DevMan RaaS portal, Steam mining traps, Bun malware builder
PRODAFT’s latest report shows the DevMan ransomware‑as‑a‑service operators have built a unified web portal that lets affiliates generate payloads, track earnings, and manage victim data, including structured records and team controls. The v3 upgrade pushes ransomware operations toward a turnkey, business‑like model, raising the bar for affiliate coordination and victim impact.
Threat actors create bogus Steam support posts that tell users to run a PowerShell "fix" for game crashes. The command silently downloads and launches an XMRig cryptocurrency miner, evading many security defenses. Gamers who follow the fake instructions end up with their PCs secretly mining Monero.
Confiant’s report shows the SourTrade campaign delivers only harmless components, then uses the legitimate Bun JavaScript runtime to assemble a Windows executable inside the victim’s browser. This in‑memory construction defeats fingerprint‑based defenses and lets the attackers target retail crypto traders at scale across dozens of countries.
GitHub now imposes a default three‑day wait before Dependabot opens version‑update pull requests, giving maintainers and security scanners time to flag malicious releases. The change follows recent npm supply‑chain attacks where poisoned packages spread within hours, and aims to cut the window for automatic infection.
Subscribe free