CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (17 March 2026)

Published: Loading…

At a Glance

  • GlassWorm's ForceMemo wave used stolen GitHub tokens to force-push obfuscated malware into hundreds of Python repositories, querying a Solana blockchain wallet for C2 instructions.
  • Boggy Serpens (MuddyWater) conducted four attack waves against a UAE marine and energy company between August 2025 and February 2026, deploying Rust-based BlackBeard and LampoRAT backdoors.
  • Poland's National Centre for Nuclear Research repelled a cyberattack with Iran cited as a suspected source, following a separate Russian-attributed attack on the country's power grid.
  • Warlock ransomware operators exploited SharePoint vulnerabilities, used a BYOVD technique via NSecKrnl.sys to kill security processes, and deployed ransomware enterprise-wide via Group Policy.
  • REDBIKE accounted for 30% of 2025 ransomware incidents, with data theft observed in 77% of intrusions and virtualisation infrastructure targeted in 43% of cases.
  • A phishing campaign on Tencent EdgeOne infrastructure abused browser APIs to silently capture photographs, video recordings, microphone audio, and contact details from victims' devices.

Summary

The GlassWorm campaign extended into a new wave dubbed ForceMemo, using GitHub tokens stolen via malicious VS Code and Cursor extensions to force-push obfuscated malware into hundreds of Python repositories whilst preserving original commit metadata. Injected payloads query a Solana blockchain wallet for command-and-control instructions before downloading encrypted credential and cryptocurrency stealers, with Russian-locale systems explicitly excluded from execution. Two React Native npm packages were separately backdoored as part of the same campaign, delivering a memory-resident payload that enforces a 48-hour re-execution lock.

Iranian state-sponsored espionage activity intensified across multiple theatres. Boggy Serpens (MuddyWater) conducted four distinct attack waves against a UAE-based marine and energy company between August 2025 and February 2026, deploying Rust-based BlackBeard and LampoRAT backdoors and hijacking legitimate government email accounts — including an Omani Ministry of Foreign Affairs mailbox — to bypass spam filtering. Poland's National Centre for Nuclear Research separately repelled a cyberattack with Iran cited as a probable source, two months after a Russian-attributed attack on the country's power grid caused permanent damage to industrial control systems.

Ransomware operations remained active across multiple sectors. The Warlock group exploited Microsoft SharePoint vulnerabilities for initial access, deployed a customised BYOVD tool via the vulnerable NSecKrnl.sys driver to terminate over 30 security product processes, and distributed the RunCryptor payload enterprise-wide through Group Policy. Google Threat Intelligence Group's analysis of 2025 incidents found REDBIKE accounted for nearly 30% of ransomware deployments, with data theft present in 77% of intrusions and virtualisation infrastructure targeted in 43% of cases — up from 29% in 2024.

Phishing campaigns expanded their data collection techniques beyond credentials. A campaign hosted on Tencent EdgeOne infrastructure abused legitimate browser APIs to silently capture photographs, video recordings, and microphone audio from victims after tricking them into granting camera and microphone permissions, with data exfiltrated to attacker-controlled Telegram bots. A separate campaign using the LiveChat SaaS platform engaged victims through real-time chat interfaces impersonating known brands to harvest credit card details, MFA codes, and PII.

Financial malware and supply chain threats continued to broaden in scope. GoPix, a Brazilian banking trojan, deployed memory-only implants and malicious Proxy AutoConfig files with injected root certificates to intercept HTTPS traffic on banking sites, expanding clipboard-hijacking to target Boleto bancário payment slips alongside Pix transactions. A Zombie ZIP technique — exploiting CVE-2026-0866 to create malformed ZIP files with misleading headers — was found to evade approximately 95% of antivirus engines tested, with roughly 60 of 63 common scanners failing to detect concealed payloads.

The UK Companies House WebFiling service was taken offline after a security flaw exposed the personal details of company directors to any logged-in user since October 2025. A Luxembourg court separately overturned Amazon's €746 million GDPR fine, vacating the penalty on procedural grounds — the regulator's failure to assess intentionality and proportionality — whilst leaving open the possibility of a revised fine following further review.

Highlights of the Day

Cyberattack Targets Poland's Nuclear Research Centre, Iran Suspected

Poland's National Centre for Nuclear Research (NCBJ) confirmed its IT infrastructure was targeted in a cyberattack, though the attempt was repelled without compromise to systems or research operations. The country's Deputy Prime Minister cited early indicators pointing to Iran as the likely source, whilst cautioning that evidence may have been planted to obscure the true origin. The incident follows a separate attack on Poland's power grid two months earlier, attributed to a Russian group, which caused permanent damage to some industrial control systems.

GlassWorm Expands to Force-Push Malware Into Hundreds of Python Repositories

The GlassWorm campaign has extended into a new attack wave, dubbed ForceMemo, in which stolen GitHub tokens — harvested from developers via malicious VS Code and Cursor extensions — are used to force-push obfuscated malware into Python repositories whilst preserving original commit metadata to avoid detection. The injected payloads query a Solana blockchain wallet for command-and-control instructions before downloading encrypted JavaScript designed to steal cryptocurrency and credentials, with Russian-locale systems excluded from execution. Two React Native npm packages were separately compromised as part of the same campaign, with malicious versions delivering a memory-resident payload that persists via a 48-hour execution lock stored in a local JSON file.

Phishing Campaign Abuses Browser Permissions to Harvest Biometric Data

A phishing campaign hosted primarily on Tencent EdgeOne infrastructure is abusing legitimate browser APIs to capture photographs, video recordings, microphone audio, and contact details from victims' devices, marking a shift beyond traditional credential theft. The campaign deploys multiple lure themes — including fake TikTok follower rewards, Telegram account freezes, and Google Drive security prompts — to trick users into granting camera and microphone permissions, after which captured data is exfiltrated directly to attacker-controlled Telegram bots. Code analysis identified emoji-embedded status messages and structured annotations within the phishing scripts, indicating likely use of generative AI tools during development.

Source: Cyble

GoPix Banking Trojan Uses Memory-Only Implants to Target Brazilian Finance

GoPix, a Brazilian banking trojan active since 2022, has evolved into one of the most technically sophisticated financial malware families documented, deploying memory-only implants, multi-stage obfuscated PowerShell loaders, and a novel man-in-the-middle technique using malicious Proxy AutoConfig files combined with injected root certificates to intercept and manipulate HTTPS traffic on legitimate banking sites. The malware uses a legitimate commercial anti-fraud service to pre-screen victims, ensuring payloads are only delivered to genuine targets whilst sandboxes and security researchers receive decoy pages. Beyond intercepting Pix transactions and cryptocurrency wallet addresses, GoPix has expanded its clipboard-hijacking capability to target Boleto bancário payment slips, with C2 servers that remain active for only a few hours to hinder investigation and attribution.

Iran–Israel Conflict Creates Escalating Cyber and Economic Risk for Southeast Asia

The outbreak of open warfare between Iran and Israel following Operation Epic Fury on 28 February 2026 has created measurable downstream risk for Southeast Asia across cybersecurity, energy supply, and financial systems. Iranian state-sponsored groups including APT33, APT34, APT35, APT42, and MuddyWater are assessed to have pre-positioned infrastructure across global networks, with US-aligned targets, energy sector organisations, financial institutions, and telecoms in the region considered plausible retaliation targets. Singapore's role as a primary energy trading hub and its identification by FinCEN as a centre for Iranian shadow banking — with $9 billion in suspicious transactions recorded in 2024 — places it at heightened exposure to both operational disruption and intensified US secondary sanctions enforcement.

Source: CloudSEK

Warlock Ransomware Group Abuses SharePoint and Legitimate Tools in Targeted Attack

The Warlock threat group (tracked as Water Manaul) exploited Microsoft SharePoint vulnerabilities to gain initial access, deploying Cobalt Strike via DLL sideloading before pivoting to a multi-layered command-and-control infrastructure combining the Velociraptor DFIR tool, VS Code tunnelling, Cloudflare Tunnel, and a newly identified SOCKS5 proxy tool named Yuze. The attackers achieved full domain compromise via DCSync credential theft, then used a customised BYOVD tool — disguised as TrendSecurity.exe — to terminate over 30 security product processes at the kernel level via the vulnerable NSecKrnl.sys driver before deploying ransomware enterprise-wide through Group Policy. Data exfiltration was conducted using a renamed rclone instance, with files uploaded directly to an attacker-controlled S3 bucket prior to encryption with the run.dll RunCryptor payload.

Ransomware Tactics Shift as Profits Decline and Virtualisation Attacks Rise

Google Threat Intelligence Group's analysis of 2025 ransomware incidents found that vulnerability exploitation — primarily targeting VPNs and firewalls from Fortinet, SonicWall, Palo Alto, and Citrix — was the leading initial access vector, whilst data theft accompanied 77% of intrusions, up from 57% in 2024. REDBIKE was the most frequently deployed ransomware family at nearly 30% of incidents, and virtualisation infrastructure was targeted in 43% of intrusions compared to 29% in 2024, with operators increasingly automating ESXi deployment. Despite record-high data leak site posts in 2025 — surpassing 2024 by almost 50% — ransom payment rates reached a historic low in Q4 2025, with average demands dropping from $2 million to $1.34 million, prompting a shift towards smaller targets and data-theft-only extortion models.

Luxembourg Court Overturns Amazon's €746 Million GDPR Fine

A Luxembourg administrative court has overturned the €746 million GDPR fine imposed on Amazon by the National Commission for Data Protection (CNPD) in 2021, the second largest since the regulation took effect. The court vacated the penalty not on the basis that Amazon's data practices were lawful, but because the regulator failed to assess whether the violation was intentional and did not adequately consider whether the fine was proportionate. The CNPD acknowledged that Amazon has since brought its practices into compliance and left open the possibility of issuing a revised fine following further review.

Source: The Record

MuddyWater Deploys AI-Generated Rust Backdoors in Sustained Middle East Campaign

Boggy Serpens (MuddyWater), attributed to Iran's Ministry of Intelligence and Security, has conducted a sustained espionage campaign targeting diplomatic, maritime, energy, and financial organisations across the Middle East and beyond, with four distinct attack waves against a single UAE-based marine and energy company documented between August 2025 and February 2026. The group has shifted towards Rust-based tooling — including the BlackBeard backdoor and LampoRAT, which uses the Telegram Bot API for command and control — whilst indicators within the malware code, including emoji-formatted status strings, suggest active use of generative AI during development. A defining operational trait is the systematic hijacking of legitimate government and corporate email accounts, including a compromised Omani Ministry of Foreign Affairs mailbox, to distribute phishing documents that bypass reputation-based spam filtering by originating from authenticated internal accounts.

Daily Coverage

Developments
Glassworm Forcememo WaveBoggy Serpens / MuddywaterPoland Nuclear Centre AttackWarlock Byovd Ransomware
Vulnerabilities
CVE-2025-47813Wing Ftp Server (Medium)CVE-2026-3630CVE-2026-3631CVE-2026-0866CVE-2026-32267Cms >= 4.0.0-Rc1, < 4.17.6 (Critical)CVE-2025-62847Qts 5.2.X (High)
Threat Groups
MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.APT33APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.APT35Magic Hound is an Iraniansponsored threat group that conducts long term, resourceintensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U. S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.APT34OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nationstate interests.APT42APT42 is an Iraniansponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and opensource tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.