CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (10 March 2026)

Published: Loading…

At a Glance

  • Russian state hackers impersonated a Signal Support chatbot to extract verification codes and hijack officials' accounts globally.
  • InstallFix attackers cloned Claude Code install pages and paid for Google Search placement to distribute Amatera Stealer malware.
  • ACSC, NCSC, and CERT Tonga jointly warned of INC Ransom affiliates targeting Pacific healthcare and government networks since early 2025.
  • A0Backdoor malware was deployed via Microsoft Teams impersonation and Quick Assist abuse against financial and healthcare organisations.
  • Identity compromise underpinned 83% of cloud and SaaS intrusions in H2 2025, per Google Cloud's Threat Horizons Report.
  • HTTP/1.x request smuggling flaws CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836 were patched in Pingora OSS framework version 0.8.0.

Summary

Russian state-sponsored hackers are conducting a large-scale campaign to compromise Signal and WhatsApp accounts belonging to government officials, military personnel, and journalists worldwide. Dutch intelligence agencies MIVD and AIVD confirmed Dutch government employees are among the victims, noting the operation abuses legitimate app features — including a fake Signal Support chatbot used to extract verification codes and the "linked devices" function to maintain persistent access — rather than exploiting any technical vulnerabilities in the messaging platforms.

Social engineering via trusted communication channels extended to corporate environments, with the threat cluster Blitz Brigantine — linked to Black Basta ransomware affiliates — deploying a new backdoor dubbed A0Backdoor against financial and healthcare organisations. Attackers overwhelmed targets with email spam before contacting them via Microsoft Teams posing as IT support, then used Windows Quick Assist to sideload a malicious DLL; the backdoor evades detection by routing command-and-control traffic through covert DNS MX record queries via public resolvers.

A separate social engineering pattern targeted developers through cloned installation pages for Anthropic's Claude Code, surfaced via paid Google Search placement. The campaign, dubbed InstallFix, replaced legitimate install commands with malicious one-liners fetching Amatera Stealer payloads from attacker-controlled infrastructure hosted on Cloudflare Pages, Squarespace, and Tencent EdgeOne, harvesting browser credentials, session tokens, and system data.

INC Ransom, a Russia-linked Ransomware-as-a-Service operation, has expanded activity across the Pacific, prompting a joint advisory from the ACSC, New Zealand's NCSC, and CERT Tonga. Confirmed incidents include a June 2025 attack on Tonga's Ministry of Health and intrusions against New Zealand health-sector organisations, with 11 attributed incidents recorded in Australia between July 2024 and December 2025; affiliates gain initial access via spear-phishing, unpatched systems, or purchased credentials before conducting data exfiltration and double extortion.

Google Cloud's H1 2026 Threat Horizons Report found identity compromise drove 83% of cloud and SaaS intrusions in the second half of 2025, with third-party software vulnerabilities overtaking weak credentials as the leading initial access vector. The exploitation window between vulnerability disclosure and active attack has collapsed from weeks to days, a pattern reflected in the disclosure of three HTTP/1.x request smuggling flaws — CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836 — affecting standalone Pingora OSS deployments, patched in version 0.8.0.

Highlights of the Day

Russian State Hackers Target Signal and WhatsApp Accounts in Global Campaign

Dutch intelligence agencies MIVD and AIVD have confirmed that Russian state-sponsored hackers are conducting a large-scale campaign to compromise Signal and WhatsApp accounts belonging to government employees, military personnel, and dignitaries, with Dutch officials confirmed among the victims. The operation exploits legitimate app features rather than technical vulnerabilities — primarily by impersonating a Signal Support chatbot to extract verification codes, and by abusing the "linked devices" function to gain persistent access. Once an account is compromised, attackers can silently read messages and access group chats, with the campaign likely yielding sensitive information.

Source: AIVD

Attackers Clone Claude Code Install Pages to Distribute Infostealer Malware

Researchers at Push Security have identified a campaign, dubbed "InstallFix," in which threat actors cloned the installation pages of Anthropic's Claude Code and distributed them via Google Search sponsored results. The fake pages are near-identical replicas of the legitimate site, with the sole difference being malicious install commands that fetch payloads from attacker-controlled servers rather than the official source. Analysis of the payloads identified Amatera Stealer, a subscription-based infostealer capable of harvesting browser credentials, session tokens, and system information, with malicious infrastructure hosted across Cloudflare Pages, Squarespace, and Tencent EdgeOne.

INC Ransom Expands Ransomware Campaign Across Pacific Region

Australia, New Zealand, and Tonga have issued a joint advisory warning of escalating activity from INC Ransom, a Russia-linked Ransomware-as-a-Service operation that has been actively targeting healthcare and professional services organisations across the Pacific since early 2025. The group's affiliate model enables distributed attackers to conduct intrusions using shared infrastructure, with entry typically gained through spear-phishing, exploitation of unpatched systems, or purchased credentials — followed by data exfiltration and double-extortion tactics. Confirmed incidents include a June 2025 attack on Tonga's Ministry of Health and a separate intrusion against a New Zealand health-sector organisation, with the ACSC recording 11 attributed incidents in Australia between July 2024 and December 2025.

REMCOS RAT Spread via Trojanised Shotcut Video Editor Packages

A campaign delivering REMCOS RAT has been observed using trojanised versions of the legitimate open-source video editor Shotcut as a delivery vehicle, with the malware embedded in replaced DLL files rather than the application itself. The attack chain begins with a ClickFix social engineering lure — typically a fake CAPTCHA on a compromised website — that tricks victims into executing malicious commands, ultimately unpacking the poisoned Shotcut package. Once deployed, the paid version of REMCOS grants attackers extensive capabilities including keylogging, credential theft, webcam access, UAC bypass, and persistent command-and-control communication.

Source: LevelBlue

Black Basta-Linked Group Deploys New Backdoor via Teams Impersonation

BlueVoyant has identified a new malware payload, dubbed A0Backdoor, deployed by the threat cluster Blitz Brigantine — also tracked as Storm-1811 and linked to Black Basta ransomware affiliates. The campaign follows a well-documented playbook: targets are overwhelmed with email spam, then contacted via Microsoft Teams by attackers posing as IT support, who request remote access through Windows Quick Assist before sideloading a malicious DLL to deliver the backdoor. Notably, A0Backdoor communicates with its command-and-control infrastructure via covert DNS MX record queries routed through trusted public resolvers, helping it evade detection controls tuned to earlier attack patterns.

Source: BlueVoyant

Google Cloud Report Finds Identity Breaches and Faster Exploitation Defining 2025 Threats

Google Cloud's H1 2026 Threat Horizons Report, drawing on data from Google Threat Intelligence Group and Mandiant, found that identity compromise underpinned 83% of cloud and SaaS intrusions in the second half of 2025, with data theft the primary objective in 73% of cases. Third-party software vulnerabilities overtook weak credentials as the leading initial access vector for the first time, with the window between vulnerability disclosure and active exploitation collapsing from weeks to days. The report also documents a North Korean campaign abusing Kubernetes workloads to steal millions in cryptocurrency, a CI/CD supply chain attack that achieved full cloud compromise within 72 hours, and a growing trend of malicious insiders using cloud storage services to exfiltrate sensitive data.

Daily Coverage

Developments
Signal/Whatsapp HijackingInstallfix CampaignInc Ransom Pacific AdvisoryA0Backdoor Deployment
Vulnerabilities
CVE-2021-22054CVE-2025-11158CVE-2025-26399Web_Help_Desk 12.8.6 (Critical)CVE-2026-26110CVE-2026-26113CVE-2026-26144CVE-2026-2836CVE-2026-2835CVE-2026-2833CVE-2026-24018Forticlientlinux 7.4.0 (High)
Threat Groups
APT28[Also known as: Sednit, Fancy Bear] APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.INC RansomINC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Storm-1811Storm1811 is a financiallymotivated entity linked to Black Basta ransomware deployment. Storm1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with nonmalicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.