Cybersecurity: AI-Driven Threats Accelerate Across Scams, Backdoors, and Compromised Supply Chains
Explore how AI fuels scams, backdoors, and supply chain compromises in cybersecurity. Stay informed on emerging threats and real-world incidents.
Illustrative image generated with AI
ChatGPT Used to Automate Fraud Campaigns
OpenAI disabled ChatGPT accounts linked to a Cambodia-based network. The operators used the model to create investment scams, romance scams, gambling fraud, and fake police communications.
The operation used AI to generate fake identities, translate messages, create promotional images, and forge documents. Disabling the accounts cut off access to the platform, but further details about the campaign’s scale and victims remain unknown.
QuickFox Installer and Zbtlink Routers: Two High-Risk Compromises
A supply chain compromise distributed a trojanized Electron installer for QuickFox VPN and its related gaming acceleration application. The program ran a JavaScript loader that installed the FDMTP malware on Windows systems.
The loader analyzed running processes, avoided Steam users, and prioritized devices containing development tools, databases, or cryptocurrency wallets. QuickFox removed the malicious components after Fortinet reported the issue. No specific installer versions have been disclosed.
Even more serious is the EndlessDoors backdoor, discovered in several Zbtlink cellular routers and models sold under other brands. Based on the Rctl tool, the component contacts a command-and-control infrastructure at startup and accepts unauthenticated root commands.
Anyone controlling the C2 endpoints can execute shell commands or open interactive shells with administrative privileges. No inbound service exposure is required. VulnCheck recommends treating affected devices as untrusted and has published detection guidance; the exact models and firmware versions remain unknown.
DoubleCup Delivers Malware Through ClickFix Campaigns
The Russian DoubleCup group, active in the Loader-as-a-Service market, has reportedly operated ClickFix campaigns since early June 2026. The attacks combine steganography with environment profiling to determine when to deploy the payload.
The second-stage malware includes an updated version of CountLoader, compatible with Windows and macOS, which modifies legitimate binaries to hinder analysis. Researchers also observed DeviceManager RAT, whose command-and-control address is discovered through smart contracts on the Ethereum and Polygon networks.
No specific countermeasures have been disclosed. Organizations should therefore look for unusual script execution, modified legitimate files, and connections to blockchain addresses used for C2 discovery.
Amgen, IEH, and U.S. Ports: Exposed Data and Operational Disruptions
In July 2026, Amgen detected unauthorized access to data stored in third-party cloud environments. The company later confirmed the exfiltration of proprietary information and patients’ protected health information.
No impact has been reported to products, manufacturing, financial systems, or patient care. The investigation into the scope of the accessed data is ongoing, and required notifications are expected.
On August 4, IEH Corporation identified unauthorized access to an employee’s Microsoft 365 mailbox. The attack began with a phishing message posing as a potential business inquiry and leading to a fake login page.
During the compromise, the attacker could read emails, attachments, purchase orders, and technical documents concerning Hyperboloid connectors for the defense, aerospace, and space sectors. No messages appear to have been sent from the account, and there is no evidence of successful data exfiltration.
Also on August 4, an attack disrupted systems at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The gates reopened the following day after the contingency plan was activated and the compromise contained. It is not known whether sensitive data was stolen.
Voice-phishing campaigns targeting major hedge funds were also reported, but no information is available about the specific targets, techniques, or impact.
Apple Limits Researcher Reports as FCC Prepares Transceiver Restrictions
Apple has introduced a limit on the number of reports researchers can submit through its bug bounty program. The decision follows an increase in low-quality reports generated by AI hallucinations.
Bynario reached the threshold after using ChatGPT to identify more than 50 alleged macOS vulnerabilities, including a privilege-escalation exploit that it could not immediately report. Researchers can request a higher limit; Apple also uses AI for triage.
On the infrastructure front, the FCC is preparing rules to block the import of new Chinese optical transceivers intended for data centers. The goal is to reduce the risk of data theft, malware, and outages affecting AI infrastructure.
The Trump administration aims to finalize the measure by the end of the current year. U.S. manufacturers have already gained market share, while cloud operators could face higher costs when switching suppliers.
Sources
This article is an original reworking based on the sources below.




