GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

Antivirus Sep 18, 2026

GajAV - Malware Signature Update — PhantomRaven.JS.Stealer

These signatures detect the JavaScript payloads of PhantomRaven, an information-stealer documented by CrowdStrike in September 2026 and notable for being largely written by a large language model. It was distributed through the npm software registry by a financially-motivated actor (a self-described bug bounty hunter) who published packages with names imitating legitimate developer tools. The published packages look harmless — often just a trivial script — but they declare a hidden dependency fetched over a web link from the attacker's own server; when a developer installs the package, that server returns the actual stealer, which harvests system information, credentials, and software-development secrets such as CI/CD and repository tokens. These signatures identify the fetched stealer payloads by exact fingerprint.

If GajAV flags one of these files, treat it as a probable developer or build-system compromise: identify the affected machine (often a developer workstation or a continuous-integration runner), and because this stealer targets credentials and CI/CD and repository tokens, treat those as exposed — rotate npm, git, cloud, and CI secrets that the machine could reach, and review the associated repositories and pipelines for unauthorized use. Identify and remove the malicious npm package and its remote dependency, and audit the project's dependencies for other typosquatted packages.

IPS Signature Sep 18, 2026

GajIPS - IPS Signature Update — GajIPS JA4 TLS-fingerprint signature: Atomic macOS Stealer (AMOS) C2 client fingerprint

This is a GajIPS JA4 fingerprint signature. This particular signature detects the Atomic macOS Stealer (AMOS), a macOS information-stealer that harvests browser credentials, cryptocurrency wallets, session tokens, and other sensitive data, typically installed when a user is tricked into pasting a command into the macOS Terminal. The signature recognises AMOS's TLS client fingerprint in outbound encrypted traffic.

A hit indicates a Mac on your network is making encrypted connections whose setup matches AMOS's networking behaviour, suggesting the device may be infected and communicating with attacker infrastructure. Treat it as a probable compromise: identify the Mac and user, and — because AMOS steals stored credentials, session tokens, and cryptocurrency wallets — treat those as exposed and reset them from a known-clean device, revoking active sessions.

Antivirus Sep 18, 2026

GajAV - Malware Signature Update — GS.Android.RatHat

These signatures detect Android application files (APKs) for RatHat, a sophisticated Android banking trojan linked to China-based threat actors. RatHat steals banking credentials, payment PINs, one-time passwords, two-factor codes, and device-unlock secrets, and captures screen and input activity. It spreads by tricking users into installing APKs from outside the official app store — via scam text messages (smishing), malicious ads, and fake download sites — while disguised as legitimate apps. Once installed it abuses Android's Accessibility and Wireless-Debugging (ADB) features to gain shell-level control, overlays fake screens on real banking and payment apps to capture entries, intercepts SMS and notifications to grab OTPs, and is notably difficult to remove — it can fake the uninstall screen and silently reinstall itself. It also uses a generative-AI component to help operators navigate infected devices.

If GajAV flags one of these files crossing the gateway, treat it as an attempted RatHat delivery to a device on your network, identify the destination device and user, and — because this malware targets financial credentials and OTPs — advise the user accordingly and route the device to mobile security handling. Given RatHat resists ordinary uninstallation and can reinstall itself, a suspected-infected device should be assessed with mobile threat-defence tooling and, where compromise is confirmed, factory-reset with credentials rotated; simply deleting the app is not sufficient.

Antivirus Sep 17, 2026

GajAV - Malware Signature Update — GS.Brevo.Injected script signatures

These signatures detect malicious JavaScript from the Brevo supply-chain attack of 14 September 2026. In that incident, a compromise of infrastructure belonging to Brevo (an email-marketing and website-chat provider, formerly Sendinblue) let attackers tamper with Brevo's own hosted scripts — its tracking SDK loader and its Conversations chat widget — so that any of the 100,000+ websites embedding those Brevo components would serve attacker code without their owners changing anything. The tampered scripts pulled a further malicious script from attacker-controlled infrastructure. Logged-in WordPress administrators were then targeted with an attempt to silently install a backdoor plugin, while other visitors were shown a fake "verification" page (a ClickFix lure) intended to trick them into running a malicious command. These signatures identify the three confirmed tampered script variants by exact fingerprint; the clean Brevo scripts are deliberately not signed, and Brevo's legitimate content-delivery network should not be blocked.

If GajAV flags one of these files, treat it as a probable compromise reaching your environment through an embedded Brevo widget: review which Brevo-hosted scripts your sites load and confirm they are clean, inspect any affected WordPress sites for an unexpected backdoor plugin and hidden administrator accounts, and treat any Windows endpoint whose user completed the fake "verification" prompt as potentially infected — from a known-clean device, reset that user's credentials and revoke active sessions.

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — GS TROJAN: Atomic macOS Stealer (AMOS) staged exfiltration beacon

Severity: HIGH · Priority: P2 — probable macOS infostealer infection, investigate on hit

This rule raises an alert when a Mac on your network sends the staged check-in signals used by AMOS (Atomic macOS Stealer), a widely-sold macOS information-stealer. AMOS is typically delivered by tricking a user into pasting a command into the macOS Terminal — often from a fake "macOS toolkit," a bogus fix-it prompt, or a poisoned ad — which installs the stealer. Once running, it harvests browser credentials, cryptocurrency wallets, messaging-app data, and cloud and developer configuration files, then reports progress to the attacker's server as a sequence of labelled stages while it uploads the stolen data. This rule watches for those stage labels in the outbound requests.

A hit strongly suggests a Mac is actively stealing and exfiltrating data. The stage markers this rule matches have no legitimate use, so a match is a high-confidence indicator that theft is in progress or has just occurred. Treat it as a probable compromise: identify the Mac and user, and — because AMOS captures the user's login password through a fake prompt and steals session tokens, cookies, and wallet material — treat those credentials as exposed. From a known-clean device, reset the user's passwords and revoke active sessions, prioritising anything of value stored on that Mac (cryptocurrency wallets, cloud and developer accounts, browser-saved logins). Then inspect the Mac for the stealer's persistence — malicious files disguised as macOS system components in the user's Library folders — and remove it; reimaging is the safest remediation.

Antivirus Sep 17, 2026

GajAV - Malware Signature Update — FamousSparrow malware components - GS.FamousSparrow

Severity: HIGH · Priority: P2 — targeted-APT malware, escalate on hit

These GajAV signatures detect malicious files used by FamousSparrow, a China-aligned state-sponsored cyberespionage group active since at least 2019. The group compromises governments, international organisations, and industry — most recently concentrating on government entities in Latin America — usually gaining entry by exploiting internet-facing Microsoft Exchange servers, then deploying backdoors (including SparrowDoor, ShadowPad, and the newer SparroWocky) for stealthy remote control. These signatures identify the group's malicious components — loaders, side-loading DLLs, a web shell, a dropper, and backdoors — by exact file fingerprint. 

If GajAV flags any of these files, treat it as a probable nation-state intrusion: isolate the affected host, preserve it for forensic investigation, and escalate to incident response with a view to assessing the wider environment rather than cleaning a single machine. Because entry is typically via an exposed Exchange server, confirm those are fully patched, and inspect the host for the group's other traces — unusual DLL side-loading, unexpected Windows services or startup entries, and reflectively loaded code.

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — FamousSparrow command-and-control detection

Severity: HIGH · Priority: P2 — targeted-APT activity, escalate on hit

These GajIPS rules detect network connections to command-and-control infrastructure used by FamousSparrow, a China-aligned state-sponsored cyberespionage group active since at least 2019. The group targets governments, international organisations, and industry, and in its most recent activity has concentrated heavily on government entities in Latin America, typically gaining initial access by exploiting internet-facing Microsoft Exchange servers. Its backdoors give attackers stealthy remote control — running commands, stealing data, capturing screenshots, and relaying traffic. These rules watch for a device on your network contacting the group's known control servers, both by network address and by domain-name lookup.

A hit is a serious signal: this is a targeted, well-resourced nation-state actor, not commodity crime. Treat any confirmed match as a probable compromise and escalate to incident response — given the actor, a broader compromise assessment across the environment is warranted rather than single-host cleanup. Because the group's usual entry point is an exposed Exchange server, prioritise confirming those are fully patched, and pair these alerts with host-level hunting (unusual DLL side-loading, unexpected services or startup entries, reflectively loaded code).

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: GLPI unauthenticated SQL injection in inventory feature, CVE-2025-24799

Severity: HIGH · Priority: P2 — exploitation attempt against a serious flaw, escalate on hit

This rule raises an alert when an attacker attempts to exploit a serious flaw in GLPI, a widely used open-source IT asset-management tool. GLPI's inventory feature accepts data from agents without requiring a login, and in vulnerable versions it fails to properly clean one of the values it receives — letting an unauthenticated attacker inject database commands. This can be used to read sensitive data from the database, including stored access tokens for user accounts, and can be chained with a second flaw to achieve full remote code execution on the server. Because GLPI is frequently connected to corporate directory services, a compromise can become a foothold into the wider network. This rule watches for the specific injection pattern used against the vulnerable inventory request.

A hit indicates an attempt to exploit this flaw against one of your servers. The flaw is unauthenticated and network-reachable, affects GLPI versions 10.0.0 through 10.0.17, and is fixed in 10.0.18. Treat an alert as an active exploitation attempt: confirm whether the targeted host runs GLPI and whether it is patched to 10.0.18 or later; if it is unpatched and the inventory feature is enabled, assume the attempt may have succeeded and escalate to incident response. Because a successful attack can steal account tokens, treat GLPI user credentials and API tokens as potentially exposed — rotate them — and check for follow-on activity such as unexpected authenticated sessions or signs of code execution. Updating to the fixed version, and disabling the inventory feature if it is not needed, are the definitive fixes.

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — GS TROJAN: ScreenConnect abuse C2 domain in DNS lookup

Severity: HIGH · Priority: P2 — probable intrusion via abused remote tool, investigate on hit

This rule raises an alert when a device on your network looks up the malicious domain, the domain used by attackers in a phishing campaign. The campaign begins with a fake transaction-receipt email and a bogus "Adobe Flash update" prompt, and ends with a legitimate remote-management tool (ConnectWise ScreenConnect) being silently installed and connected back to the attacker's server on this domain — giving the attacker persistent remote control of the machine, from which they can transfer files, run commands, and deploy further malware.

A hit indicates a device is resolving the attacker's remote-control server, which strongly suggests the machine has reached the final stage of this infection. Treat it as a probable compromise: isolate the device, and — because the attacker's foothold is a legitimate remote-management tool rather than obvious malware — look specifically for an unexpected ScreenConnect installation and a connection to the attacker's server; ordinary antivirus will not flag the remote tool itself.

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — GS TROJAN: KREMLIN (REF9334) Brazilian banking malware network activity

Severity: HIGH · Priority: P2 — probable banking-malware infection, investigate on hit

These rules detect network activity from KREMLIN, a banking-fraud malware toolkit that steals online-banking credentials and active login sessions. Despite the name, it is not a Russian operation — researchers attribute it to a Brazilian criminal group (tracked as REF9334) that has been active since May 2025 and primarily targets customers of Brazilian banks. The malware tricks a user into opening a malicious file disguised as a bank receipt or invoice, then secretly installs a rogue extension into the Chrome or Edge browser — forging the browser's own security checks so the extension appears trusted. Once active, it can steal cookies, saved logins, session tokens, keystrokes, and screenshots, and can alter banking pages in the browser. Because it hijacks an already-logged-in session, it can enable fraud even where a password alone would not.

The rules watch for three stages of the malware talking to its operators: its initial loader checking in, the theft of stolen browser data being sent out, and lookups of the attacker's dynamic configuration service. A hit strongly suggests a device on your network is infected. The web addresses and service names these rules match have no legitimate use, so a match is a high-confidence indicator. Treat it as a probable compromise of the device and the user's accounts: isolate the device, and from a known-clean system treat the user's banking and browser-stored credentials as exposed — reset passwords and revoke active sessions, prioritising any Brazilian-bank or financial accounts. Then inspect Chrome and Edge for an unfamiliar extension (it disguises itself under a benign-sounding name) and remove it; reimaging the device is the safest remediation given the malware's depth of browser tampering.