Interestana
Home/News/Ransomware Affiliate Betrays Group, WhatsApp RAT Discovered
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Ransomware Affiliate Betrays Group, WhatsApp RAT Discovered

Ransomware Affiliate Betrays Group, WhatsApp RAT Discovered

Cybersecurity threats continue to emerge with a notable incident involving a ransomware affiliate who allegedly betrayed their group by withholding profits. This event highlights internal trust issues within criminal organizations operating in the cybercrime landscape. The affiliate's actions suggest a growing trend of individual actors prioritizing personal gain over group cohesion, potentially destabilizing established ransomware-as-a-service (RaaS) operations.

Further compounding the week's security concerns, a new threat dubbed the "WhatsApp RAT" has been identified. This Remote Access Trojan (RAT) specifically targets users of the popular messaging application WhatsApp, indicating a sophisticated effort to exploit widely used communication platforms. The RAT likely allows attackers to gain unauthorized access to a user's device, potentially enabling them to monitor communications, steal data, or control the device remotely. Details regarding the RAT's specific functionalities and the methods of infection are still under investigation, but its existence underscores the persistent threat to mobile users.

In a separate discovery, a server containing a trove of hacker tools and evidence of intrusion was found exposed. This accidental disclosure by attackers provides valuable insights into their operational methods and the tools they employ. Security researchers are analyzing the exposed data to understand the nature of the attacks and to develop countermeasures. The presence of both tools and intrusion traces on the same server suggests a potential lapse in the attackers' own security practices, ironically mirroring the vulnerabilities they exploit in their targets.

Beyond these headline incidents, the week's threat landscape also included malicious code found within developer packages and extensions. This tactic, often referred to as "dependency confusion" or "supply chain attacks," involves injecting malicious code into legitimate software components that developers rely on. When these compromised components are integrated into larger projects, the malware can spread widely, affecting numerous downstream users and applications. The discovery of such threats in developer tools emphasizes the critical need for robust security vetting throughout the software development lifecycle. The continuous emergence of these diverse threats, from affiliate betrayals to sophisticated RATs and supply chain compromises, paints a concerning picture of the evolving cybercrime ecosystem.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next