CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (22 April 2026)

Published: Loading…

At a Glance

  • Scattered Spider member pleaded guilty to wire fraud conspiracy from 2022 SMS phishing enabling SIM-swapping crypto theft exceeding eight million dollars.
  • Mustang Panda deployed updated LOTUSLITE backdoor via CHM phishing and Microsoft-signed DLL sideloading targeting Indian banking sector and Korean policy entities.
  • NGate Android malware variant uses trojanised HandyPay NFC application to steal payment card data and PINs in Brazil campaign.
  • Microsoft GitHub Windows-driver-samples repository workflow flaw enables remote code execution via unsanitised issue body injection into Python script.
  • CISA added eight actively exploited vulnerabilities affecting Cisco SD-WAN, Zimbra, and other platforms, enforcing federal remediation deadlines under KEV programme.

Summary

Scattered Spider member pleaded guilty to wire fraud conspiracy from 2022 SMS phishing enabling SIM-swapping cryptocurrency theft exceeding eight million dollars. The campaign targeted major technology platforms using credential harvesting techniques. Stolen access enabled cryptocurrency diversion through mobile number takeover.

CISA added eight actively exploited vulnerabilities to its KEV catalogue, including Cisco Catalyst SD-WAN Manager, Zimbra, Kentico, and PaperCut flaws requiring urgent remediation across federal systems. The update includes multiple vendors with confirmed exploitation across enterprise environments. Federal agencies face mandated deadlines for patch deployment under KEV requirements.

Microsoft GitHub Windows-driver-samples workflow flaw enables remote code execution through unsanitised issue body injection into Python execution context on GitHub Actions runners exposing repository secrets. The vulnerability allows unauthorised code execution within CI pipelines. Repository secrets are at risk of exposure through compromised workflow execution.

Google Antigravity IDE flaw combines prompt injection and unsafe file search handling to achieve remote code execution and sandbox escape within agentic development environment. The issue impacts tool execution chains within the IDE. Sandbox protections are bypassed through native tool call exploitation.

Mustang Panda deployed updated LOTUSLITE backdoor through CHM phishing and DLL sideloading using Microsoft-signed executables to target Indian banking and Korean policy sectors. The campaign uses dynamic DNS infrastructure for command-and-control communication. Execution chains rely on legitimate signed binaries for payload delivery.

North Korea-linked Void Dokkaebi operation spreads malware via compromised code repositories, injecting malicious VS Code tasks and committing infected configuration files across developer platforms. The campaign propagates through developer workflows and source control systems. Over 750 repositories have been affected across multiple platforms.

NGate Android malware abuses trojanised HandyPay NFC application to steal payment card data and PINs in Brazil contactless fraud campaign. The malware relays NFC data to attacker-controlled infrastructure. PIN exfiltration supports unauthorised transaction authorisation.

Former ransomware negotiator Angelo Martino pleaded guilty to assisting BlackCat ransomware attacks against US companies while working within cyber incident response industry. The scheme involved facilitating extortion operations during negotiation processes. Insider access was leveraged for ransomware campaign support.

Phishing campaigns increasingly leverage valid credentials and MFA workflow exploitation, using trusted accounts to deliver internal-style business email lures and credential harvesting attacks. Attackers rely on compromised identity trust to bypass security controls. Business communication patterns are used for malicious message delivery.

Cloud platform Vercel confirmed breach involving third-party tool compromise and OAuth abuse, leading to credential exposure affecting a limited subset of customers. Attackers exploited connected application permissions for access. OAuth token misuse enabled unauthorised data exposure.

North Korea’s Lazarus Group attributed to $290 million KelpDAO crypto theft, exploiting blockchain routing dependencies and triggering failover to poisoned infrastructure nodes. The attack targeted decentralised finance routing mechanisms. Compromised infrastructure nodes facilitated transaction manipulation.

Healthcare data breaches affecting multiple US organisations exposed records of approximately 600,000 individuals amid ransomware-related intrusions and credential-based network access incidents. Sensitive patient data was accessed through compromised credentials. Multiple healthcare providers reported coordinated intrusion activity.

Highlights of the Day

CISA Adds Eight Actively Exploited Vulnerabilities to KEV Catalogue

CISA added eight vulnerabilities to its Known Exploited Vulnerabilities catalogue, including flaws affecting PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra, and Cisco Catalyst SD-WAN Manager. The listed issues include improper authentication, path traversal, cross-site scripting, and sensitive information exposure vulnerabilities, all confirmed to be actively exploited in the wild. The update follows Binding Operational Directive 22-01, which mandates remediation deadlines for US federal agencies to address vulnerabilities posing significant risk to federal networks.

NGate Malware Variant Uses Trojanised NFC App to Steal Cards

ESET researchers identified a new NGate malware variant that abuses a trojanised version of the legitimate Android NFC relay app HandyPay to capture and transmit payment card data. The malware relays NFC data from victims’ cards to attacker-controlled devices for contactless ATM withdrawals and payments, while separately capturing PIN codes and exfiltrating them to a command-and-control server over HTTP. The campaign, active since November 2025 and targeting Android users in Brazil, distributes the malicious app via a fake lottery website and a counterfeit Google Play page hosting download links.

Prompt Injection Flaw Enables RCE in Google Antigravity IDE

Pillar Security researchers discovered a prompt injection vulnerability in Google’s Antigravity agentic IDE, where the find_by_name tool passes unsanitised input to the fd utility, enabling command injection. Attackers can exploit the Pattern parameter using the -X flag to execute arbitrary code, staging payloads within the workspace and triggering execution without additional user interaction. The flaw bypasses Antigravity Secure Mode protections because native tool calls execute before sandbox restrictions, enabling remote code execution and sandbox escape even under the strictest configuration.

Void Dokkaebi Spreads Malware Through Infected Code Repositories

Trend Micro reports that North Korea-linked Void Dokkaebi targets developers with fake job interviews, tricking them into running malicious repositories that deploy malware via VS Code tasks and injected JavaScript. Compromised machines propagate the attack by committing infected .vscode configurations and obfuscated code into repositories, enabling worm-like spread across GitHub, GitLab, Bitbucket, and downstream projects. Analysis identified over 750 infected repositories, malicious commit tampering tools, and blockchain-based payload delivery retrieving and executing malware such as DEV#POPPER RAT from Tron, Aptos, and Binance Smart Chain.

GitHub Workflow Flaw Enabled RCE in Microsoft Sample Repo

Tenable researchers disclosed a critical vulnerability in Microsoft’s Windows-driver-samples GitHub repository, where a GitHub Actions workflow improperly interpolated user-controlled issue content into a Python script without sanitisation. Attackers could inject arbitrary Python code via crafted issue bodies, enabling remote code execution on the GitHub runner and access to repository secrets. Microsoft confirmed and patched the issue in March 2026 after responsible disclosure, addressing the insecure handling of untrusted input in the workflow configuration.

Source: Tenable

Mustang Panda Targets Banks With Updated LOTUSLITE Backdoor

Acronis researchers identified a new LOTUSLITE backdoor variant attributed to Mustang Panda, delivered via spear-phishing CHM files that deploy malware using JavaScript loaders and DLL sideloading through a Microsoft-signed executable. The implant communicates with command-and-control servers over HTTPS using dynamic DNS infrastructure, providing remote shell access, file operations, and session management capabilities. The campaign targets India’s banking sector and Korean policy entities, with updated code including modified packet signatures, API resolution techniques, and persistence mechanisms while maintaining core command structures from earlier LOTUSLITE versions.

Scattered Spider Member Pleads Guilty to Phishing and Crypto Theft

A British national linked to the Scattered Spider cybercrime group pleaded guilty to wire fraud conspiracy and aggravated identity theft tied to large-scale SMS phishing attacks in 2022. The campaign targeted companies including Twilio, LastPass, DoorDash, and Mailchimp, enabling intrusions that supported SIM-swapping operations and cryptocurrency theft totalling at least $8 million. Investigators linked the suspect to phishing infrastructure through domain registrations and seized devices containing stolen data, with sentencing scheduled for August 2026.

Daily Coverage

Developments
Scattered Spider PleaLotuslite BackdoorNgate Nfc FraudGithub Rce Flaw
Vulnerabilities
CVE-2025-29635CVE-2026-5752CVE-2026-40372CVE-2026-21876CVE-2025-48700N/A N/A (Medium)
Threat Groups
Mustang PandaMustang Panda is a Chinabased cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and nongovernmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.DEV#POPPERContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.