Russian State Hackers Go After IoS Devices
Digest
This podcast highlights several significant cybersecurity threats. A new macOS malware called Infinity Stealer targets Mac users through clickjacking, stealing credentials and secrets. Russian state hackers are exploiting iPhones using the Darksword exploit kit in spearfishing campaigns. China-linked actors are employing a stealthy Linux backdoor, BPF Door, for long-term persistence in telecom networks. The threat group TeamPCP has compromised the Telnix package on PyPI, distributing malware hidden in audio files. Additionally, Iranian-linked groups are specifically targeting the healthcare sector, causing disruptions and data destruction without ransom demands.
Outlines

Cybersecurity Threats: Malware, Espionage, and Supply Chain Attacks
This segment covers a range of cybersecurity threats, including new malware like Infinity Stealer targeting macOS users via clickjacking, and the Darksword iOS exploit kit used by Russian state hackers for iPhone attacks. It also details a China-linked espionage campaign using the BPF Door backdoor in telecom networks, TeamPCP's compromise of the Telnix package on PyPI to distribute malware, and Iranian-linked groups deliberately targeting the healthcare sector with disruptive attacks.
Keywords
Infinity Stealer
A new macOS malware that steals credentials and secrets using clickjacking and a stealthy Python payload.
Darksword iOS Exploit Kit
Used by Russian state hackers to target iPhones via spearfishing, delivering data miner malware.
BPF Door
A stealthy Linux backdoor used by China-linked actors for long-term persistence in telecom networks.
Supply Chain Attack
Attackers compromising trusted software components, like TeamPCP's Telnix package compromise on PyPI.
Paida Ki (Fox Kitten)
An Iran-linked group targeting the U.S. healthcare sector with disruptive attacks.
Q&A
What is Infinity Stealer and how does it target Mac users?
Infinity Stealer is a new macOS malware that uses clickjacking, a social engineering tactic. Attackers create fake webpages to trick users into running commands that execute the malware, stealing credentials and other sensitive information.
How are Russian state hackers using the Darksword exploit kit?
Russian state hackers are using Darksword to target iPhones via spearfishing emails. These emails, often spoofing legitimate organizations, deliver the Ghostblade data miner malware, expanding the group's targeting beyond previous methods.
What makes the BPF Door backdoor used by Red Menshen particularly dangerous?
BPF Door is dangerous because it's a stealthy Linux backdoor operating at the kernel level. It avoids detection by not opening listening ports or using visible command and control channels, allowing for long-term, invisible persistence in telecom networks.
How did TeamPCP compromise the Telnix package, and what is the impact?
TeamPCP uploaded backdoor versions of the Telnix package to PyPI. This official Python SDK, with over 740,000 monthly downloads, was used to distribute malware hidden in WAV files, affecting a significant number of developers integrating Telnix services.
Why is the targeting of the healthcare sector by Iranian-linked groups significant?
The deliberate targeting of healthcare by groups like Handala and Paida Ki is significant because it disrupts critical services, leading to canceled surgeries and potential destruction of data without ransom. This indicates a strategic focus on critical infrastructure.
Show Notes
Mac Malware 'Infinity Stealer,' DarkSword iOS Exploits, China Telecom Espionage & TeamTNT Supply Chain Hits
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
David Shipley reports from Seoul on major threats: Malwarebytes details Infinity Stealer, a new macOS info-stealer delivered via "ClickFix" social engineering and built as a compiled Python payload (Nuitka) that steals browser credentials, Keychain data, crypto wallets, and developer secrets while notifying attackers via Telegram. Proofpoint links Russia-aligned TA446 (Cold River/Star Blizzard) to spear-phishing using the DarkSword iOS exploit kit to deliver GhostBlade, with DarkSword now leaked on GitHub and Apple pushing unusual on-device warnings for vulnerable iOS versions. Rapid7 describes China-linked "Red Menshen" using the kernel-level BPFdoor backdoor to persist in global telecom networks. TeamTNT compromises the Telnyx PyPI package with WAV-steganography payloads that steal secrets and target Kubernetes. Iran-linked activity includes a symbolic FBI director email breach and escalating, deliberate healthcare disruption via attacks on Stryker and a Pay2Key incident.
00:00 Show Intro and Sponsor
00:53 Mac ClickFix Stealer
03:25 Dark Sword iOS Exploits
06:30 China Telecom Backdoor
08:47 TeamTNT PyPI Supply Chain
12:20 Iran Cyber and Healthcare
17:41 Wrap Up and Thanks
18:43 Sponsor Message
























