Isometric network nodes illustrating AI malware, ransomware, and data breaches.

Daily Cybersecurity News - February 2, 2026

eScan Updates Distribute Malware

Executive Summary

The update infrastructure for eScan antivirus was compromised by an unidentified threat actor to distribute multi-stage malware. This supply chain attack pushed malicious, signed updates to enterprise and consumer systems, disabling the antivirus product and deploying a backdoor.

Attack Overview

  • Attack Path: Attackers breached a regional eScan update server to deliver a trojanized update package. The malware, posing as a legitimate file, used a 'fake invalid digital signature' that the update client failed to reject, allowing it to establish persistence and disable future security updates.
  • Attacker: Unidentified Threat Actor.

Impact Assessment

  • Operational Impact: The malware rendered the eScan antivirus ineffective by tampering with its configuration and blocking connections to update servers. This action prevented automatic remediation and left systems vulnerable to further compromise.

Strategic Takeaway

The compromise of a trusted software supply chain turns a security tool into a malware distribution vector, bypassing conventional defenses and eroding user trust.

Relevant professional terms

Supply Chain Attack
A cyberattack that targets a trusted third-party vendor or software that has access to a target's systems, using that relationship to breach the final target.
Multi-stage Malware
A type of malicious software that executes its attack in several steps, often starting with a small initial downloader to evade detection before fetching more damaging payloads.

School Refuses Ransom, Hackers Extort Parents

Executive Summary

After a Belgian secondary school refused a ransom demand, cybercriminals pivoted to directly extorting students' parents. The attackers threatened to leak and sell stolen data unless a fee was paid for each child.

Attack Overview

  • Attack Path: Attackers gained access to the internal networks of the OLV Pulhof school shortly after the Christmas break.
  • Attacker: BitLock (Possible LockBit impersonator)

Impact Assessment

  • Data Stolen: Student and staff data, including ID cards, financial records, and confidential mental health data.
  • Operational Impact: The school's servers were encrypted using ransomware.

Strategic Takeaway

This incident highlights a tactical shift where attackers apply secondary pressure by extorting individuals whose data was compromised when the primary corporate target refuses to pay.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system or files until a sum of money is paid.
Extortion
The practice of obtaining money or other valuables through coercion or threats, such as the threat of leaking sensitive data.
Source: The Record

Publisher Hijack Infects Code Extensions

Executive Summary

Threat actors compromised a legitimate publisher's account on the Open VSX marketplace, distributing malicious versions of popular VS Code extensions. The attack deployed the GlassWorm malware, a self-propagating worm designed to steal developer credentials and cryptocurrency.

Key TTPs

  • Initial Access: Compromise of developer publishing credentials (leaked token or unauthorized access) to push malicious updates.
  • Execution: Malicious code runs automatically when the infected extension is installed and activated in the developer's IDE.
  • Defense Evasion: Malicious code is hidden from reviewers using invisible Unicode characters that do not render in code editors.

Campaign Analysis

This incident highlights a significant evolution in software supply chain attacks, weaponizing trusted developer tools for widespread distribution. The malware's worm-like, self-propagating nature and use of decentralized C2 infrastructure make it highly resilient and difficult to eradicate.

Targeting & Infrastructure

  • Target Profile: Software developers using VS Code extensions from the Open VSX and Microsoft marketplaces.
  • Infrastructure: Leverages the Solana blockchain and Google Calendar for a resilient, decentralized Command and Control (C2) system.

Relevant Terms

  • Supply Chain Attack: A cyberattack that targets less-secure elements in an organization's software or hardware supply network to compromise the final target.
  • C2 (Command and Control): The server infrastructure used by attackers to send commands to and receive data from a compromised system.
Source: SecurityWeek

Malicious AI Assistants Steal Source Code

Executive Summary

Two VS Code extensions, "ChatGPT - 中文版" and "ChatMoss," with 1.5 million combined installs, are exfiltrating source code and other sensitive data to servers in China. The extensions function as AI coding assistants while covertly stealing data from developers.

Key TTPs

  • Initial Access: Malicious code is embedded within seemingly legitimate VS Code extensions available on the official marketplace.
  • Execution: The extensions read and Base64-encode the full contents of any opened or edited file, sending it to a remote server.
  • Defense Evasion: Data is exfiltrated via hidden iframes, blending in with legitimate traffic and avoiding user suspicion by providing genuine AI assistance.

Campaign Analysis

Dubbed "MaliciousCorgi," this campaign represents a significant supply chain attack, turning trusted developer tools into spyware. The operation uses analytics SDKs to profile users, likely to identify high-value targets for further data theft.

Targeting & Infrastructure

  • Target Profile: 1.5 million developers who have installed the malicious "ChatGPT - 中文版" or "ChatMoss" VS Code extensions.
  • Infrastructure: The exfiltrated data, including source code, API keys, and credentials, is sent to servers in China.

Actionable Intelligence

  • Domains: aihao123[.]cn

Relevant Terms

  • Data Exfiltration: The unauthorized transfer of data from a computer or network.
  • Supply Chain Attack: A cyberattack that targets a trusted third-party vendor or software that has access to an organization's systems or data.

Social Lures Deploy Remote Access Tools

Executive Summary

Threat actors are leveraging social engineering campaigns that use seemingly harmless messages, like party invitations, to trick victims into installing Remote Access Trojans (RATs). This grants attackers complete control over the compromised device to steal data and credentials.

Key TTPs

  • Initial Access: Phishing emails or social media messages with enticing lures, such as fake party or event invitations.
  • Execution: Victims are tricked into opening a malicious attachment or clicking a link that downloads the RAT payload.

Campaign Analysis

This tactic preys on user curiosity and trust, proving that simple but effective social engineering remains a highly successful vector for malware delivery. Attackers often use these methods to deploy established malware like Emotet or other publicly available RATs.

Targeting & Infrastructure

  • Target Profile: Campaigns can be widespread, targeting the general public, or focused on specific industries and employees with financial access.

Relevant Terms

  • Remote Access Trojan (RAT): A type of malware that creates a backdoor on a victim's computer, allowing an attacker to gain complete administrative control remotely.
  • Social Engineering: The psychological manipulation of people into performing actions or divulging confidential information.
Source: Malwarebytes

Data Theft Reshapes Ransomware Landscape

Executive Summary

Attackers are increasingly forgoing encryption in favor of pure data exfiltration, a stealthier method that renders traditional backups ineffective for incident response. This shift focuses on extortion through the threat of public data leaks, fundamentally changing the defense priorities for organizations.

Key Findings

  • A significant majority of ransomware attacks, as high as 80-91%, now involve data exfiltration as a primary component.
  • Exfiltration-only attacks are reportedly 34% faster for threat actors to execute than those involving encryption.
  • The median attacker dwell time for ransomware incidents has decreased to as little as five days, giving security teams a much smaller window to detect and respond.
  • Attackers often abuse legitimate IT and cloud tools like RClone, PowerShell, and Azure Copy to blend in with normal network traffic and evade detection.

The Bottom Line

The pivot to exfiltration-only attacks marks a strategic evolution in extortion, rendering data recovery from backups an insufficient defense strategy. This tactic deliberately bypasses many detection tools focused on malware and encryption processes, shifting the security focus to data governance and egress traffic monitoring. Organizations must now prioritize preventing unauthorized data movement over solely defending against file encryption, as the primary threat is no longer business interruption but the severe regulatory and reputational damage of a data breach.

Relevant Terms

  • Data Exfiltration: The unauthorized transfer or theft of data from a computer or network. In this context, it's used as the primary means of extortion.
  • Dwell Time: The period of time a threat actor remains undetected within a network, from initial compromise to discovery.

AI Agents Elevate Pentesting Automation

Executive Summary

A new generation of open-source AI-powered tools can now automate complex penetration testing tasks, moving beyond simple scanning to mimic the reconnaissance and exploitation techniques of human security testers. These tools aim to augment security professionals by handling repetitive tasks and identifying vulnerabilities more efficiently.

Key Features

  • AI-Driven Reconnaissance: Tools like BugTrace-AI analyze URLs, JavaScript, and headers to identify potential vulnerabilities such as SQLi and XSS without active exploitation.
  • Autonomous Exploitation: The Shannon tool focuses on autonomous exploitation of common vulnerabilities, providing proof-of-concept evidence for confirmed bugs.
  • Modular Frameworks: The Cybersecurity AI (CAI) framework uses a modular, agent-based design that integrates with over 300 AI models and various security tools for both offensive and defensive tasks.

Use Case (The "So What?")

For Red Teams, these tools automate the discovery and exploitation phases, allowing operators to focus on more complex, logic-based flaws. For Blue Teams, they represent a new class of automated threat that requires defenses capable of detecting sophisticated, multi-stage attacks that don't rely on static signatures.

Availability

The tools mentioned, including BugTrace-AI, Shannon, and CAI, are available as open-source projects. CAI also offers commercial licenses for enterprise use.

Relevant Terms

  • Pentesting: Short for penetration testing, it is a simulated cyberattack against a computer system to check for exploitable vulnerabilities.
  • XSS (Cross-Site Scripting): A type of security vulnerability where an attacker injects malicious scripts into content from otherwise trusted websites.