing on Windows host compromise for resale.
## TTPs
- **T1584.005:** Infrastructure: Botnet (Use of Solana blockchain for dead drop resolution).
- **T1068:** Exploitation for Privilege Escalation (BYOVD technique using `GoFly64.sys`).
- **T1553.002:** Subvert Trust Controls: Code Signing (Use of signed drivers to bypass security software).
- **T1195.002:** Supply Chain Compromise: Compromise Software Dependencies (Malicious VS Code extensions).
- **Geofencing:** Payloads programmed to terminate if Russian language or timezones are detected.
## Affected Systems
- **Windows OS:** Primary target for BraZetsu and VulcanRAT207.
- **Visual Studio Code:** Developers using the Visual Studio Marketplace or Open VSX environments.
- **Baidu Security Products:** Specifically targeted for termination by the VulcanRAT207 loader.
## IoCs
- **Domains:**
- c2[.]installscenter[.]com
- painel[.]installscenter[.]com
- **IP Addresses:**
- 80[.]78[.]27[.]252
- **Files:**
- Statement[.]exe
- GoFly64[.]sys
- **Extensions:**
- Coca-Cola Christmas (VS Code)
- Aurora Borealis Studio Theme (VS Code)
- Cosmic Nebula Themes (VS Code)
## Mitigations
- **Extension Vetting:** Implement organizational policies to restrict VS Code extension installations to verified publishers only.
- **Driver Signature Enforcement:** Use Windows Defender Application Control (WDAC) to block known vulnerable drivers (BYOVD mitigation).
- **Network Monitoring:** Monitor for unusual outbound traffic to blockchain gateways (Solana API endpoints) from developer workstations.
- **Email/Messaging Filtering:** Block execution of `.exe` and `.sys` files delivered through non-standard channels like WhatsApp or personal email.
## Conclusion
The threat landscape is currently characterized by "trust exploitation"—whether it is the trust developers place in IDE extensions or the trust the OS places in signed drivers. Organizations should prioritize securing developer environments and implementing strict controls over kernel-mode drivers to mitigate these sophisticated multi-stage campaigns.