Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands
Another week of recycled tradecraft — abused integrations, poisoned WordPress, and ransomware crews still gunning for endpoint sensors.

Monday again. The threat feed reads like a rerun.
Most of what crossed the wire this week wasn't novel. It was familiar tradecraft applied at scale: weak credentials harvested, OAuth integrations abused, browser extensions over-permissioned, and compromised WordPress sites pressed back into service as malware delivery infrastructure. The continuity is the story.
Several clusters are worth flagging, with the usual attribution caveats.
EDR killers continue their renaissance. Multiple ransomware affiliates — overlapping TTPs across what some vendors track as separate clusters — are shipping bring-your-own-vulnerable-driver tooling to terminate endpoint sensors before encryption. The technique isn't new. The packaging is getting better. Affiliates who couldn't write a driver loader six months ago are now dropping signed-but-vulnerable binaries pulled from public repositories. Capability has diffused downward, which is the part defenders should care about.
On the browser side, researchers disclosed exploitable bugs in widely deployed engines this week. Patch cycles matter here. Track CVE listings at NVD directly rather than trusting downstream summaries — the CVSS rescoring on a few of these shifted after initial publication.
An Android banking trojan made the rounds with a permission manifest that reads like a wishlist. Accessibility services, SMS interception, overlay rendering, and device admin. The dropper hides behind a fake utility app distributed outside Play. TTPs overlap with families previously associated with operators tracked as part of the broader Brazilian and Eastern European mobile-fraud ecosystem, though I'd put that at low-to-medium confidence pending samples.
A TV-based botnet got attention this week as well. Internet-connected smart TVs with stale firmware are being conscripted into proxy networks — the same playbook run against routers and IP cameras for years, now pointed at a softer target with worse patching discipline. It's a capability story more than an intent one. Whoever runs the infrastructure is renting it out.
An OpenBSD flaw also landed. Worth patching, low drama, but notable because OpenBSD bugs of this class are rare enough that they get scrutinized harder than equivalents elsewhere.
The through-line: none of this requires nation-state tooling. Kimsuky, Mustang Panda, Sandworm — pick your APT — none of them needed to show up this week because the commodity ecosystem is doing the work. Initial access brokers feed affiliates. Affiliates feed ransomware operations. The infrastructure churns.
A few things to actually do this week. Audit OAuth grants in your tenant and revoke anything stale. Push browser updates aggressively; the gap between disclosure and exploitation keeps shrinking. Review driver allowlists if you've got the telemetry for it. And if your MDM doesn't block sideloading on managed Android, that's a conversation worth having before the next trojan campaign lands on a corporate device.
Nothing here is novel. That's the point.



