CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (25 April 2026)

Published: Loading…

At a Glance

  • FIRESTARTER backdoor malware infected a US federal agency's Cisco Firepower device in September 2025, surviving subsequent security patches and firmware updates.
  • Bitwarden CLI npm package was compromised in a Checkmarx-linked supply chain attack delivering the Shai-Hulud worm to steal developer credentials.
  • Operation TrustTrap used over 16,800 malicious domains embedding government labels in subdomains to harvest credentials from fake US, Indian, and UK portals.
  • Medical data belonging to 500,000 UK Biobank volunteers was listed for sale on Chinese e-commerce platform Alibaba following unauthorised researcher access.
  • A large-scale OAuth device code phishing campaign abused Kali365 infrastructure to compromise Microsoft 365 accounts across North America and EMEA in April 2026.
  • Tropic Trooper deployed a trojanised SumatraPDF loader to execute AdaptixC2 Beacon agents, using GitHub repositories for encrypted command-and-control communications.

Summary

FIRESTARTER backdoor malware compromised a US federal Cisco Firepower device running ASA software in September 2025, maintaining persistent remote access through subsequent patches. CISA and the UK NCSC issued a joint advisory confirming the backdoor's ability to re-establish access without re-exploiting the original vulnerabilities. The activity is attributed to UAT-4356, previously linked to the ArcaneDoor espionage campaign targeting network perimeter devices.

The Bitwarden CLI npm package was compromised as part of a Checkmarx-linked supply chain attack deploying the Shai-Hulud self-propagating worm, stealing SSH keys, cloud credentials, and developer tokens. Three separate supply chain attacks struck npm, PyPI, and Docker Hub within a 48-hour window, with each campaign targeting CI/CD pipeline secrets and API keys. The Checkmarx KICS Docker images and VS Code extensions were also compromised in the same campaign cluster.

Operation TrustTrap deployed over 16,800 malicious domains using embedded government labels in subdomains to impersonate DMV, toll, and registration portals across the US, India, Vietnam, and UK. Infrastructure was concentrated on Tencent Cloud and Alibaba Cloud nodes, with more than 62 percent of domains initially undetected on VirusTotal. An infrastructure cluster within the dataset showed activity consistent with APT36 targeting Indian government entities.

Tropic Trooper distributed a trojanised SumatraPDF loader executing AdaptixC2 Beacon agents in memory, using GitHub repository issues and file uploads for encrypted command-and-control. Post-compromise activity included reconnaissance commands, scheduled tasks, and deployment of VS Code tunnels for remote access. A large-scale OAuth device code phishing campaign separately abused Kali365 infrastructure to compromise Microsoft 365 accounts and register attacker-controlled devices for persistence across North America and EMEA.

Medical data belonging to 500,000 UK Biobank volunteers, including genetic sequences, blood samples, and health records, was listed for sale on Alibaba following access by a researcher operating under a legitimate contract. ADT confirmed a separate data breach after the ShinyHunters extortion group threatened to leak stolen customer information unless a ransom was paid. A French court separately sentenced a 20-year-old suspect using the alias HexDex for breaches affecting sports organisations, with stolen data posted to BreachForum and Darkforum.

A newly disclosed Windows RPC architectural flaw dubbed PhantomRPC allows processes with SeImpersonatePrivilege to escalate to SYSTEM-level access across modern Windows Server versions, with no patch or CVE currently assigned. The LMDeploy SSRF vulnerability CVE-2026-33626 was actively exploited within 13 hours of public disclosure, targeting the open-source LLM deployment toolkit. CISA added 10 vulnerabilities to its Known Exploited Vulnerabilities catalogue this week, with 111 critical-rated flaws disclosed across enterprise software and cloud services.

Highlights of the Day

Early FAST16 Malware Targeted Engineering Software for Sabotage

SentinelOne researchers identified a malware sample named FAST16, likely developed around 2005, designed to run on Windows XP systems and deploy a driver that alters floating-point calculations. The malware specifically searches for and interferes with high-precision engineering and simulation tools including LS-DYNA 970, PKPM, and the MOHID hydrodynamic modelling platform. Analysis indicates it attempted to introduce calculation errors in domains such as structural analysis and environmental modelling, with code suggesting deliberate industrial sabotage capabilities predating Stuxnet.

PhantomRPC Flaw Enables Windows Privilege Escalation via RPC Spoofing

Kaspersky researchers disclosed a Windows RPC architectural flaw dubbed PhantomRPC that allows processes with SeImpersonatePrivilege to escalate privileges to SYSTEM by impersonating high-privileged clients. The technique exploits RPC calls to unavailable services by deploying malicious servers that mimic legitimate endpoints such as TermService, enabling impersonation through high-level RPC requests. Multiple exploitation paths were demonstrated across services including Group Policy, Edge, WDI, DHCP, and Windows Time, affecting modern Windows Server versions without a patch or CVE assignment.

Source: Kaspersky

Tropic Trooper Uses GitHub for Covert AdaptixC2 Operations

Zscaler ThreatLabz observed Tropic Trooper distributing a trojanised SumatraPDF loader that downloads decoy documents while executing an AdaptixC2 Beacon agent in memory using AES-128 encrypted shellcode. The malware leverages a custom GitHub-based command-and-control channel, using repository issues and file uploads to exchange encrypted tasks and exfiltrated data, with rapid deletion of artefacts to evade analysis. Researchers also identified post-compromise activity including reconnaissance commands, scheduled tasks, and deployment of VS Code tunnels for remote access, alongside infrastructure hosting EntryShell and Cobalt Strike payloads.

Source: Zscaler

TrustTrap Campaign Uses 16,800 Domains to Spoof Government Portals

Cyble researchers identified Operation TrustTrap, a phishing campaign using over 16,800 domains that embed “.gov” tokens in subdomains to impersonate government services across the United States, India, Vietnam, and UK-related targets. The infrastructure, largely hosted on Tencent Cloud and Alibaba Cloud, delivers fake DMV, toll, and registration portals designed to harvest credentials and payment data, with more than 62 percent initially undetected on VirusTotal. Analysis revealed domain obfuscation techniques including subdomain injection and hyphen manipulation, rapid domain rotation, and an infrastructure cluster with activity consistent with APT36 targeting Indian government entities.

Source: Cyble

Device Code Phishing Campaign Exploits OAuth Tokens via Kali365

Arctic Wolf reported a large-scale April 2026 campaign abusing OAuth device code flow to trick users into authorising attacker-initiated sessions, granting access and refresh tokens for Microsoft 365 accounts. The operation used Kali365 Live phishing-as-a-service infrastructure with Cloudflare-hosted lures, capturing tokens and enabling mailbox access, inbox rule manipulation, and device registration for persistence. Researchers linked activity to shared TLS infrastructure across multiple servers and observed token reuse, multi-tenant affiliate operations, and post-compromise actions across sectors in North America and EMEA.

Daily Coverage

Developments
Firestarter Cisco BackdoorBitwarden Cli CompromiseOperation TrusttrapUk Biobank Data Sale
Vulnerabilities
CVE-2024-57726CVE-2026-33626Lmdeploy < 0.12.3 (High)
Threat Groups
APT36Transparent Tribe is a suspected Pakistanbased threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.Tropic TrooperTropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and hightech industries and has been active since 2011.