Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems

2026-05-29T14:52:18Za992a08741f8d04e04111346191d690967fb0e592437fff504a606714eaa7e4f
APTChina-linkedGlasswormGrafanaJinx-0164Kali365Linux-ptraceTanStackWebwormbotnet-takedowncredential-theftgithub-breachin-person-impersonationinfostealerlocal-info-leakmacOS-malwaremalwaremini-shai-huludnpmoauth-token-theftphishingpurelogssocial-engineeringsupply-chainvs-code-extension

What happened

Recent Infosecurity Magazine reporting highlights a surge in high-impact social-engineering and supply-chain attacks. Notable items: Silent Ransom (Luna Moth) actors have escalated to voice and in-person IT impersonation to gain direct system access; prolific supply‑chain compromises and malicious packages continue (Mini Shai‑Hulud in the AntV npm ecosystem, realistic package impersonation, AI‑generated npm infostealers that even leaked their own GitHub token); malicious VS Code/Visual Studio Marketplace extensions (Nx Console) contributed to GitHub internal repo breaches and a related Grafana

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
a992a08741f8d04e04111346191d690967fb0e592437fff504a606714eaa7e4f
Enrichment time
2026-05-29T14:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.