What to look out for today
- Ransomware groups focusing on data theft (not just encryption) by targeting internet-exposed business platforms used in product and supplier workflows.
- Mailbox/webmail compromise risk where attackers aim to read email, harvest directories and grab authentication/recovery information.
- Trojanised “plugins” and bundled installers that look like legitimate tools (e.g., a normal app packaged with a fake add-on) to gain a foothold on Windows PCs.
Why this matters to smaller businesses
SMEs often rely on a small number of business-critical systems (email, line-of-business apps, supplier portals, design/product tools, and shared file stores). If attackers steal data rather than immediately encrypting, you may not realise for days or weeks—until you receive extortion demands, customers get scam emails, or confidential documents appear in leaks.
Separately, fake plugins and “helpful” add-ons are a common way to compromise a single PC and then pivot to passwords, finance mailboxes, and shared drives—especially where staff have local admin rights or software can be installed without oversight.
Warning signs
- Unexpected new add-ons/plugins showing up in tools used by staff, or requests to “install a plugin to view/edit a document”.
- Unusual browser behaviour on a work PC (background processes, high CPU when “nothing is open”, or odd new profiles/extensions).
- Email account anomalies: new inbox rules/forwarding, sign-ins from unfamiliar locations, password resets not initiated by the user.
- Supplier/customer reports of strange emails “from you” (invoice chasers, payment change requests, urgent document shares).
- Sudden concern about internet-exposed business systems (e.g., externally reachable admin portals) that haven’t been reviewed recently.
How attackers may exploit the situation
- Targeting exposed enterprise apps to steal sensitive files and then extort, even if they never deploy encryption.
- Abusing email access to quietly monitor threads, intercept invoices, and time a convincing payment diversion.
- Using trojanised “plugins” to establish persistence on a PC, then harvest credentials and move laterally.
- Blending in with normal tools (e.g., using the victim environment to communicate) to make detection harder.
What to do today
- Confirm what is publicly reachable: ask for a list of internet-exposed systems and admin portals (including any specialist business platforms).
- Lock down software installs: ensure users cannot install plugins/add-ons without approval, and use allow-listing where feasible.
- Harden email quickly: enforce MFA, review mailbox forwarding rules, and protect finance mailboxes with stricter sign-in controls.
- Run a short staff reminder: “No new plugins/extensions/apps to view documents. If you’re asked, report it.”
- Validate backups and restore: confirm you can restore key file shares and critical systems, and that backups are not easily reachable from everyday accounts.
Ask your IT provider
- Which of our systems are internet-exposed today, and which are business-critical? When were they last reviewed?
- Do we have alerting for unusual email rules (auto-forwarding, mass rule creation) and suspicious sign-ins?
- Can staff install software/plugins without admin approval? If yes, what’s the plan to reduce that risk?
- What’s our ransomware readiness: restore time for file shares, immutable/offline backups, and who makes the shut-down decision?
- Do we have central visibility (EDR/AV logs) to spot unusual browser/background activity and persistence attempts?
Patch watch - only one short paragraph, and only if relevant
If your organisation runs specialist industrial or manufacturing monitoring systems, be aware that CISA has issued advisories for certain industrial products. For most office-based SMEs this won’t apply, but it’s a useful prompt to inventory any operational/production kit connected to your IT network and ensure it is managed, monitored and supported.
One action today
Send a same-day internal note: “Do not install any new plugins/extensions or ‘viewer tools’ from emails or shared links—report requests to IT,” and have IT verify that users cannot install plugins without approval.
Related Actions On Cyber resource
CTA: Actions On Cyber checklist — Invoice & payment change verification (anti-BEC quick checks)
Sources
- Clop ransomware targets Windchill, FlexPLM in data theft attacks (BleepingComputer)
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge (The Hacker News)
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes (The Hacker News)
- Hackers abuse Notepad++ plugins to stealthily install malware (BleepingComputer)
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks (The Hacker News)
- Weintek cMT3092X (CISA Cybersecurity Advisories)
- Panduit IntraVUE (CISA Cybersecurity Advisories)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.