Cyber Attackers Flex Muscles as Clop Leak Site Taken Down and Docker Botnet Hunts AI Keys
A complex web of cyber threats has been unfolding in recent days, with multiple attack vectors targeting everything from browser AI assistants to water utility systems. The latest salvo came when the notorious Cl0p ransomware gang’s leak site was seized by rival attackers ShinyHunters, who not only defaced the site but also claimed to have stolen server logs, source code, and private keys for Clop’s onion service.
At the heart of the dispute is a long-standing feud between the two groups that dates back to their involvement in last year’s Oracle E-Business Suite campaign. ShinyHunters has accused Clop of making threats against them, prompting the retaliatory attack on their leak site. The group demanded an eight-figure payment and a public apology from Clop in exchange for not exposing companies that allegedly paid them during the Oracle campaign.
Meanwhile, researchers at endpoint security firm Forever have uncovered a set of flaws known as BragJack, which allow malicious extensions to take control of browser AI assistants in popular browsers like Chrome, Edge, Opera Neon, Perplexity Comet, and Claude. By injecting scripts or tampering with network traffic, an attacker can hijack the assistant’s prompts without any user interaction, enabling access to sensitive information such as emails, local files, screenshots, camera and microphone permissions.
In a separate development, an attacker has published malicious versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent harness. The malware, known as sckit, is a previously unseen Go implant that hunts for secrets in popular services like npm, PyPI, GitHub, AWS, and Hugging Face. While there is currently no evidence of propagation, the implant contains templates for spreading through npm, PyPI, and GitHub Actions.
The use of AI-powered relay networks has also come under scrutiny, with Team Cymru discovering nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open-source gateways pool AI accounts to enable multiple users to share them while model providers see only the relay and not the real user’s location.
In a more concerning development, SpyCloud has analyzed stolen identity data tied to 10,000 US water and wastewater utilities and their technology vendors. The analysis revealed active infostealer exposure at 1,787 organizations, with credentials for OT or remote-access systems exposed at 258. In one case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals.
Finally, Cisco Talos has documented CLOSEDQUORUM, a Go-based Windows implant that hands its command-and-control decisions to commercial Large Language Models (LLMs) instead of a human operator or attacker-run server. The implant executes the winning choice and sends LSASS dumps, browser passwords, and crypto wallet data to the operator’s Discord channel.
In light of these attacks, it is essential for organizations to remain vigilant about their security posture. This includes keeping software up-to-date, implementing robust authentication measures, and being cautious when using AI-powered tools or services. By staying informed and proactive, businesses can better protect themselves against the evolving cyber threat landscape.
Source: SecurityWeek — 2026-09-25