INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AI Agent Phishing Worm Code Leaked

| 2026-06-11 13:20 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is increasingly dominated by sophisticated and targeted attacks, with the Five Eyes intelligence alliance countries warning of China's aggressive use of job platforms to target individuals for sensitive information. A previously unknown group known as SiribClone has been targeting Russian military personnel using bait applications for "safe photo exchange" to distribute malicious files. This is just one example of how Russia-focused phishing waves are being conducted, with the targeted groups including Russia maritime universities, energy facilities, diplomatic missions and government agencies. The threat actors behind these campaigns include an unidentified group that has also been targeting Russian military personnel since at least July 2024, as well as Cloud Atlas, which is using ZIP archives containing malicious shortcuts to launch PowerShell scripts. This malware payload can drop a credential grabber, highlighting the potential for sophisticated attacks in the future.
Technical Mitigations AI-generated
• Use built-in OS settings to weaken endpoint tools. • Be cautious of online offers for consulting work that may be a scam, and treat them with extreme caution.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview PowerShowerPowerShowerShai-HuludShai-HuludVBShowerVBShowerRansomHubRansomHubCobalt StrikeCobalt StrikeAgent TeslaAgent Tesla CVE-2026-49494CVE-2026-49494
Target & Sectors
ASEAN ASEAN NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE CIS CIS defensedefense governmentgovernment maritimemaritime energyenergy
Incident Timeline
‎late 2020
Russian-speaking malware developer and vendor "o1oo1" leaked worm code.
target_region Russian Federation
‎May 2021
Threat actors used a contractor's login credentials to access the target company's network and execute malicious PowerShell scripts.
financial $862 $ damage case
‎November 2023
Threat actors used a Five Eyes intelligence alliance countries' AI agent to phish Claude code.
organisation Reuters
organisation the Chinese Embassy
‎at least July 2024
Russian maritime universities and energy facilities were targeted through phishing campaigns by an unidentified group since at least July 2024.
target_region Russian Federation
tactic Phishing
industry Maritime
industry Energy
industry Government
‎July 2024
Threat actors used RDP, SSH, and RevSocks to lateral move into systems via PAExec or PsExec as part of the PowerAdmin framework.
organisation Google Sheets
organisation Chrome, Edge
organisation RevSocks
organisation PAExec
organisation PsExec
organisation PowerAdmin
organisation MLTBackdoor
organisation MTLBackdoor
organisation Zscaler ThreatLabz
organisation Beacon Object Files
‎April 2025
CrowdStrike identified Famous Chollima as the North Korean threat actor responsible for 47% of state-sponsored attacks on tech sectors between April 2025 and March 2026.
source_region DPRK
attribution CrowdStrike
threat_actor Contagious Interview
general_metric 47 %
‎2025/06/11
Threat actors exploited vulnerabilities in Claude code to infect 11.1B devices, while also using AI agents to steal and distribute stolen credentials from over 3.3 billion compromised accounts.
infrastructure 11.1 devices
data_breach 3.3 stolen credentials
‎June 2025
Threat actors used Iran's BLUEWIPE malware to infect a target, where they also exploited an unknown vulnerability in the BLUERABBIT AI agent.
source_region Iran, Islamic Republic of
organisation BLUERABBIT
organisation BLUEWIPE
organisation SEWERGOO
‎early 2025
Threat actors used a worm code to compromise computer systems.
‎September 2025
Threat actors used ClickFix to distribute the MaaS RAT, which targets credentials via Hijack Loader campaigns.
organisation ClickFix
organisation Hidden Virtual Network Computing
‎November 2025
Threat actors used NinjaOne Remote Monitoring and Management (RMM) to target Brazilian organizations, followed by the abuse of Claude Code Action for phishing campaigns.
organisation RMM
organisation SEFAZ
organisation Cato Networks
organisation NinjaOne
organisation Landscape
infrastructure Android
organisation APK
organisation Pinchy
organisation the U.S. Justice Department
infrastructure Windows
organisation Binary Defense
organisation DLL
organisation Protected Process Light
organisation AV
organisation Windows Access Control Lists
infrastructure 4.4
organisation OOB
organisation TikTok
organisation Business Email Compromise
organisation Google Chrome
infrastructure Linux
organisation ELF
organisation DNS
organisation HTTPS (DoH
organisation SAN
organisation TLS
organisation GCP OAuth2
infrastructure 7.5
organisation PoC
organisation Inspect.sys
organisation CVSS
organisation NFC
organisation ISO-DEP
organisation WebSocket
organisation Apple
organisation EDR
organisation EDRChoker
organisation Endpoint Detection and Response
organisation Quality of Service
organisation QoS
organisation STX
organisation Cyderes
organisation Leda Elacoate
organisation Tesla
organisation SMTP
organisation KYC
organisation Claude & DeepSeek
organisation DATA
organisation Meta
organisation Meta IP
organisation the Sectricity Security Team
organisation GCP
organisation TCP
victims 100 reported users
‎March 2026
Threat actors used CrowdStrike's AI agent to phish current or former U.S. government and military employees, with Famous Chollima being behind the North Korean threat actor known as Contagious Interview that accounted for 47% of state-sponsored hands-on-keyboard operations against tech companies between April 2025 and March 2026.
source_region DPRK
attribution CrowdStrike
threat_actor Contagious Interview
general_metric 47 %
infrastructure 13 domains
‎the beginning of April 2026
Threat actors used a worm code to infect over 33,000 unique users across multiple countries.
target_region India
target_region Brazil
target_region Argentina
target_region Mexico
target_region Spain
victims 33,000 unique users
‎April 29, 2026
The threat actors used a Golang backdoor called BLUERABBIT to route malware through RabbitMQ for tasking, Redis for state management and MinIO for S3-compatible data exfiltration.
infrastructure 2.1.128
organisation Nimbus Manticore
organisation LinkedIn
financial $200 $ job
organisation Golang
organisation S3
organisation Nextron Systems
organisation Ebix Recruitment
‎May 5
The Claude Code version 2.1.128 was released on May 5 after being patched following a responsible disclosure incident on April 29, 2026.
infrastructure 2.1.128
‎May 2026
Threat actors used RustyRocket to target 33,000 users.
victims 33,000 unique users
organisation SvitStealer
organisation World Leaks
organisation VIPERTUNNEL
organisation RustyRocket
organisation WooCommerce
organisation CloudSEK
organisation PE
organisation Traffic Distribution System
organisation TDS
organisation AnimateClipper
organisation SessionGate
‎2026/06/04
Threat actors used a worm code to compromise 304 components of various devices.
general_metric 304 components
‎June 8, 2026
The attackers used Microsoft Exchange to send spoofing emails masquerading as any user.
infrastructure Windows
infrastructure Macos
organisation Iru
organisation SStar
organisation SiribGrabber
organisation PyPI
organisation RubyGems
organisation GitHub Actions
organisation SSH
organisation Exchange
organisation Microsoft Exchange
infrastructure Android
organisation SafeDep
organisation Google
organisation Search
organisation Search Live
organisation the Search Services History
organisation POST
organisation GitHub
organisation Telegram
infrastructure 50,000 downloads
‎Jun 11, 2026
Threat actors used a public repository to distribute a supply chain attack kit, including a RAT that clones browsers.
organisation Hacking News / Cybersecurity News
financial $5,000 $ RAT
‎2016 to 2023
Murray sold lists containing information on Jamaican scammers to lottery fraud perpetrators in the United States.
target_region Jamaica
target_region United States
‎2026/06/11
Threat actors used AI-generated TikTok videos to direct users to sketchy sites that deployed Vidar Stealer malware.
organisation TikTok
Tactical Metrics
Metrics
victims
33,000
Unique Users
Metrics
infrastructure
13
Internet Domains
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
11,100,000
Devices
Metrics
data_breach
3,300,000,000
Stolen Credentials
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎4.4
Software Version
Metrics
infrastructure
‎7.5
Software Version
Metrics
infrastructure
‎2.1.128
Software Version
Metrics
financial
862,000
$ Damage Case
Metrics
financial
200,000
$ Job
Metrics
financial
5,000
$ Rat
Metrics
infrastructure
50,000
Downloads
Metrics
victims
100,000,000
Reported Users