Threat actors have used a multi-stage framework deploying a remote access trojan and a fake information-stealing Google Docs Offline extension for Chrome in yet another twist to the GlassWorm campaign, The Hacker News reports.
Attacks in the campaign, which avoided Russia-based systems, involved the exploitation of Solana transactions as a dead drop resolver for command-and-control server and OS-specific payload retrieval, according to an analysis from Aikido researchers.
Installation of an information-stealing framework with cryptocurrency wallet and credential theft and system profiling functionality as a second-stage payload enables exfiltration of obtained data in the form of a ZIP archive to an external server and the subsequent retrieval of a .NET binary for hardware wallet phishing and a Websocket-based JavaScript RAT for browser data compromise and arbitrary code execution. Targeted session surveillance is then made possible by the JavaScript RAT's forced installation of the malicious Chrome extension on Windows and macOS systems.
Such findings come as malicious npm packages spoofing the WaterCrawl Model Context Protocol server were reported by Koi researchers to have facilitated illicit payload delivery in GlassWorm attacks.
Attacks in the campaign, which avoided Russia-based systems, involved the exploitation of Solana transactions as a dead drop resolver for command-and-control server and OS-specific payload retrieval, according to an analysis from Aikido researchers.
Installation of an information-stealing framework with cryptocurrency wallet and credential theft and system profiling functionality as a second-stage payload enables exfiltration of obtained data in the form of a ZIP archive to an external server and the subsequent retrieval of a .NET binary for hardware wallet phishing and a Websocket-based JavaScript RAT for browser data compromise and arbitrary code execution. Targeted session surveillance is then made possible by the JavaScript RAT's forced installation of the malicious Chrome extension on Windows and macOS systems.
Such findings come as malicious npm packages spoofing the WaterCrawl Model Context Protocol server were reported by Koi researchers to have facilitated illicit payload delivery in GlassWorm attacks.




