AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets – 01/19/2026

Black Basta Ransomware Leader Added to INTERPOL Red Notice

Ukrainian and German law enforcement have identified suspects linked to the notorious Black Basta ransomware group following coordinated raids in western Ukraine. Germany’s Federal Criminal Police Office named 35-year-old Russian national Oleg Evgenievich Nefedov as the alleged leader, adding him to both the European Union’s Most Wanted list and INTERPOL’s Red Notice. Two Ukrainian nationals were also identified as “hash crackers” who specialized in extracting passwords to enable network intrusions. Between 2022 and 2025, Black Basta is accused of targeting over 700 organizations worldwide, causing hundreds of millions of euros in damage, including attacks on hospitals, government agencies, and critical infrastructure. The group has been linked to the now-defunct Conti ransomware operation, and authorities believe Nefedov may have connections to Russian intelligence agencies.

Malicious Chrome Extensions Hijack Enterprise HR and ERP Accounts

Security researchers at Socket discovered five malicious Chrome extensions impersonating productivity tools for enterprise platforms like Workday, NetSuite, and SAP SuccessFactors. The extensions, which collectively reached over 2,300 installations, worked in concert to steal authentication tokens, block incident response capabilities, and enable complete account takeover through session hijacking. The campaign deployed three distinct attack types: continuous cookie exfiltration every 60 seconds to attacker-controlled servers, DOM manipulation to block security administration pages, and bidirectional cookie injection allowing attackers to assume victims’ authenticated sessions without passwords or MFA. Four of the extensions were published under the name “databycloud1104” while a fifth used different branding but shared identical infrastructure patterns. Most have been removed from the Chrome Web Store but remain available on third-party download sites.

GootLoader Malware Evades Detection With Malformed ZIP Archives

The GootLoader malware loader has evolved its evasion techniques by using deliberately malformed ZIP archives containing 500 to 1,000 concatenated files, according to researchers at Expel. The technique causes popular analysis tools like 7-Zip and WinRAR to crash or fail when processing the files, while Windows’ built-in unarchiver handles them without issue. This allows the malware to bypass automated security workflows while remaining fully functional for victims who double-click the downloaded files. The malware, which has been linked to the Vanilla Tempest threat actor and Rhysida ransomware deployments, generates unique archives for each victim using hashbusting and randomized metadata, making hash-based detection virtually useless. Expel recommends organizations use Group Policy to change the default handler for JavaScript files from Windows Script Host to Notepad, preventing automatic execution.

AWS CodeBreach Vulnerability Threatened Massive Supply Chain Attack

Security researchers at Wiz disclosed a critical supply chain vulnerability dubbed “CodeBreach” that could have allowed attackers to take over core AWS GitHub repositories, including the JavaScript SDK that powers the AWS Console. The flaw stemmed from a misconfigured regex filter in AWS CodeBuild pipelines—just two missing characters allowed unauthenticated attackers to bypass security checks by creating GitHub user IDs that contained approved maintainer IDs as substrings. Wiz demonstrated they could gain full admin access to the aws-sdk-js-v3 repository, which is present in approximately 66% of cloud environments. The vulnerability was disclosed to AWS in August 2025 and fixed within 48 hours, with additional hardening measures implemented in September. AWS confirmed no evidence of exploitation in the wild, but the incident highlights the growing risk of CI/CD pipeline attacks targeting software supply chains.

South Korean Giant Kyowon Confirms Data Theft in Ransomware Attack

South Korean conglomerate Kyowon Group has confirmed that customer data was exfiltrated during a ransomware attack that disrupted its operations earlier this month. Government investigators estimate that up to 9.6 million accounts across the company’s eight affiliates may be affected, representing approximately 5.5 million unique individuals. The attack, detected on January 10, impacted roughly 600 of the company’s 800 servers, forcing the shutdown of websites for its education, tutoring, home appliance rental, and funeral services businesses. Kyowon is working with the Korea Internet & Security Agency (KISA) and private cybersecurity firms to investigate the scope of the breach. The incident follows a wave of high-profile cyberattacks against South Korean companies, including breaches at Coupang, Korean Air, and SK Telecom in recent months.

Related Posts