Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems
2026-05-29T14:52:18Z•a992a08741f8d04e04111346191d690967fb0e592437fff504a606714eaa7e4f
APTChina-linkedGlasswormGrafanaJinx-0164Kali365Linux-ptraceTanStackWebwormbotnet-takedowncredential-theftgithub-breachin-person-impersonationinfostealerlocal-info-leakmacOS-malwaremalwaremini-shai-huludnpmoauth-token-theftphishingpurelogssocial-engineeringsupply-chainvs-code-extension
What happened
Recent Infosecurity Magazine reporting highlights a surge in high-impact social-engineering and supply-chain attacks. Notable items: Silent Ransom (Luna Moth) actors have escalated to voice and in-person IT impersonation to gain direct system access; prolific supply‑chain compromises and malicious packages continue (Mini Shai‑Hulud in the AntV npm ecosystem, realistic package impersonation, AI‑generated npm infostealers that even leaked their own GitHub token); malicious VS Code/Visual Studio Marketplace extensions (Nx Console) contributed to GitHub internal repo breaches and a related Grafana
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- a992a08741f8d04e04111346191d690967fb0e592437fff504a606714eaa7e4f
- Enrichment time
- 2026-05-29T14:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.