As reported by SecurityAffairs in their Malware Newsletter Round 115, this week's threat landscape paints a sobering picture of converging attack vectors that demand defender attention. Several distinct threads emerge from the collection of research highlights — and each carries implications that extend well beyond the individual incidents.
Three Trends Defenders Cannot Ignore
1. AI is now both weapon and target. The newsletter references multiple AI-related threats: RatHat, an AI-powered mobile threat targeting credentials and bank accounts; skill poisoning attacks that turn AI agents into malware droppers (flagged by China's own National CERT); and academic research on adversarial attacks against LLM-based malware analyzers (ALIBI). This is no longer theoretical. Threat actors are actively building AI into their tooling while simultaneously probing AI security systems for weaknesses. Security teams that have deployed AI-powered detection or autonomous response tools should assume these systems are themselves under attack.
2. Supply chain attacks have reached industrial scale. The Brevo supply chain attack reportedly compromised over 100,000 sites with WordPress backdoors and Clickfix malware. This follows a now-familiar pattern: compromise a trusted upstream provider, inject malicious payloads downstream, and let the trust relationship do the distribution work. The scale here is what matters — 100,000 sites is not a targeted campaign, it's a mass-infection event that creates persistent infrastructure for future operations.
3. Browser extensions and OAuth tokens remain an underdefended perimeter. The malicious Twitch extension exposing 30,000 users' OAuth tokens to a Russian bot service, combined with the KREMLIN campaign forging Chrome integrity checks to steal banking sessions, illustrates that the browser — and especially its extension ecosystem — remains one of the most exploitable surfaces in enterprise environments. OAuth tokens grant persistent access without requiring password re-entry, making them high-value targets that MFA does not protect.
What the Geography Tells Us
The newsletter's geographic spread is notable. Iranian threat actors are targeting dissidents and journalists. Chinese groups are chaining Chrome and Windows zero-days and operating MQTT-based infection brokers across Asia. Russian-linked infrastructure is harvesting OAuth tokens. Central Asian energy and government sectors face SilkParasite/SpiceRAT campaigns. This is not random noise — it reflects a world where geopolitical tensions increasingly manifest through cyber operations against both hardened targets and soft civilian infrastructure.
The common thread across these campaigns is exploitation of trust: trust in software supply chains, trust in browser extensions, trust in AI systems, and trust in geopolitical quiet. Defenders should audit where their trust assumptions are most exposed.
Shield53 Recommendations
The overarching lesson from this week's landscape: attackers are scaling through trust, automating through AI, and diversifying through geography. Defenders must match that breadth — not by chasing every headline, but by systematically reducing the trust surfaces that make these campaigns possible.