Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (7 March 2026)
Published: Loading…
At a Glance
- Seedworm deployed two new backdoors, Dindoor and Fakeset, across a US bank, airport, and defence software firm since February 2026.
- A ClickFix campaign used Windows Terminal to deploy Lumma Stealer, replacing the traditional Windows Run dialog as the execution vector.
- CISA added five actively exploited flaws from Hikvision, Rockwell Automation, and Apple to its Known Exploited Vulnerabilities catalogue.
- VOID#GEIST delivered XWorm, XenoRAT, and AsyncRAT via Early Bird APC injection into explorer.exe using a fileless, batch-script-based chain.
- A trojanised Red Alert rocket warning app harvested SMS messages, contacts, and GPS data from Israeli users via a smishing campaign.
- Cisco patched two maximum-severity flaws in Firewall Management Center enabling unauthenticated root-level code execution on affected devices.
Summary
Seedworm (MuddyWater), an Iranian APT linked to Iran's Ministry of Intelligence and Security, has maintained active footholds across multiple US and Canadian organisations since February 2026, including a bank, an airport, a non-profit, and the Israeli operations of a US defence software supplier. Two previously undocumented backdoors were deployed: Dindoor, leveraging the Deno JavaScript runtime, and Fakeset, a Python-based implant — both signed with certificates tied to prior Seedworm activity. A concurrent report attributed more than 60 Iranian-aligned cyber groups mobilising within hours of the February 28 US-Israel military escalation, with AI tools identified as lowering the barrier to targeting internet-exposed industrial control systems.
CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue, covering flaws in Hikvision and Rockwell Automation products — the latter a CVSSv3 9.8 flaw disclosed in 2021 whose in-the-wild exploitation has only now been confirmed — alongside three Apple iOS use-after-free and integer overflow vulnerabilities tied to the Coruna nation-state-grade exploit kit. Cisco separately patched two maximum-severity flaws in its Secure Firewall Management Center: CVE-2026-20079, enabling unauthenticated authentication bypass and root script execution, and CVE-2026-20131, enabling unauthenticated arbitrary Java code execution via insecure deserialisation. A maximum-severity authentication bypass in the pac4j-jwt Java library (CVE-2026-29000) was also patched, allowing attackers with knowledge of a server's RSA public key to impersonate arbitrary users.
Social engineering campaigns continued to abuse terminal and command-line execution as a delivery mechanism. A ClickFix campaign observed in February 2026 redirected victims to launch Windows Terminal and self-execute commands deploying Lumma Stealer, replacing the previously favoured Windows Run dialog. A separate InstallFix campaign distributed near-pixel-perfect clones of the Claude Code installation page via Google-sponsored search results, with the malicious install commands delivering Amatera Stealer — a subscription-based infostealer capable of harvesting browser credentials, cookies, and session tokens. A fake CleanMyMac site similarly instructed macOS users to paste commands into Terminal, installing SHub Stealer and backdooring cryptocurrency wallet applications including Exodus and Ledger Live.
The VOID#GEIST malware chain used obfuscated batch scripts to stage a legitimate embedded Python 3.10 runtime, decrypt XOR-encrypted shellcode blobs for XWorm, XenoRAT, and AsyncRAT, and inject all three payloads into separate suspended instances of explorer.exe via Early Bird APC injection. No decrypted executables were written to disk at any stage, with persistence established via a batch script dropped into the Windows Startup folder. Pakistan-aligned Transparent Tribe was separately observed using AI-assisted coding tools to mass-produce implants written in Nim, Zig, and Crystal, targeting India through high-volume campaigns hosted on trusted services.
A smishing campaign distributed a trojanised Red Alert rocket warning Android app to Israeli users via SMS messages spoofing the Home Front Command, harvesting SMS messages, contacts, GPS location, device accounts, and installed applications. The malware employed certificate spoofing and runtime signature forgery to mimic a Google Play installation, with exfiltration routed to an attacker-controlled endpoint. Transport for London also confirmed that its 2024 breach exposed the data of more than 7 million customers — significantly more than the 5,000 initially disclosed — with affected records linked to Oyster and contactless payment users.
Highlights of the Day
Iranian APT Seedworm Breaches US Bank, Airport and Software Firm
The Iranian state-linked threat group Seedworm (also known as MuddyWater) has been active on the networks of several US and Canadian organisations since February 2026, with intrusions continuing in the wake of US and Israeli military strikes on Iran. Targets include a US bank, an airport, a Canadian non-profit, and the Israeli operations of a US defence and aerospace software supplier. Two previously undocumented backdoors were identified across the affected networks: Dindoor, which leverages the Deno JavaScript runtime and was found at the software firm and bank, and Fakeset, a Python-based backdoor discovered at the airport and non-profit — both signed with certificates linked to prior Seedworm activity. An attempt to exfiltrate data from the software company using Rclone to a Wasabi cloud storage bucket was also observed, though whether it succeeded remains unclear.
CISA Flags Five Actively Exploited Vulnerabilities Across Major Vendors
CISA has added five vulnerabilities to its Known Exploited Vulnerabilities catalogue, citing evidence of active exploitation in the wild. The entries span products from Hikvision, Rockwell Automation, and Apple, covering flaws including improper authentication, insufficient credential protection, integer overflow, and two use-after-free vulnerabilities. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies are required to remediate catalogued vulnerabilities by specified deadlines.
Trojanised Rocket Alert App Targets Israeli Users with Spyware
Acronis Threat Research Unit has identified a smishing campaign targeting Israeli citizens with a trojanised version of the Red Alert rocket warning Android app, delivered via SMS messages spoofing the official Home Front Command. The malicious application retains full alert functionality as cover whilst silently harvesting SMS messages, contacts, GPS location, device accounts and installed applications, transmitting the data to a remote command-and-control server at a Namecheap-registered domain. The malware employs certificate spoofing, runtime signature forgery to impersonate a Google Play installation, and layered Base64 and XOR obfuscation to resist analysis — with Acronis tentatively attributing the campaign to Arid Viper (APT-C-23) based on targeting patterns and tooling characteristics.
Malicious Ads Serve Fake Claude Code Install Pages to Steal Credentials
Attackers are cloning the installation pages of popular developer tools — most recently Anthropic's Claude Code — and distributing them via Google-sponsored search results to deliver infostealer malware. The technique, dubbed InstallFix by Push Security researchers, presents victims with near-pixel-perfect replicas of legitimate installation pages where the only alteration is the install command itself, which fetches malware from an attacker-controlled server rather than the genuine source. Analysis of the payload identified Amatera Stealer, a subscription-based infostealer capable of harvesting browser credentials, cookies and session tokens, with the malware using direct NTSockets for C2 communication and dynamic API resolution to evade endpoint defences.
Multi-Stage Python Loader Deploys Three RATs via Fileless Injection
Securonix Threat Research has documented VOID#GEIST, a multi-stage malware campaign that uses an obfuscated batch script to deliver XWorm, XenoRAT, and AsyncRAT entirely in memory, without writing decrypted executables to disk. The attack chain stages a legitimate embedded Python 3.10 runtime downloaded directly from python.org, uses XOR-encrypted shellcode blobs decrypted at runtime with external JSON key files, and injects all three payloads into separate suspended instances of explorer.exe via Early Bird APC injection. Persistence is achieved by dropping a secondary batch script into the Windows Startup folder, with a lightweight HTTP POST beacon sent to TryCloudflare-hosted infrastructure confirming successful compromise.
Daily Coverage