← Blog · · df00tech

ThreatsDay Roundup: Ransomware Affiliate Keeps the Loot, Exposed Attacker Infrastructure, and Malicious Packages in the Wild

security-news campaign

What happened

According to a weekly roundup published by The Hacker News, a ransomware affiliate reportedly broke from the usual ransomware-as-a-service revenue split and kept victim payments for himself rather than sharing proceeds with the ransomware operator. Separately, researchers found an attacker-controlled server left exposed on the internet, reportedly containing intrusion tooling and traces of prior activity. The same roundup notes malicious code was found in developer packages and browser/IDE extensions, though specific package names, ecosystems, and a reported WhatsApp-targeting RAT are not detailed in the summary provided.

Why it matters for defenders

Internal friction among ransomware affiliates and operators doesn't reduce the threat to victims — payment is still extorted, and infighting can even accelerate double-extortion tactics as affiliates look to maximize personal payout before trust breaks down further. The exposed attacker server is a reminder that threat actors make the same operational security mistakes defenders do, which can be a source of valuable intelligence when researchers find such infrastructure first. Malicious code in developer packages and extensions is a supply-chain risk that affects any organization whose developers pull dependencies from public registries or install IDE/browser extensions, regardless of industry.

What defenders should watch for or do now

  • Review dependency and extension install logs for packages added recently from low-reputation or newly-published sources, and audit CI/CD pipelines for unexpected package installs.
  • Treat ransomware negotiations and affiliate behavior as unpredictable — do not assume a single "trusted" threat actor will honor commitments even if payment is made.
  • Hunt for anomalous outbound connections from developer workstations and build systems, which is often how malicious package payloads first phone home.
  • If messaging-app-themed malware is a concern in your environment, monitor for unusual app permission requests and unexpected companion/automation tooling tied to messaging clients.
  • Where threat intel teams encounter exposed attacker infrastructure, follow responsible disclosure and legal guidance before interacting with it directly.

Developing story

This item is drawn from a weekly news digest covering more than a dozen separate stories; the summary available here does not include full technical detail on every item (such as the specific WhatsApp RAT or the named malicious packages). Treat this as a pointer to ongoing coverage rather than a complete technical breakdown, and consult the original report for the full list of stories and any updates: ThreatsDay Bulletin — The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.