// 2 ZERO-DAY · 3 CVE · 1 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
The October 8, 2026 ThreatsDay report documents a saturated ransomware-as-a-service market driving affiliate betrayal and an unprecedented offensive against developer platforms — VS Code, npm, and RubyGems — signaling a collapse of trust across both criminal and legitimate software ecosystems.

The October 8, 2026 ThreatsDay report maps a landscape where the ransomware market is so saturated it generates fratricide among affiliates, while everyday development platforms — VS Code, npm, RubyGems — face a structured offensive without recent precedent. The convergence is clear: the decomposition of trust spares neither the criminal nor the legitimate side of the software ecosystem.

Key Takeaways
  • A ransomware affiliate known as Azazel betrayed the Gentlemen group, stealing its victims across six countries and launching an independent leak site dubbed "Leakned" to pocket extortion payments directly.
  • Nine npm packages published in 33 minutes from the "dirtyblanket" account contain a self-spreading Linux worm with a systemd-fontd backdoor, while 42 RubyGems gems target crypto developers with reverse shells.
  • Two malicious VS Code themes (Coca-Cola Christmas, Aurora Borealis) linked to the GlassWorm actor use Solana transactions as a dead-drop resolver to evade takedown.
  • CISA added Citrix NetScaler vulnerabilities CVE-2026-88771 (CVSS 9.8) and CVE-2026-88772 (CVSS 8.1) to the KEV Catalog for active exploitation, with 50,277 exposed instances detected by Unit 42.

Azazel's Betrayal: RaaS Turns Individualist

The ransomware-as-a-service model has operated for years on a division of labor: operators supply the ransomware, affiliates supply access and handle extortion, profits are split. The ThreatsDay report documents the collapse of this pact in the case of the Gentlemen group. An affiliate dubbed Azazel "built and operated its own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program." The quote, attributed to CloudSEK in the primary source, describes a double betrayal: against the RaaS operator and simultaneously against victims, whose data is monetized twice.

The mechanism matters because it signals a perverse criminal maturity. When the market is crowded, the reputational constraint between operators and affiliates loosens: the affiliate has incentive to maximize individual profit rather than preserve the collective brand. The dossier does not specify the total volume of profits siphoned via Leakned, nor Azazel's real identity. The source reports victims in six countries without listing them.

VS Code, npm, RubyGems: Supply Chain as Battleground

The week saw an unusual concentration of campaigns against software distribution platforms. Two VS Code themes — "Coca-Cola Christmas" and "Aurora Borealis" — were linked to the GlassWorm actor. According to Socket researcher Kirill Boychenko, "that build contains the same Solana address, the same AES key, and the same execution pattern documented previously in GlassWorm activity." The blockchain dead-drop technique lets malware retrieve payloads without contacting traditional C2 servers, rendering infrastructure takedown ineffective.

On the npm front, package "@subql/common" version 5.8.3 hosted a hidden payload for credential harvesting and remote shell. StepSecurity documented that "the code targets developer workstations and CI environments, including GitHub Actions runners and accessible cloud services." Contamination begins during installation and upon package import.

In parallel, the RubyGems account "reqthrottle_3474" published 42 malicious gems. SafeDep detected that eleven gems open reverse shells to 45.138.12.177 on port 8089 or 8090, while thirty-one download wgkit.tar.gz. The gems do not activate in CI or sandbox environments; on developer machines they wait 20–40 minutes before executing.

Nine npm packages from the "dirtyblanket" account round out the picture with a self-spreading Linux worm that installs the "systemd-fontd" backdoor as a fake systemd service, published within a 33-minute window. The dossier does not report the number of actual installations.

Legitimate Tools, Malicious Ends: Power BI, Signed Drivers, and Generative AI

Abuse of trusted infrastructure characterizes the other documented operations. Huntress detected a phishing campaign that funnels victims to legitimate Power BI domains with a fake reference document; "after a few seconds, a script programmatically triggers a hidden download link." The payload is a rogue ScreenConnect installer.

The VulcanRAT207 RAT, distributed via WhatsApp through a "Statement.exe" lure, employs the BYOVD (Bring Your Own Vulnerable Driver) technique with the signed driver GoFly64.sys. Morphisec documented that "after unpacking, the loader examines the host, attempts elevation, and injects a downloader into the LocalSystem Task Scheduler process." The signed driver terminates selected Baidu security processes.

Huntress also documented vulnerabilities in municipal recreation management software exploited for web shells and payment data theft. The analysis notes user-agents consistent with Chinese origin and, in a cautious note, "suspects the use of AI-generated scripts throughout the kill chain, from the large number of failed initial access attempts to the final upload of PowerShell scripts with extensive comments in the provided instructions." This is a probability assessment, not forensic confirmation.

Why It Matters

The dossier does not document specific remediation measures for most of the campaigns described. The source does not specify whether patches are available for all eight Citrix NetScaler vulnerabilities or only the two added to the KEV Catalog. The total number of actual victims from the compromised npm and RubyGems packages does not emerge. Azazel's real identity remains undisclosed, as does the full extent of the Qilin group and the precise role of the arrested suspect.

What emerges clearly is the direction: trust — in cybercrime as in software development — has become a cost. Affiliates betray operators, package marketplaces host sophisticated malware with evasion techniques designed to resist discovery, legitimate platforms become social engineering vectors. RaaS betrayal is not an absolute novelty, but the frequency and documented organization in the report signal an acceleration.

"Healthcare data – including medical histories, diagnostic images, lab results, and prescription records – remains valuable for a lifetime, making the sector especially vulnerable to harvest-now, decrypt-later (HNDL) attacks" Forescout, cited in the ThreatsDay report

Medical Devices, Extradition, and Data Collection: Other Fronts

The report touches on themes beyond the purely technical that complete the picture. Forescout analyzed approximately 2.5 million devices across more than fifty healthcare organizations: only 6% of IoMT devices and 16% of medical OT devices use SSH implementations capable of supporting transition to post-quantum cryptography. 31% of exposed systems support TLS 1.3, the only version with standardized PQC support.

A 28-year-old Russian citizen, member of the Qilin ransomware group, was arrested in Osaka in May 2026 and extradited to Germany on October 2, 2026. He is accused of an attack on a German logistics company in September 2024 with extortion of over $160,000 in cryptocurrency.

Meta Muse AI builds hourly dossiers on users and people mentioned in chats, including non-users. Meta, questioned by TIME, responded that "Muse remembers what matters most to you, including information about others you choose to share, so it can be a helpful personal assistant." The TIME report describes behavior documented in internal instructions, not a confirmed legal violation.

CERT-AGID and Truffle Security found 543,699 still-valid GitHub credentials in the "The Stack v3" AI training dataset (15.9 TB, approximately 224 million repositories). The average age of working credentials is 784 days. The credentials were exposed in public repositories, not stolen from the dataset.

Citrix in KEV and Warlock Attribution

CISA confirmed "reports and partner threat intelligence attesting that threat actors are actively exploiting these vulnerabilities globally." Unit 42 identified 50,277 potentially vulnerable exposed NetScaler instances. The CVSS v4.0 score for both CVEs is 9.5 according to Unit 42, while official NVD sources cite 9.8 (CVE-2026-88771) and 8.1 (CVE-2026-88772).

Symantec attributed the Warlock ransomware to the Chinese group Longlegs (Storm-2603), with at least four organizations attacked in two months, including a water utility and a telecom provider. In one intrusion, Longlegs disabled security software on over 40 hosts and deployed Warlock via SYSVOL share on 33 hosts.

Reading: The End of Trust as a Business Model

Azazel's betrayal and the npm contamination are not isolated incidents. They are manifestations of the same phenomenon: when an ecosystem scales too fast, the reputation mechanisms that govern it give way. In cybercrime, RaaS introduced an organizational innovation: specialization and division of labor. Its current crisis shows that, without enforcement, informal contracts among criminals decompose like those among any other merchants.

In software development, the distributed open source model has functioned on cross-cutting trust: I download a package, assuming the community vetted it. The GlassWorm campaign and the "dirtyblanket" packages demonstrate that this trust has become a systemic opportunity for actors capable of simulating technical legitimacy — digital signatures, catchy names, activation delays that evade sandboxes. The difference is that while the Gentlemen RaaS loses an affiliate, the software supply chain loses structural credibility. The first is a crisis of a criminal business model; the second is a crisis of shared digital infrastructure.

The ThreatsDay report offers no solutions. It does, however, provide a precise map of where pressure is mounting: in package marketplaces, in abused signed drivers, in impersonated Power BI domains, in AI training datasets that retain forgotten credentials. For those managing infrastructure, the takeaway is that verification can no longer be delegated entirely to platform reputation.

Frequently Asked Questions

Is Azazel's betrayal an unprecedented event in ransomware?
No. The brief describes it as an emerging pattern, not an absolute novelty. CloudSEK's documentation confirms its organization and scale, not historical uniqueness.
Why do GitHub credentials remain valid after years of exposure?
The 784-day average age indicates credentials are not rotated or revoked automatically, not that the AI dataset actively compromised them. Responsibility for revocation remains with repository owners.
Does the malware in npm packages activate immediately upon installation?
The @subql/common package activates on import; RubyGems gems wait 20–40 minutes; the "dirtyblanket" worm installs as a systemd service. Timing and mechanisms vary by campaign.

Information is based on the cited advisory and current as of publication.

Sources

Information is based on the cited source and current as of publication.

Fonti


Sources and references
  1. thehackernews.com
  2. hendryadrian.com
  3. cisa.gov
  4. cisecurity.org
  5. cert-agid.gov.it
  6. security.com
  7. unit42.paloaltonetworks.com