New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

2026-04-09T01:24:15Z6a8025e7c894dfc45a8b930f8a96b1ada2c33e8308a0f9b8e33ba3a381bfe796
APT28BYOVDChaosComfyUIDDoSDPRKEDR-bypassGPUBreachMasjesuOT-targetingPLCsPRISMEXPyPISOCKS-proxyactive-exploitationbotnetcloud-misconfigurationcryptominingmalwarenpmpackage-poisoningprivilege-escalationsupply-chainvulnerability

What happened

A broad set of high-impact threats and active vulnerabilities were reported: an evolved Chaos malware variant now targets misconfigured cloud deployments (adds SOCKS proxy), new botnets (Masjesu) and cryptomining/proxy campaigns are exploiting exposed IoT, ComfyUI and cloud instances, and APT28/PRISMEX and DPRK-linked actors are conducting espionage and supply-chain attacks. Multiple high-severity vulnerabilities are being actively exploited or widely exposed—most notably Flowise CVE-2025-59528 (CVSS 10.0, active RCE across ~12k instances), Fortinet CVE-2026-35616 (critical, exploited in the-w

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6a8025e7c894dfc45a8b930f8a96b1ada2c33e8308a0f9b8e33ba3a381bfe796
Enrichment time
2026-04-09T01:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy · Baitaphish