Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (17 April 2026)
Published: Loading…
At a Glance
- UAC-0247 targeted Ukrainian government clinics and hospitals using phishing campaigns delivering multi-stage malware for browser credential theft and WhatsApp data exfiltration.
- W3LL phishing-as-a-service platform enabled over 500 actors to compromise Microsoft 365 accounts globally by bypassing multi-factor authentication through session cookie theft.
- PowMix botnet targeted Czech organisations using phishing ZIP files with LNK loaders, establishing encrypted command-and-control channels via Heroku infrastructure.
- ShinyHunters breached McGraw Hill Salesforce environment, exposing 13.5 million user records including emails, phone numbers, and physical addresses through misconfiguration.
- Sapphire Sleet macOS campaign used fake Zoom updates to deploy credential-stealing malware with Telegram exfiltration and persistence via launch daemons.
- Attackers abused QEMU virtual machines to conceal ransomware operations, enabling covert persistence, credential harvesting, and deployment of PayoutsKing ransomware.
Summary
UAC-0247 conducted phishing operations against Ukrainian government healthcare institutions, deploying multi-stage malware focused on browser credential theft and messaging data extraction. The campaign used LNK and HTA loaders with supporting tools for persistence and lateral movement across affected systems.
The W3LL phishing-as-a-service ecosystem enabled large-scale Microsoft 365 account compromise through session hijacking techniques that bypassed multi-factor authentication. Infrastructure components supported credential theft campaigns affecting over 500 operators across multiple regions.
The PowMix botnet targeted Czech organisations using phishing archives containing LNK-based loaders and PowerShell execution chains. Command-and-control traffic was concealed through encrypted REST-like paths and cloud-based infrastructure supporting dynamic updates.
The McGraw Hill Salesforce breach exposed 13.5 million user records through a misconfigured environment exploited by ShinyHunters. Stolen datasets included personal identifiers and contact information later leaked after attempted extortion.
The Sapphire Sleet macOS campaign delivered fake Zoom update scripts that executed credential-harvesting payloads and established persistence via system services. Exfiltration channels included Telegram APIs and targeted browser, wallet, and keychain data.
Attackers leveraged QEMU virtual machines to hide ransomware activity and maintain covert access to compromised environments. The technique supported credential harvesting, internal reconnaissance, and deployment of PayoutsKing ransomware across affected networks.
Highlights of the Day
UAC-0247 Targets Ukrainian Clinics with Multi-Stage Data Theft Malware
CERT-UA reported UAC-0247 campaigns between March and April 2026 targeting Ukrainian government and healthcare entities using phishing emails linking to compromised or AI-generated sites delivering LNK and HTA-based malware loaders. The infection chain deploys tools including RAVENSHELL, AGINGFLY, and SILENTLOOP to establish command execution, maintain persistence, and retrieve C2 infrastructure details via Telegram and alternative mechanisms. The attacks enable credential theft from Chromium browsers and WhatsApp, alongside reconnaissance and lateral movement using tools such as ChromElevator, ZAPiXDESK, RustScan, and tunnelling utilities.
W3LL Phishing Platform Enabled Global BEC Attacks
Group-IB detailed a seven-year operation by threat actor W3LL, who built a phishing-as-a-service ecosystem including the W3LL Panel and W3LL Store used by over 500 criminals to compromise Microsoft 365 accounts. The AiTM-enabled phishing kit bypassed multi-factor authentication by hijacking session cookies, while associated infrastructure, Telegram groups, and over 700 malicious attachments supported credential theft and large-scale BEC campaigns. Investigators linked backend servers, underground accounts, and operational data to identify more than 500 victims and trace the actor’s activities from 2017 through law enforcement disruption efforts.
PowMix Botnet Targets Czech Workforce via Phishing Campaign
Cisco Talos identified a campaign active since December 2025 targeting Czech organisations with the previously undocumented PowMix botnet, delivered through phishing ZIP archives containing LNK-triggered PowerShell loaders that bypass AMSI protections. The malware executes in memory, establishes persistence via scheduled tasks, and uses XOR-encrypted configurations, CRC32-based bot IDs, and Heroku-hosted infrastructure to manage command-and-control communications. PowMix employs randomised beaconing intervals and REST-like URL paths embedding encrypted host data, enabling remote command execution, reconnaissance, and dynamic C2 domain updates while evading network detection.
Cargo Theft Actor Uses Signed Tools to Maintain Network Access
Proofpoint observed a cargo theft threat actor maintaining access for over a month after compromising transportation targets via load board phishing emails delivering VBS payloads that installed ScreenConnect remote access tools. The attacker deployed multiple RMM platforms including Pulseway and SimpleHelp, and used a signing-as-a-service platform to re-sign malware components with valid certificates to evade detection and bypass revoked signatures. Post-compromise activity included PowerShell-based reconnaissance of financial systems, browser data extraction, cryptocurrency wallet targeting, and exfiltration of host intelligence to Telegram channels.
McGraw Hill Breach Exposes 13.5 Million User Records
ShinyHunters breached McGraw Hill’s Salesforce environment in April 2026 by exploiting a misconfiguration, exfiltrating data later leaked online affecting approximately 13.5 million user accounts. The exposed dataset, exceeding 100GB, includes email addresses, names, phone numbers, and physical addresses obtained from a webpage hosted on the Salesforce platform. McGraw Hill stated the incident did not impact its core systems or databases, while the threat group initially claimed to have stolen up to 45 million records and attempted extortion.
AI Code Reviewers Tricked by Spoofed Git Commit Identities
Manifold researchers demonstrated that AI-powered GitHub workflows such as Claude Code can be bypassed by spoofing commit author identities using simple Git configuration changes, enabling malicious pull requests to be auto-approved and merged. The attack chain used a malicious SKILL.md file placed in IDE directories to instruct coding agents to exfiltrate sensitive data such as .env contents to attacker-controlled infrastructure. Analysis identified over 12,400 public repositories referencing Claude-based workflows where trust decisions rely on unsigned metadata, exposing CI/CD pipelines and developer environments to supply chain compromise.
APT36 Uses AI-Generated “Vibeware” to Evade Detection
ReversingLabs reported that APT36 is using AI-driven “vibeware” to generate large volumes of malware implants written in niche languages such as Nim, Zig, and Crystal to evade traditional detection systems. The campaign deploys multiple implants per target with varied command-and-control channels using platforms like Slack, Discord, Supabase, and Google Sheets, enabling persistence and redundancy across infected endpoints. Researchers observed the strategy overwhelms detection systems by producing diverse, low-quality variants that bypass signature-based tools and complicate incident response efforts.
North Korean Hackers Target macOS with Fake Zoom Updates
Microsoft identified a macOS campaign by North Korean actor Sapphire Sleet using social engineering, where victims run a malicious Zoom SDK Update.scpt AppleScript that triggers multi-stage payload delivery via curl-to-osascript chains. The attack deploys components including a com.apple.cli monitor, services backdoor, and credential-harvesting systemupdate.app that presents fake password prompts and exfiltrates validated credentials through the Telegram Bot API. The malware bypasses macOS TCC protections by modifying the TCC database, establishes persistence using launch daemons, and exfiltrates browser data, cryptocurrency wallets, keychains, SSH keys, and Telegram sessions to attacker-controlled infrastructure.
Attackers Use QEMU VMs to Hide Ransomware Activity
Sophos identified two campaigns, STAC4713 and STAC3725, where attackers abused QEMU virtual machines to conceal malicious activity, establish reverse SSH tunnels, harvest credentials, and deploy ransomware including PayoutsKing. In STAC4713, attackers used scheduled tasks to launch hidden QEMU VMs with disguised disk images, enabling covert access and data theft via tools like AdaptixC2, Chisel, and Rclone. In STAC3725, threat actors exploited CitrixBleed2 and deployed ScreenConnect alongside QEMU-based environments running tools such as Impacket, BloodHound, and Kerbrute for Active Directory reconnaissance and credential extraction.
Daily Coverage