New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
2026-04-08T19:24:08Z•6935d7987b45276c2ea8c3742739582dbbc28197669c5cf4b21f65543468847a
APT28BYOVDCOM hijackingCVEComfyUIDDoSDockerFlowiseFortinetGPUBreachPLC/OT attacksPyPIRCESOCKS proxyactive exploitationbotnetcloud misconfigurationcredential sprayingespionagemalwarenpmransomwaresteganographysupply chain
What happened
A broad set of active threats and high-severity vulnerabilities were reported: a new Chaos malware variant now targets misconfigured cloud deployments and adds a SOCKS proxy; Masjesu botnet is offered as DDoS‑for‑hire targeting diverse IoT architectures; APT28 is deploying a novel PRISMEX malware leveraging steganography, COM hijacking and cloud abuse; multiple supply‑chain and repo poisoning campaigns (npm/PyPI/Go/Rust) and exposed AI platforms (Flowise, ComfyUI) are being actively exploited for RCE and cryptomining; Fortinet and Docker disclosed serious authorization/privilege‑escalation/EMS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6935d7987b45276c2ea8c3742739582dbbc28197669c5cf4b21f65543468847a
- Enrichment time
- 2026-04-08T19:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.