NEWS

ThreatsDay Recap: Ransomware Affiliate Betrayal, WhatsApp RAT & More

Weekly roundup: a ransomware affiliate's betrayal, a new WhatsApp RAT, exposed attacker tools, Qilin's extradition, and more supply-chain abuse.

Dylan H.

News Desk

October 8, 2026
7 min read
ThreatsDay Recap: Ransomware Affiliate Betrayal, WhatsApp RAT & More

ThreatsDay Recap: 15 Stories, and Trust Breaking Down on Both Sides

This week's ThreatsDay bulletin from The Hacker News, published October 8, 2026, rolls up roughly 15 separate incidents — and the recurring theme is trust failing on every side of the fence. A ransomware affiliate cut his own gang out of the payout and leaked the data himself, while elsewhere an attacker's own staging server was found wide open on the internet, tools and intrusion evidence still sitting on it. Below are the seven most significant items from the roundup, led by the two named in the original headline — the ransomware affiliate betrayal and a new WhatsApp-delivered RAT — plus a law-enforcement extradition, exposed attacker infrastructure, fresh supply-chain abuse, and a major anti-scam takedown.


Ransomware Affiliate Pockets the Payout

The Gentlemen ransomware-as-a-service operation has an internal integrity problem. A Russian-speaking affiliate using the alias Azazel broke from the group's payout structure, stealing victim data from at least two dozen organizations across six countries and republishing it on a separate extortion site called Leakned rather than routing proceeds back through the RaaS operator as affiliate agreements normally require. The move effectively double-extorts the same victims — once under the Gentlemen brand, and again under Azazel's own leak site — while cutting the ransomware operator entirely out of its usual affiliate-fee cut.

The episode underscores that RaaS "trust" is contractual, not technical: nothing stops an affiliate with data access from reselling or re-leaking it independently. For victims, a single intrusion can now mean extortion demands — or public leaks — from more than one party.

A New WhatsApp-Delivered RAT: VulcanRAT207.A

Researchers also flagged a WebSocket-based remote access trojan tracked as VulcanRAT207.A, distributed via WhatsApp using a financial-themed lure disguised as an executable named Statement.exe. Once run, the malware loads a vulnerable signed driver, GoFly64.sys, in a Bring Your Own Vulnerable Driver (BYOVD) technique to terminate Baidu security processes, then injects into a legitimate process using a variant of the PoolParty injection method (Variant 7) staged through Windows Task Scheduler — notably without calling CreateRemoteThread, a function many EDR products specifically monitor.

Once resident, VulcanRAT207.A collects system metadata, opens an interactive shell back to its operators, enumerates accounts, manipulates the clipboard, and can self-terminate to evade forensic capture. Pairing a trusted consumer messaging app for delivery with a BYOVD-plus-PoolParty chain for defense evasion makes this one of the more technically complete RAT campaigns in this week's roundup.

Qilin Ransomware Suspect Extradited to Germany

On the law-enforcement side, a 28-year-old Russian national linked to the Qilin ransomware operation was extradited to Germany on October 2, 2026, after being detained in Osaka, Japan, back in May 2026. Authorities tie the suspect to a September 2024 attack on a logistics company in which Qilin affiliates demanded more than $160,000 in cryptocurrency. It's a rare case of a Qilin-linked arrest actually resulting in extradition rather than remaining stuck in diplomatic limbo.

Exposed Attacker Infrastructure Tied to Viva Aerobus Intrusion

Researchers investigating the late-September 2026 intrusion at Mexican airline Viva Aerobus found that the attacker's own staging server, at 151.243.232[.]123, had been left exposed on the open internet — complete with 17 distinct post-exploitation tools, including Mimikatz output, credential-testing scripts, SQL utilities, and file-transfer tools. Initial access into Viva Aerobus reportedly came through a Microsoft SQL Server instance via xp_cmdshell, with stolen data exfiltrated as Base64-encoded output smuggled through MSSQL query results.

Because the staging infrastructure was left unsecured, researchers warned that unrelated internet hosts — not just the original investigators — could have stumbled onto and interacted with the same attacker-controlled server, a reminder that criminal infrastructure is frequently as poorly secured as the environments it targets.

Malicious npm and RubyGems Packages Target Developers

Supply-chain abuse continued across multiple ecosystems. On npm, the package @subql/common v5.8.3 shipped a credentials collector with remote shell access, targeting both developer workstations and CI/CD runners including GitHub Actions. Separately, a RubyGems publisher using the handle reqthrottle_3474 pushed 42 malicious gems: 11 opened reverse shells to 45.138.12[.]177 over ports 8089/8090, while 31 others downloaded a secondary payload (wgkit.tar.gz) from the same IP on port 8092.

A third cluster, nicknamed "dirtyblanket," published 9 self-spreading Linux worm packages to npm inside a 33-minute window on September 29, 2026. The worms drop a backdoor disguised as systemd-fontd running the CHAOS RAT, communicate over Tor, harvest SSH keys, and attempt further propagation via Arch User Repository (AUR) packages — an unusually aggressive, self-propagating pattern for a package-registry attack.

GlassWorm Returns in Malicious VS Code Extensions

The GlassWorm campaign resurfaced in four new Visual Studio Code extensions — "Aurora Nocturne Night Theme," "Coca-Cola Christmas," "Aurora Borealis Studio Theme," and "Cosmic Nebula Themes" — published across both the official Visual Studio Marketplace and Open VSX. Each extension hides an obfuscated Windows downloader; once triggered, a loader decrypts and runs embedded JavaScript that resolves its command infrastructure through Solana blockchain transaction memos acting as a dead-drop, and the malware deliberately avoids executing on systems with Russian-language settings or time zones.

Researchers linked the "Cosmic Nebula Themes" extension to the same Solana wallet address and AES key documented in earlier GlassWorm activity, and identified six cluster-linked publisher identities spread across the two marketplaces — underscoring that extension marketplaces remain an under-scrutinized software supply chain.

Operation Blackout: $17 Billion Seized From Scam Compounds

On the enforcement side, a multinational effort dubbed Operation Blackout led to hundreds of arrests and the seizure of roughly $17 billion in assets tied to forced-labor scam compounds across Southeast Asia, the Middle East, and Africa. Authorities say thousands of trafficked workers were freed from purpose-built compounds used to run fake cryptocurrency investment schemes targeting elderly victims in the United States via social media, phone calls, SMS, and Telegram.


Recommendations

For Security Teams

  • Hunt for BYOVD indicators — unusual signed-driver loads that terminate security processes — and for PoolParty-style process injection staged via Task Scheduler rather than CreateRemoteThread.
  • Treat ransomware affiliate programs as an unreliable trust boundary: assume stolen data can surface on a secondary leak site even if a primary ransom is never paid.
  • Monitor for xp_cmdshell usage and unusual Base64-encoded query-result traffic on internet-facing MSSQL instances.

For Developers and DevOps

  • Pin dependency versions and review diffs before upgrading npm or RubyGems packages; treat sudden maintainer or publishing-pattern changes as a red flag.
  • Restrict CI/CD runner egress and credential scope so a single compromised dependency can't pivot into GitHub Actions secrets.
  • Audit installed VS Code and Open VSX extensions by publisher identity and requested permissions, not just install counts.

For End Users

  • Treat executables sent over WhatsApp or other messaging apps — even convincingly named files like Statement.exe — as untrusted by default.
  • Be skeptical of unsolicited cryptocurrency investment pitches via SMS, Telegram, or social media; Operation Blackout's scale shows these schemes are industrialized, not isolated scams.

Key Takeaways

  1. RaaS "trust" is contractual, not technical — a rogue Gentlemen affiliate (Azazel) re-extorted victims independently, cutting the ransomware operator out entirely.
  2. VulcanRAT207.A pairs a trusted delivery channel (WhatsApp) with BYOVD driver abuse and CreateRemoteThread-free process injection, a combination built to slip past standard EDR heuristics.
  3. Attacker infrastructure is often as poorly secured as victim environments: the exposed Viva Aerobus-linked staging server handed researchers — and potentially anyone else online — a full 17-tool kit, including Mimikatz output.
  4. Supply-chain abuse hit multiple ecosystems simultaneously this week, with malicious packages surfacing on npm, RubyGems, and VS Code/Open VSX extension marketplaces via GlassWorm.
  5. Law enforcement delivered two notable wins: the extradition of a Qilin-linked suspect to Germany, and Operation Blackout's $17 billion seizure from forced-labor scam compounds.
  6. Across nearly every item this week, initial compromise relied on abusing something inherently trusted — a messaging app, a signed driver, a package registry, or an affiliate agreement — rather than a novel technical exploit.

Sources