CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (17 April 2026)

Published: Loading…

At a Glance

  • UAC-0247 targeted Ukrainian government clinics and hospitals using phishing campaigns delivering multi-stage malware for browser credential theft and WhatsApp data exfiltration.
  • W3LL phishing-as-a-service platform enabled over 500 actors to compromise Microsoft 365 accounts globally by bypassing multi-factor authentication through session cookie theft.
  • PowMix botnet targeted Czech organisations using phishing ZIP files with LNK loaders, establishing encrypted command-and-control channels via Heroku infrastructure.
  • ShinyHunters breached McGraw Hill Salesforce environment, exposing 13.5 million user records including emails, phone numbers, and physical addresses through misconfiguration.
  • Sapphire Sleet macOS campaign used fake Zoom updates to deploy credential-stealing malware with Telegram exfiltration and persistence via launch daemons.
  • Attackers abused QEMU virtual machines to conceal ransomware operations, enabling covert persistence, credential harvesting, and deployment of PayoutsKing ransomware.

Summary

UAC-0247 conducted phishing operations against Ukrainian government healthcare institutions, deploying multi-stage malware focused on browser credential theft and messaging data extraction. The campaign used LNK and HTA loaders with supporting tools for persistence and lateral movement across affected systems.

The W3LL phishing-as-a-service ecosystem enabled large-scale Microsoft 365 account compromise through session hijacking techniques that bypassed multi-factor authentication. Infrastructure components supported credential theft campaigns affecting over 500 operators across multiple regions.

The PowMix botnet targeted Czech organisations using phishing archives containing LNK-based loaders and PowerShell execution chains. Command-and-control traffic was concealed through encrypted REST-like paths and cloud-based infrastructure supporting dynamic updates.

The McGraw Hill Salesforce breach exposed 13.5 million user records through a misconfigured environment exploited by ShinyHunters. Stolen datasets included personal identifiers and contact information later leaked after attempted extortion.

The Sapphire Sleet macOS campaign delivered fake Zoom update scripts that executed credential-harvesting payloads and established persistence via system services. Exfiltration channels included Telegram APIs and targeted browser, wallet, and keychain data.

Attackers leveraged QEMU virtual machines to hide ransomware activity and maintain covert access to compromised environments. The technique supported credential harvesting, internal reconnaissance, and deployment of PayoutsKing ransomware across affected networks.

Highlights of the Day

UAC-0247 Targets Ukrainian Clinics with Multi-Stage Data Theft Malware

CERT-UA reported UAC-0247 campaigns between March and April 2026 targeting Ukrainian government and healthcare entities using phishing emails linking to compromised or AI-generated sites delivering LNK and HTA-based malware loaders. The infection chain deploys tools including RAVENSHELL, AGINGFLY, and SILENTLOOP to establish command execution, maintain persistence, and retrieve C2 infrastructure details via Telegram and alternative mechanisms. The attacks enable credential theft from Chromium browsers and WhatsApp, alongside reconnaissance and lateral movement using tools such as ChromElevator, ZAPiXDESK, RustScan, and tunnelling utilities.

W3LL Phishing Platform Enabled Global BEC Attacks

Group-IB detailed a seven-year operation by threat actor W3LL, who built a phishing-as-a-service ecosystem including the W3LL Panel and W3LL Store used by over 500 criminals to compromise Microsoft 365 accounts. The AiTM-enabled phishing kit bypassed multi-factor authentication by hijacking session cookies, while associated infrastructure, Telegram groups, and over 700 malicious attachments supported credential theft and large-scale BEC campaigns. Investigators linked backend servers, underground accounts, and operational data to identify more than 500 victims and trace the actor’s activities from 2017 through law enforcement disruption efforts.

Source: Group-IB

PowMix Botnet Targets Czech Workforce via Phishing Campaign

Cisco Talos identified a campaign active since December 2025 targeting Czech organisations with the previously undocumented PowMix botnet, delivered through phishing ZIP archives containing LNK-triggered PowerShell loaders that bypass AMSI protections. The malware executes in memory, establishes persistence via scheduled tasks, and uses XOR-encrypted configurations, CRC32-based bot IDs, and Heroku-hosted infrastructure to manage command-and-control communications. PowMix employs randomised beaconing intervals and REST-like URL paths embedding encrypted host data, enabling remote command execution, reconnaissance, and dynamic C2 domain updates while evading network detection.

Cargo Theft Actor Uses Signed Tools to Maintain Network Access

Proofpoint observed a cargo theft threat actor maintaining access for over a month after compromising transportation targets via load board phishing emails delivering VBS payloads that installed ScreenConnect remote access tools. The attacker deployed multiple RMM platforms including Pulseway and SimpleHelp, and used a signing-as-a-service platform to re-sign malware components with valid certificates to evade detection and bypass revoked signatures. Post-compromise activity included PowerShell-based reconnaissance of financial systems, browser data extraction, cryptocurrency wallet targeting, and exfiltration of host intelligence to Telegram channels.

Source: Proofpoint

McGraw Hill Breach Exposes 13.5 Million User Records

ShinyHunters breached McGraw Hill’s Salesforce environment in April 2026 by exploiting a misconfiguration, exfiltrating data later leaked online affecting approximately 13.5 million user accounts. The exposed dataset, exceeding 100GB, includes email addresses, names, phone numbers, and physical addresses obtained from a webpage hosted on the Salesforce platform. McGraw Hill stated the incident did not impact its core systems or databases, while the threat group initially claimed to have stolen up to 45 million records and attempted extortion.

AI Code Reviewers Tricked by Spoofed Git Commit Identities

Manifold researchers demonstrated that AI-powered GitHub workflows such as Claude Code can be bypassed by spoofing commit author identities using simple Git configuration changes, enabling malicious pull requests to be auto-approved and merged. The attack chain used a malicious SKILL.md file placed in IDE directories to instruct coding agents to exfiltrate sensitive data such as .env contents to attacker-controlled infrastructure. Analysis identified over 12,400 public repositories referencing Claude-based workflows where trust decisions rely on unsigned metadata, exposing CI/CD pipelines and developer environments to supply chain compromise.

Source: Manifold

APT36 Uses AI-Generated “Vibeware” to Evade Detection

ReversingLabs reported that APT36 is using AI-driven “vibeware” to generate large volumes of malware implants written in niche languages such as Nim, Zig, and Crystal to evade traditional detection systems. The campaign deploys multiple implants per target with varied command-and-control channels using platforms like Slack, Discord, Supabase, and Google Sheets, enabling persistence and redundancy across infected endpoints. Researchers observed the strategy overwhelms detection systems by producing diverse, low-quality variants that bypass signature-based tools and complicate incident response efforts.

North Korean Hackers Target macOS with Fake Zoom Updates

Microsoft identified a macOS campaign by North Korean actor Sapphire Sleet using social engineering, where victims run a malicious Zoom SDK Update.scpt AppleScript that triggers multi-stage payload delivery via curl-to-osascript chains. The attack deploys components including a com.apple.cli monitor, services backdoor, and credential-harvesting systemupdate.app that presents fake password prompts and exfiltrates validated credentials through the Telegram Bot API. The malware bypasses macOS TCC protections by modifying the TCC database, establishes persistence using launch daemons, and exfiltrates browser data, cryptocurrency wallets, keychains, SSH keys, and Telegram sessions to attacker-controlled infrastructure.

Source: Microsoft

Attackers Use QEMU VMs to Hide Ransomware Activity

Sophos identified two campaigns, STAC4713 and STAC3725, where attackers abused QEMU virtual machines to conceal malicious activity, establish reverse SSH tunnels, harvest credentials, and deploy ransomware including PayoutsKing. In STAC4713, attackers used scheduled tasks to launch hidden QEMU VMs with disguised disk images, enabling covert access and data theft via tools like AdaptixC2, Chisel, and Rclone. In STAC3725, threat actors exploited CitrixBleed2 and deployed ScreenConnect alongside QEMU-based environments running tools such as Impacket, BloodHound, and Kerbrute for Active Directory reconnaissance and credential extraction.

Source: Sophos

Daily Coverage

Developments
Ukraine Clinic TargetingW3Ll TakedownPowmix BotnetMcgraw Hill Breach
Vulnerabilities
CVE-2026-34197Apache Activemq Broker (High)CVE-2024-3721Dvr-4104 20240412 (Medium)CVE-2017-17215CVE-2026-33825Microsoft Defender Antimalware Platform 4.0.0.0 (High)
Threat Groups
Sapphire SleetAPT38 is a North Korean statesponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.APT36Transparent Tribe is a suspected Pakistanbased threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.