Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.
Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.
Google is tightening restrictions on one of mobile malware's most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection.
The move, announced Thursday, targets a problem that has haunted Android security for years. The AccessibilityService API was built to help people with disabilities use their smartphones. Screen readers, voice control apps, and motor-assistance tools all rely on it. But the privileges it carries are significant. Apps that tap into the API can run in the background, observe what appears on screen, intercept UI events, and take actions inside other applications on a user's behalf. That set of capabilities made it a target for malware developers almost immediately after it was introduced.
Google stated in its announcement that the new version automatically restricts AccessibilityService access to verified Accessibility Tool applications, closing off a major attack avenue while keeping genuine assistive technology functional.
A Clichéd Attack Path
Malware families have been weaponizing Android's accessibility services since at least 2017. The list of known offenders runs long: Vultur, SharkBot, Xenomorph, BianLian, Anatsa (also tracked as TeaBot), and more recently BTMOB RAT, a remote access trojan documented attacking banking customers across Brazil, Argentina, Spain, Portugal, and Mexico through 2025 and 2026. According to Kaspersky data, trojans accounted for 40 percent of Android malware infections in Q1 2025, with nearly 12 percent of malicious apps falling into the banking trojan category that specifically abused the Accessibility API, totaling around 154,000 apps.
The attack chain is well understood. A malicious app, typically distributed through sideloaded APKs or disguised as something routine, tricks a user into granting accessibility permissions. The Anatsa trojan, for instance, slipped onto Google Play as a PDF viewer update as recently as July 2025. Once the permission is granted, the malware operates without root access. It can monitor keystrokes, layer fake login pages on top of legitimate banking apps, approve system dialogs silently, and initiate fraudulent fund transfers from financial applications without the user noticing anything unusual on screen. Google noted in its announcement that this access also allows malware to block its own uninstallation, locking users out of any easy remedy.
What Changes in Android 17
The new restriction applies specifically when Advanced Protection is active, a device-level security mode introduced with Android 16 that consolidates multiple hardening features under a single toggle. When a user enables it, the system now automatically enforces that only verified, legitimate accessibility apps can request AccessibilityService access. Everything else is denied.
This is part of a gradual tightening that has been underway for several years. Android 13 made it significantly harder for sideloaded apps to acquire accessibility permissions. In-call protections, rolled out more recently, prevent users from granting those permissions during a phone call, cutting off a common social engineering scenario. Google also introduced the `accessibilityDataSensitive` flag to let developers mark UI elements as off-limits to third-party accessibility readers.
The Rest of Android 17's Security Updates
The accessibility change is one piece of a wider hardening effort in Android 17. Intrusion Logging, developed in collaboration with Amnesty International's Security Lab and other civil society organizations, creates a persistent, privacy-preserving forensic record of sensitive system events. Amnesty's team simultaneously updated AndroidQF and its Mobile Verification Toolkit to process the new log format, making it immediately useful for researchers investigating suspected spyware infections.
USB Protection blocks new data connections over a USB port while the device is locked, preventing physical access attacks where an attacker might attempt to extract data or push commands through a connected cable. Google has also included an option to disable WebGPU, a graphics API that has surfaced in sophisticated browser-based exploit chains. Failed Authentication Lock responds to repeated incorrect login attempts by locking the device entirely, making brute-force attempts against a stolen or seized phone substantially harder.
A fifth addition, View Supporting Apps, gives users a clear window into which installed applications have checked whether Advanced Protection is active on the device.
For developers, Google confirmed that applications can receive a notification when a user enables Advanced Protection, allowing them to switch on their own high-security features automatically for that audience.
Existing Advanced Protection users will receive a notification when the new capabilities land on their device. Intrusion Logging is not switched on by default and must be enabled manually from the Advanced Protection settings page.
Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The campaign abuses the open-source Baileys library, an unofficial implementation of the WhatsApp API that developers use to build customer support bots, chat managers, and automation tools, to carry out the subscriptions without any visible prompt or warning.
The packages have collectively been downloaded roughly 490,000 times, with 116,000 of those downloads occurring in the last 30 days. The single most downloaded package, `ourin-baileys`, accounts for 130,589 installs on its own, nearly a quarter of the campaign's total reach. As of publication, the majority of the 101 packages remain live on npm. Sixteen had been removed, and seven of those were pulled before researchers could review the code to determine which variant of the malware they carried.
The campaign did not begin in 2026. The oldest package in OX Security's list, `alipclutch-baileys`, was first published in October 2025. Several others date to December 2025, meaning this operation has been running quietly on the registry for close to a year before receiving a formal write-up.
Three Ways to Hide the Same Payload
OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko identified three distinct variants of the malware, each handling the subscription routine differently.
The first variant, found in 19 packages, fetches channel IDs from GitHub at runtime. By hosting the target list externally, operators can swap out which accounts receive new followers without ever publishing a new package version to npm. One package, `@rixxcodex/baileys`, hides the GitHub URL inside media-download code using Base64 encoding so it is unlikely to catch the eye of anyone skimming the source.
The second variant, covering 60 packages, simply embeds the channel IDs in cleartext inside the source code. Two packages took additional steps to bury this, placing the subscription logic inside an upstream connection handler and inside a file named after the Signal cryptographic protocol, a location most developers would never think to inspect.
The third variant, found in 14 packages, encodes the hardcoded channel IDs using Base64. One package in this group, `neuralwhatsapp`, takes a slightly different approach: rather than storing a channel ID directly, it resolves its target from a hardcoded WhatsApp invite code at runtime.
The Follower Inflation Business
The goal is not data theft or ransomware deployment. The channels identified in this campaign are mostly small bot-seller and marketplace accounts, largely Indonesian, where follower counts function as social proof for selling bot scripts, premium APKs, social media boosting services, and in-game resources.
Among the specific channels researchers identified: Neural has 798 followers and markets game-currency sales through a platform called JualanRSS, which deals in in-game resources including food, ore, stone, timber, and gold. MONTE-BMG has 1,000 followers. CORTANA TECH has 1,300 and points visitors to a dedicated website. Fyxzpedia.ID-Utama, with 4,800 followers, sells WhatsApp and Telegram bot scripts and bot-building services outright. One Spanish-language channel called Redes Oficiales sits at 19,000 followers and is linked to a YouTube creator, pushing back against the assumption that this is a purely Indonesian operation.
The threat actors mute these channels on the victim's device after subscribing them, so the added follower count appears organic to outside observers. A channel with thousands of followers reads as trustworthy, and that manufactured trust is the product being sold to the operators running these marketplaces.
One channel, MONTE-BMG, illustrates how the monetisation funnel actually works. It posts what appears to be a screenshotted sales negotiation in Arabic, ending with a group invite link. That link leads to a brand-new channel with only 12 followers, whose own description contains yet another group invite. The inflated parent channel is only the entry point. The actual transaction gets moved progressively deeper into a private chain of groups where there is no public record.
Beyond follower inflation, the SafeDep research team noted earlier this year that some Baileys forks in this campaign also inject the package author's advertising URL into every image and video the bot sends, a second payload the follower-count headline tends to obscure.
One Coordinated Operation, Many Names
OX Security found that 32 channels are followed by more than one package across this campaign. The single most reused channel, identified by the ID `120363400911374213@newsletter`, is targeted by ten separate packages. One remote channel list hosted on GitHub feeds five different packages simultaneously, meaning the operator can retarget all five installations by editing a single file.
Operators routinely publish near-identical packages under slightly different names to preserve the campaign when individual listings get removed. `noxleyss` and `@noxleyss/baileys`, for example, carry the same code under different publisher accounts.
Details of the abuse first emerged in August 2026 when SafeDep identified Baileys npm forks making installers' WhatsApp accounts follow attacker-controlled channels. Earlier this month, the Xygeni Security Research Team separately detailed another Baileys modification, `@dappaoffc/baileys-mod`, which subscribed developers' authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.
The campaign follows a pattern OX Security has tracked on npm before. An earlier operation used the same registry to host fake Cloudflare CAPTCHA pages designed to redirect visitors to ClickFix phishing infrastructure. The registry's scale and the institutional trust developers place in what appear to be legitimate forks of known libraries make it a dependable distribution channel for this kind of abuse.
Because the packages carry none of the classic malware signatures, no API token theft, no heavy obfuscation across the board, no destructive payload, standard threat detection tools are likely to miss them entirely. That is precisely why most of these packages have remained live for months.
What Developers Should Do
Security recommends checking whether your WhatsApp account has been added to unknown channels and blocking or reporting any that appear. Developers should avoid any npm package that requires connecting a personal WhatsApp account and should add detection rules to their pipelines flagging known malicious Baileys forks. Remote channel-list URLs identified in these packages can be added to URL-reputation and threat-intelligence pipelines for ongoing monitoring.
Infoblox discovered that around 65,000 earlier previously registered domains are re-registered everyday, showing around one in five newly found domains,
When a domain is dead, the history does not vanish immediately. The domain may still consist of traffic, backlinks, search-engine visibility, and an image built when it was in legitimate use previously.
Attackers can buy these domains and exploit the existing digital footprint. This can make a malicious infrastructure less dangerous than an entirely new domain.
The tactic is usually called “dropcatchin”. Instead of making new sites from scratch, threat actors buy domains that have already created some level of visibility and trust.
One of the largest campaigns detected by Infoblox is an attacker called Sable Squirrel. According to experts, the group has control over 10,000 domains and believe that it has invested over $7 million buying expired domains.
“This actor has spent years turning other people’s domain history into its own criminal infrastructure, then using that infrastructure to run illegal sports streaming, online gambling promotion, and malware command-and-control (C2) side by side,” Infoblox said.
Majority of the domains support a large gambling operation and sports streaming aimed mostly at Asian users, But experts found that some of the same infrastructure was utilised for command and control (C2) operations.
Infoblox found over 31000 malware samples interacting with Sable Squirrel infrastructure such as njRAT, Remcos, NanoCore, DCRat, AsnycRAT, and Quasar RAT additionally with samples linked to HiddenTear ransomware. Experts confirmed 405 domains being exploited as malware command-and-control infrastructure.
Sable Squirrel was not the only group using dead domains, Infoblox also detected groups such as Swiping Squirrel, Shady Squirrel and Stuffy Squirrel. Some groups buy domains previously associated with malicious activity and exploit the existing traffic to redirect targets towards malware, advertising fraud, or scams.
Sable Squirrel’s main business is gambling, but it masks it as a streaming operation, while also doubling as an acquisition channel for the same.
“In Sable Squirrel’s hands, the domain becomes more than an address. It is the unit of trust, the traffic source, the brand surface, the routing layer, and, in some cases, the control channel,” said Infoblox.
The malware was analyzed in infected environments consisting of F5 BIG-IP Access Policy Manager (APM) and was discovered by Sophos as Linux/Agnt-IC. “The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments,” Sophos reported.
The research was posted on September 7, 2026, and shows how the rootkit interferes with the PHP runtime and Apache web server to deploy malicious code without making major modifications to authentic PHP files stored on the device.
One significant feature of the malware is that it can install malicious PHP code directly into the running web server’s memory.
Generally, threat actors planting a PHP web shell would also modify or make a PHP file on the server. Security teams can then detect the malicious file via antivirus scans, manual investigation, or file-integrity monitoring.
The rootkit detailed by Sophos takes another approach. It changes how PHP files are shown to the running Apache process while the original files on disk are left unchanged.
This means that a file scan could demonstrate that a PHP is authentic even when the server is actively running malicious code.
Researchers at Sophos discovered that the implant deploys various sophisticated approaches to take command over the web server. It integrates into the device’s startup process and surveys Apache activity to find out when the PHP module is loaded.
After this, the malware can bring its own web-shell functionality and change the in-memory PHP environment.
The installed web shell gets specially tailored HTTP requests and runs commands given by the threat actor. Sophos also found the implant deploying a Unix domain to socket to offer another path of communicating with an infected system and launching a shell.
This combination allows attackers several ways of maintaining access while covering the traces left on the filesystem.
The attack has become a problem for experts as the malware does not always have to alter files to attack a server. Security teams should check beyond traditional file-integrity check and analyze memory activity, network traffic and running processes.
Sophos recommends that security teams look beyond conventional file-integrity checks and examine network traffic, running processes and memory activity.
A remote access tool built for IT departments and help desks is now being weaponized against them. Researchers at Huntress say they've found hacked versions of ConnectWise's ScreenConnect software that don't just give attackers a foothold on one machine, they use that foothold to infect whoever connects to it next, turning a single compromised endpoint into a launching pad for further attacks.
Huntress said its Security Operations Center issued three critical incident alerts in late August after spotting the same unusual pattern across customer networks that had nothing else in common. In each case, a rogue ScreenConnect client had been planted through social engineering, and once running, it began quietly automating an infection chain that most victims never saw coming.
Three break-ins, one playbook
The entry points varied, but the outcome didn't. On August 20, Huntress caught a case that started with a classic tech support scam: someone called a victim claiming their computer had been hacked, then walked them through opening Quick Assist, the remote help tool that ships with Windows, and handing over control. Once inside, the attacker installed a ScreenConnect client wired to call home to a server at 45.13.237[.]190, an address that VirusTotal had tied to a domain called tele-sync.opik[.]net earlier that same month.
A second incident, logged the same day, took a different path in. The victim ran a file called ScreenConnect.ClientSetup.msi straight out of a Microsoft Edge downloads folder, almost certainly after clicking through a phishing email. That installer set up a client pointed at a separate server, 131.123.40[.]98, over port 8041. Huntress later found the same machine reaching out to several more IP addresses tied to the campaign's infrastructure.
The third case, on August 24, started with something almost mundane: a person searching online for a Geek Squad refund form. Instead of a form, they got a rogue ScreenConnect.Client.exe that connected back to a domain named borertors92.anondns[.]net. Huntress shut this one down quickly enough that it never progressed past the initial script execution.
Different bait, same result. Once the ScreenConnect client landed on a machine, it began repeatedly calling wscript.exe, the built-in Windows scripting engine, to fire off four files named, plainly, 1.vbs, 2.vbs, 3.vbs and 4.vbs.
What the four scripts actually do
Huntress pulled the scripts apart and found a loader designed to feel its way around a system before deciding what to drop on it.
The first script checks whether ScreenConnect is already installed, looks for security software including Huntress's own agent, CrowdStrike, SentinelOne, Sophos, Malwarebytes and Cisco AMP, and checks how much memory the machine has, likely a crude way of ruling out sandboxes and virtual machines used by researchers. It boils all of that down into a three-digit code and drops it into a file called value.txt in the Windows temp folder.
The second script waits for that file to appear, then fetches a link from Dropbox, decodes it and stores the result as a lookup table. Each possible three-digit combination in that table maps to a different payload and a different AES decryption key. The third script reads the table, matches it against the code generated earlier, and downloads whichever payload fits. The fourth script grabs the matching decryption key, builds a PowerShell script from scratch inside the VBScript itself, and runs it with Windows' script execution safeguards switched off.
That PowerShell script does the actual unwrapping, decrypting the downloaded file and handing control to a second, more capable PowerShell script that Huntress found renamed as PyTorchFix.ps1. Depending on which of the three outcomes the profiling scripts settled on, the victim ends up with either a bare-bones backdoored ScreenConnect client, a version bundled with tools for privilege escalation and persistence, or the full package: tunneling software and a cryptocurrency miner thrown in as well.
One small detail stood out to the researchers. A comment buried in the third script spells out the payload table's format in plain, tutorial-style language, the kind of explanatory note that reads less like something a human attacker jotted down and more like something an AI coding tool generated on the fly.
How the infection spreads on its own
This is the part that makes the campaign unusual. Buried in the backdoored ScreenConnect client is code that watches ScreenConnect's own connection list for new sessions. The moment somebody new connects, whether that's another victim, a technician, or anyone else routed through the same infrastructure, the client repackages all four VBScript files, hands them to ScreenConnect's built-in file transfer feature, flags them to run automatically, and pushes them straight to the new arrival.
Huntress described it as the modified client using the server's own connection status data to figure out who just showed up, then quietly loading them up with the same infection. The client keeps a short memory of which sessions it has already hit so it doesn't repeat itself mid-session, but that memory resets once someone disconnects, meaning a second visit from the same person can trigger the whole thing over again.
The heavier version of the payload came with extras: a copy of the tunneling tool wstunnel disguised under the filename Themes.exe, reaching out to homehub.opik[.]net over port 443; an XMRig cryptocurrency miner renamed SearchIndex.exe; and a known vulnerable driver called WinRing0, saved as svcdrv64.sys, which attackers commonly use to get code running with elevated privileges. The malware also went after Windows Defender directly, disabling its reporting and notifications and switching off a hardware-level protection called Hypervisor-Protected Code Integrity. In at least one case, the attackers also dropped a second remote access tool, UltraViewer, apparently as a fallback in case ScreenConnect got pulled.
Huntress caught and stopped all three original incidents before the attackers finished the job, but the firm says it has continued to see the same pattern show up elsewhere since. Because the malware digs in so deep, wiping the affected machines and rebuilding them from clean media is what Huntress is telling customers to do rather than trying to clean an infected system in place.
Where ConnectWise fits in, and where it doesn't
Huntress says it's been talking with ConnectWise throughout the investigation, and on September 3, ConnectWise published its own advisory describing a problem with file transfer behavior in ScreenConnect's Remote Access, Support and Access sessions, affecting both the cloud-hosted version and self-hosted, on-premises deployments.
The company said a CVE number and an official patch are coming within the week. In the meantime, it's telling ScreenConnect administrators to go into Administration, then Security, then Roles, and check whether the TransferFiles permission, called TransferFilesInSession in older builds, is switched on for any assigned role. If it is, ConnectWise says to turn it off, a change that doesn't require updating ScreenConnect itself and can be applied right away.
One thing worth being precise about: ConnectWise has not said the file transfer issue is technically the same vulnerability the Huntress campaign is exploiting. The advisory and the Huntress research came out around the same time and clearly describe related territory, file transfer abuse inside ScreenConnect sessions, but the company has stopped short of confirming a direct link between the two.
Huntress, for its part, is telling anyone running ScreenConnect on-premises to take a closer look at their deployments regardless. The firm recommends digging through ScreenConnect's server-side audit logs for RunFiles or RanFiles entries tied to a Guest process, especially any referencing unfamiliar VBScript or PowerShell activity, and treating that as an immediate red flag. Huntress also cautioned that the exact filenames tied to this campaign will likely change as the attackers adjust, so the underlying behavior, scripted execution launched through a ScreenConnect session, matters more than the specific file names.
Not the first time ScreenConnect has been a target
This isn't ScreenConnect's first brush with mass exploitation. In February 2024, ConnectWise disclosed a pair of vulnerabilities in the product, an authentication bypass rated a perfect 10 on the CVSS scale and a path traversal flaw alongside it, that let attackers create administrator accounts on exposed servers without needing valid credentials. Proof-of-concept code for those bugs went public within days, and Huntress's own CEO at the time called it the makings of what could be the biggest cybersecurity incident of that year, given that a single exploited server could hand attackers control over thousands of downstream endpoints managed through it.
What followed was a scramble. Security vendors including Sophos and Darktrace tracked ransomware built from a leaked LockBit builder tool being dropped through the exploited servers, alongside Cobalt Strike beacons and remote access trojans. The Cybersecurity and Infrastructure Security Agency later added one of the two flaws to its Known Exploited Vulnerabilities catalog. More recently, other research teams have logged waves of signed ScreenConnect droppers used in financial sector phishing campaigns, and industry researchers have generally flagged remote monitoring and management software as one of the more consistently abused categories of legitimate IT tooling over the past couple of years, precisely because it's designed to do the thing attackers want: get full control of a machine without tripping the alarms a piece of unfamiliar malware would.
The current campaign fits that same pattern in terms of how attackers get in, but the automated, self-spreading distribution mechanism built into the client itself is new territory, and it's the detail that has researchers paying closer attention this time around.
As per Elastic Security Labs, the four programs are called LockAppHost, SoftManager, WinUpdate, and ProManager.
Experts found that the components can stay on a computer even when REVSTEALER removes itself. This makes the compromise hard to locate and stop.
“Unlike most commodity stealers, REVSTEALER seems to put more effort into validating its targets; this is evident in its cryptocurrency wallet harvester, which uses a multi-layer architecture with a discovery engine followed by a collector that applies wallet-specific extension filters to extract only relevant files,” Elastic Security Labs reported.
Available as a commercial malware since February 2026, REVSTEALER is a rising Windows information stealer. It can store browser cookies and passwords, messaging data, cryptocurrency wallet details, files from compromised systems, and gaming accounts. Once the information is stolen, the primary malware deletes itself, which results in making the computer look legitimate.
But the four newly discovered programs work distinctly as they can remain on the target's computers by installing themselves.
LockAppHost
LockAppHost is the most disruptive component, because before launching a cryptocurrency miner, it can disable Windows security.
SoftManager
SoftManger turns a compromised system into a reverse proxy. This permits threat actors to direct their network traffic via the target’s internet connection, possibly covering the tracks of the threat actor’s real location.
WinUpdate
WinUpdate surveys the Windows clipboard. The malware can replace the addresses controlled by attackers when a user copies cryptocurrency wallet addresses. This may send cryptocurrency payments to the threat actors
ProManager
Cryptocurrency wallets are the main focus of this program. ProManager can steal browser wallet extensions and wallet files. Experts also discovered that the program can show attacker-controlled content over genuine cryptocurrency wallet apps and store passphrases and passwords typed by users.
LockAppHost can get admin privileges to make major changes in the Windows system, Elastic found.
LockAppHost can also disable five Windows Update services, impact Microsoft Defender, turn off two malware-removal tasks, and shut down 11 scheduled update tasks. It launches a cryptocurrency miner after compromising the computer’s security features.
The miner makes it difficult to detect for users to find out malicious operations and for security software to detect by hiding inside authenticated Windows processes.