GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

IPS Signature Sep 21, 2026

GajIPS - IPS Signature Update — GS TROJAN: TraderTraitor / Jade Sleet FLATROOF & ROOFDECK macOS backdoor delivery and C2

Severity: HIGH · Priority: P2 — targeted nation-state supply-chain intrusion, escalate on hit

These rules detect network activity from a supply-chain campaign by TraderTraitor — also known as Jade Sleet, PUKCHONG, Slow Pisces, and UNC4899 — a North Korean state-sponsored group and financially-motivated subgroup of Lazarus, responsible for the April 2026 KelpDAO/LayerZero theft ($292 million) and the 2025 Bybit compromise ($1.5 billion). The campaign is directly relevant to Indian organisations: Researchers confirmed the most recently identified victim is an Indian IT services provider with no cryptocurrency ties, showing the group's targeting has expanded beyond the crypto sector. The attack uses a weaponised Terraform coding project as its lure — a fake job-interview assignment whose lockfile secretly points Terraform to attacker-controlled registries impersonating HashiCorp domains. Running a standard terraform init command causes Terraform to download and execute the attacker's code, deploying two Rust-based macOS backdoors: FLATROOF for persistence and credential harvesting, and ROOFDECK for ongoing remote control and data exfiltration. ROOFDECK discovers its command servers through posts on public Nostr relay servers, making infrastructure rotation easy for the attackers.

IPS Signature Sep 21, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: indexed-btree npm campaign, malicious package fetch and C2/exfiltration

Severity: HIGH · Priority: P2 — active supply-chain compromise; alert on hit and treat any match as a compromised host

This group detects hosts on your network affected by the indexed-btree npm campaign, a set of eleven typosquatted packages impersonating the widely-used sorted-btree library — indexed-btree, ordered-btree, ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map and sliding-score-window — all since removed from npm after accumulating downloads in the millions. The packages carry no install hook. The loader is wired into BTree.prototype.set() and executes the first time an application stores a particular key, which means installation itself looks clean and a successful npm install is no longer evidence that a dependency is safe. Once triggered, the loader retrieves its second stage from an Ethereum Sepolia smart contract over public Infura and Alchemy RPC endpoints — using a public blockchain as rotatable, takedown-resistant C2 — harvests host telemetry, and sends it to an attacker-controlled Telegram bot and Slack workspace. It then deletes its own files and rewrites the calling module to splice out the trigger, so the installed package appears benign to anyone inspecting it afterwards. The attackers also stood up a fake GitHub repository with fabricated commit history and a curated developer account to make the packages look established. Recommended action: alert on all signatures, and block the malicious package names at your npm proxy, internal mirror and artifact repository in addition to the network layer, since a removed package may still be served from a local cache long after npm has pulled it. 

URL Filter Sep 20, 2026

GajURL Domain note — Google Pay card-harvesting phishing: gpay-deactivation.support

Severity: HIGH · Priority: P2 — active payment-card phishing, block and alert on hit

This domain hosts a phishing page impersonating Google Pay to steal payment-card details. It uses a deceptive, alarm-inducing web address suggesting the victim's account is being deactivated, and serves a form that asks for full card data — card number, expiry, and security code (CVC) — under the pretext of confirming the card to stop a supposed "unauthorized registration" or deactivation. Critically, the page is wired to send whatever the victim enters directly to an attacker-controlled chat bot (Telegram or Discord), so any card details submitted are delivered to the criminals immediately. The genuine service is Google Pay at Google's own domains; this address is an impersonation designed for financial fraud.

Recommended action: block the domain gpay-deactivation.support across web and DNS filtering, and alert on any lookup or connection to it from your network. Because this page steals payment-card data rather than just passwords, the response differs from an ordinary credential-phishing case: if any user has submitted card details, treat those cards as compromised and instruct the user to contact their bank or card issuer immediately to freeze or replace the card and watch for fraudulent transactions — resetting a password is not sufficient, since it is the card that has been stolen. Report the fraud through the card issuer and, where applicable, to the relevant financial-fraud authority.

Antivirus Sep 20, 2026

GajAV - Malware Signature  — WaterPlum (Contagious Interview) malware components

These signatures detect malware used by WaterPlum — also known as the "Contagious Interview" campaign — a North Korean state-linked operation that is the subject of a joint law-enforcement advisory from Japanese, US, Australian, and German authorities (September 2026). The group targets software developers and IT professionals with fake job interviews: posing as recruiters from AI, cryptocurrency, and NFT companies, they ask candidates to run a coding assignment, clone a repository, or "fix" a video-call issue, which installs malware. Between December 2025 and July 2026 the campaign compromised more than 30,000 devices across 100+ countries and stole roughly $10.7 million in cryptocurrency. The malware harvests browser credentials, clipboard contents, keystrokes, screenshots, cryptocurrency private keys and seed phrases, identity documents, and source code, and installs backdoors for persistent remote access. These signatures identify samples of the campaign's malware components — including the BeaverTail loader/stealer and the OtterCookie remote-access stealer, samples delivered through malicious Visual Studio Code projects, and further WaterPlum samples of undetermined family — by exact fingerprint.

If GajAV flags one of these files, treat it as a probable developer or workstation compromise: isolate the machine, and because these tools steal credentials, session cookies, and wallet keys and install remote backdoors, treat all credentials and crypto assets reachable from that machine as exposed — rotate them from a known-clean device, revoke sessions, and prioritise cryptocurrency wallets and any corporate accounts. Because the entry point is running untrusted "interview" code, check whether the user recently ran a coding assignment, cloned a repository, or opened a Visual Studio Code project from a recruiter; audit package dependencies (npm and others) for malicious packages; and because a backdoor may already be established, quarantining the initial file is not sufficient — assess the host for remote-access persistence and rebuild if confirmed.

URL Filter Sep 19, 2026

GajURL Domain note — Google-impersonation phishing: meet-google.cam

Severity: HIGH · Priority: P2 — active credential-phishing domain, block and alert on hit

This domain hosts a phishing page impersonating Google (Google Meet) to steal login credentials. It uses a deceptive name — placing the Google brand on a lookalike web address that is not Google's — and serves a fake sign-in page with a password field designed to capture whatever a victim types. A strong giveaway is the page title, which renders the brand as "Gooqle" (with the letter g replaced by q) — a deliberate near-miss of the real name used to look convincing at a glance while evading automated brand-detection. The genuine service lives only at google.com (Google Meet at meet.google.com); this address is an impersonation.

Recommended action: block the domain meet-google.cam across web and DNS filtering, and alert on any lookup or connection to it from your network. If any user has already visited it and entered credentials, treat those Google credentials as compromised — have the user reset their Google password and revoke active sessions from a known-clean device, and enable or re-verify multi-factor authentication; also check whether the same password is reused elsewhere, since attackers try harvested credentials against other services.

Two points on handling. First, block the domain name, not the addresses it currently resolves to: this site sits behind a shared content-delivery network (Cloudflare), so its IP addresses belong to that provider and are used by very large numbers of legitimate sites — blocking them would cause widespread false positives, while the domain itself is the safe, specific indicator. Second, phishing sites of this kind are short-lived and often appear in clusters, so treat this as one instance of a pattern: watch for other lookalike Google domains on low-trust top-level domains (such as .cam), and prioritise brand-impersonation and newly-registered-domain filtering over chasing individual addresses.

IPS Signature Sep 19, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Orkes Conductor unauthenticated workflow RCE, CVE-2026-58138

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

These rules raise an alert when an attacker attempts to exploit a critical flaw in Orkes Conductor, an open-source workflow-orchestration platform used to run automated business and data pipelines. Conductor lets a workflow include small script expressions, and in affected versions it runs those scripts with unrestricted access to the underlying system — so an attacker who submits a workflow containing a malicious script can break out and run operating-system commands on the server. Because the community workflow interface has no authentication by default, no login is required: simply submitting the crafted workflow to an exposed Conductor server is enough. The flaw can be exploited through either of the platform's two supported scripting languages, and these rules cover both, watching the workflow registration and start interfaces for the specific system-command techniques used in each.

A hit indicates an attempt to exploit this flaw against one of your servers. The flaw is rated critical (9.8), affects Conductor versions 3.21.21 up to 3.30.2, and is under active exploitation, with public exploit code available and security vendors reporting large numbers of blocked attempts. Treat an alert as a serious exploitation attempt: confirm whether the targeted host runs Orkes Conductor and whether it is on version 3.30.2 or later; if it is unpatched and its workflow interface is reachable, assume the attempt may have succeeded and escalate to incident response. Because a successful attack runs commands with the Conductor process's privileges — and Conductor often holds credentials for the systems it orchestrates — treat any secrets and service credentials reachable from that host as potentially exposed and rotate them, and hunt for unexpected commands, processes, or outbound connections from the server. Upgrading to Conductor 3.30.2 or later, and not exposing the workflow interface to untrusted networks, are the definitive fixes.

IPS Signature Sep 19, 2026

GajIPS - IPS Signature Update — GS TROJAN: Rapuncel infostealer campaign domain lookups

Severity: HIGH · Priority: P2 — probable infostealer infection, investigate on hit

These rules detect a device on your network looking up domains tied to the Rapuncel information-stealer campaign. Rapuncel is a Windows infostealer spread through fake software-download pages: attackers create bogus code-repository pages impersonating LastPass Authenticator and around 40 other well-known applications, and use search-engine manipulation so these fake pages rank highly when users search for the real software. Victims download an oversized installer (deliberately inflated to evade scanning) that quietly installs the stealer alongside a specially-signed driver capable of disabling 145 different antivirus and endpoint-security products. With defenses down, Rapuncel harvests saved passwords from many browsers, cryptocurrency-wallet data, messaging-app sessions, stored Windows credentials, sensitive documents, and screenshots, and uploads them to attacker infrastructure.

A hit suggests a device is contacting infrastructure tied to this campaign — either being redirected toward the malware or, if already infected, communicating with it. Treat it as a probable compromise: identify the device and user, and because this stealer specifically disables security tools and steals stored credentials, wallets, and session tokens, treat the machine as a serious, kernel-level credential-theft incident rather than a routine cleanup. From a known-clean device, reset the user's passwords and revoke sessions — prioritising password managers, cryptocurrency wallets, and any cloud accounts accessible from browser-stored credentials — and rebuild the machine, since a driver operating at the system's most privileged level cannot be reliably removed by ordinary means. Check whether the user recently downloaded software from a code-repository or search-result link rather than the vendor's official site.

IPS Signature Sep 19, 2026

GajIPS - IPS Signature Update — WordPress Core "Click2Shell" theme-install injection to RCE chain

Severity: HIGH · Priority: P2 — exploitation attempt against a serious flaw, escalate on hit

These rules detect exploitation of Click2Shell, a WordPress attack chain disclosed by the research team at pwn.ai in September 2026 and fixed in WordPress 7.1.1. The chain lets an attacker take over a WordPress site when a logged-in administrator merely visits an attacker-controlled link — no attacker account and no further clicks required. It works in two stages: a flaw in WordPress Core's theme-installer page lets a crafted link silently force the admin's site to download and install a chosen theme from the official WordPress.org catalogue; then a separate flaw in that theme  — an installer function left unprotected by any permission check — is reached while the theme is merely previewed, and made to fetch and run attacker-supplied code. The result is code execution on the web server.

A hit indicates an attempt to exploit this chain against one of your WordPress servers. The Core flaw affects all WordPress versions before 7.1.1. Treat an alert as a serious exploitation attempt: confirm whether the targeted site is on WordPress 7.1.1 or later and whether the vulnerable theme (or another affected theme) is present; if the site is unpatched, assume the attempt may have succeeded and escalate to incident response. Because success yields code execution under the web-server account, hunt for newly written plugin or theme files, unexpected admin users, and web shells, and treat database credentials and any secrets reachable by the site as potentially exposed — rotate them. Updating WordPress Core to 7.1.1 or later is the definitive fix; removing or updating affected themes closes the second stage.

IPS Signature Sep 19, 2026

GajIPS - IPS Signature Update — Transparent Tribe (APT36) "Operation RapidRust" staging and exfiltration indicators

Severity: HIGH · Priority: P2 — targeted nation-state activity, escalate on hit

These rules detect network indicators from Operation RapidRust, a campaign by APT36 (also known as Transparent Tribe), a Pakistan-aligned state-sponsored espionage group, documented in September 2026. The campaign targets government and defense organisations in India and Afghanistan, continuing APT36's long-standing focus on Indian government and defense entities — so for Indian public-sector, defense, and supply-chain organisations this is a directly relevant threat. The rules watch for name lookups of the fake "news outlet" domains the group registered to stage its malicious scripts and payloads, and for the distinctive signature of its file-stealing tools uploading stolen data.

A hit indicates a machine on your network is contacting infrastructure tied to this espionage campaign, which strongly suggests targeting or compromise. Treat it as a serious, probable intrusion warranting immediate escalation to incident response and a broader compromise assessment — not single-host cleanup. Because this actor also spreads via removable media to reach isolated systems, check for related host-side traces (a scheduled task disguised as a software updater, and archive or shortcut files disguised as PDFs on removable drives) and inspect other systems the affected machine has interacted with.

IPS Signature Sep 18, 2026

GajIPS - IPS Signature Update — GS TROJAN: WeaselBiscuit npm information-stealer command-and-control

Severity: HIGH · Priority: P2 — probable developer/build-system compromise, investigate on hit

These rules detect network activity from WeaselBiscuit, a JavaScript information-stealer documented by OpenSourceMalware in September 2026 and distributed through malicious npm packages. It is a lightweight stealer that reuses functionality from two known malware families (BeaverTail and OtterCookie); researchers note overlaps with tooling associated with North Korea's "Contagious Interview" campaign but treat that link as a hypothesis, not a confirmed attribution. WeaselBiscuit installs when a developer imports a malicious npm package, pulls its real payload from a remote hosting service, and runs it in memory without writing it to disk. It profiles the machine and harvests browser and Chrome-extension data, including cryptocurrency-wallet extensions, and takes operator commands from its control server. These rules watch for its data-upload and input-capture traffic and for connections to its known control server.

A hit indicates a machine on your network — likely a developer workstation or build system — is communicating with WeaselBiscuit's infrastructure, which strongly suggests infection. Treat it as a probable compromise: identify the machine and user, and because this stealer targets browser credentials, crypto-wallet extensions, and system information, treat those as exposed — rotate the credentials, tokens, and wallet material the machine could reach, from a known-clean device. Identify and remove the malicious npm package, audit the project's dependencies for other malicious packages, and — because the payload runs only in memory rather than on disk — do not rely on finding a malicious file to confirm or rule out infection; the network activity these rules detect may be the clearest evidence.