← Carolina Clear Tech

Cyber Threat Brief

2026-02-11

Listen to this brief (20:44)

Download MP3
Show Notes

Show Notes - 2026-02-11

Stories Covered

CVEs Referenced

CVE-2026-20841

Indicators of Compromise

Domains: vercel[.]app

Hashes: f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-02-11

Collected: 2026-02-11 11:12 PM EST Generated by: Claude Code (Opus 4.6)


Critical Alerts

Notepad++ Supply Chain Compromise by Lotus Blossom (State-Sponsored)

Between June and December 2025, the state-sponsored threat group Lotus Blossom compromised the official Notepad++ hosting infrastructure, hijacking the update server to deliver malicious NSIS installers to targeted users. Two infection chains were observed: DLL sideloading via a legitimate Bitdefender component (BluetoothService.exe loading log.dll) to deploy the Chrysalis backdoor, and a Lua script injection variant delivering Cobalt Strike Beacon. Targets span government, telecom, energy, financial, manufacturing, cloud hosting, and software development sectors across Southeast Asia, South America, the U.S., and Europe.

Notepad Markdown RCE - CVE-2026-20841 (CVSS 8.8)

Microsoft's Markdown rendering feature in Notepad contains a remote code execution vulnerability. An attacker can embed a malicious link in a Markdown file; when a user opens the file in Notepad and clicks the link, it launches unverified protocols that load and execute files with the user's permissions. Patched in the February 2026 Patch Tuesday update. No known exploitation in the wild.

Microsoft Outlook Add-in (AgreeTo) Hijacked - 4,000+ Credentials Stolen

An abandoned Outlook add-in called AgreeTo, listed on Microsoft's official Office Add-in Store since December 2022, was hijacked by a threat actor who claimed its orphaned Vercel-hosted URL (outlook-one.vercel[.]app). The attacker deployed a fake Microsoft sign-in page that harvested over 4,000 Microsoft account credentials, credit card numbers, and banking security answers. Data was exfiltrated via Telegram bot API. The add-in retained ReadWriteItem permissions, giving it access to read and modify user emails. Microsoft has now removed the add-in. This is the first malware found on the official Microsoft Marketplace and the first malicious Outlook add-in detected in the wild.


Vulnerability Disclosures

Chipmaker Patch Tuesday: 80+ Vulnerabilities from Intel and AMD

Intel and AMD published over two dozen advisories covering more than 80 vulnerabilities across their product lines as part of their February 2026 coordinated disclosures.

Microsoft Secure Boot Certificate Refresh - June 2026

The current Windows Secure Boot certificates, in service for over 15 years, will expire. Microsoft plans to roll out new certificates in June 2026.


Ransomware & Extortion

LummaStealer Resurges via CastleLoader and ClickFix Campaigns (Reported by 3 Sources)

LummaStealer (LummaC2) has scaled significantly between December 2025 and January 2026 after partially recovering from the May 2025 law enforcement takedown of 2,300 domains. The current delivery mechanism uses CastleLoader, a heavily obfuscated AutoIT/Python-based loader that executes LummaStealer entirely in memory. Distribution relies on the ClickFix technique: fake CAPTCHA pages trick users into running a malicious PowerShell command already placed in their clipboard. CastleLoader performs sandbox detection, adjusts persistence paths based on detected security products, and uses a deliberate failed DNS lookup as a C2 artifact. A separate campaign uses RenEngine, a modified Ren'Py game launcher, to deliver HijackLoader and ultimately ACR Stealer or LummaStealer via pirated game downloads.


MSP / SMB Threats

Payroll Redirect Attacks via Help Desk Social Engineering

Binary Defense documented a campaign where attackers compromise shared mailbox credentials, use them to identify employees, then call the help desk impersonating a locked-out physician to get password and MFA resets. After gaining access, the attacker authenticates via the organization's own VDI (bypassing security detections as a trusted internal user), registers new MFA devices, and redirects payroll direct deposits in Workday. Microsoft separately documented a variant using adversary-in-the-middle phishing to steal MFA codes and compromise Workday profiles at universities.

JokerOTP MFA Bypass Tool - Third Arrest

Dutch police arrested a 21-year-old suspected of selling access to JokerOTP, a phishing-as-a-service platform that intercepts one-time passwords via automated phone calls. The service caused $10M+ in losses across 28,000 attacks in 13 countries over two years, targeting PayPal, Venmo, Coinbase, Amazon, and Apple accounts. Three suspects have now been arrested. Dozens of Dutch buyers have been identified and will be prosecuted.


Windows / AD Security

WSL Being Used as a Malware Attack Vector

SANS ISC documented a malware sample (OtterCookie socketScript module 3, SHA256: f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370) that actively checks for Windows Subsystem for Linux and uses it as an attack surface. The JavaScript-based Cryxos trojan/infostealer detects WSL via WSL_DISTRO_NAME env variable and /proc/version, then accesses the Windows filesystem through /mnt/ to steal browser data. WSL functions similarly to a LOLBIN: it's a Microsoft-shipped feature that allows execution of Linux binaries, and attackers can drop tools into the WSL rootfs via \\wsl$ and execute them from Windows.

Windows 11 26H1 Released (Snapdragon X2 Only), .NET 3.5 Removed

Windows 11 26H1 is available exclusively for new Qualcomm Snapdragon X2 hardware. Microsoft explicitly states versions 24H2 and 25H2 remain the recommended enterprise releases. .NET Framework 3.5 has been removed as a Windows Feature on Demand in 26H1; it must now be installed via standalone installer. .NET 3.5 end of support is January 9, 2029.

SSH Worm Compromises Systems in 4 Seconds

SANS ISC captured a complete SSH worm attack from brute-force to full botnet enrollment in under 4 seconds. The worm targets default Raspberry Pi credentials (pi/raspberry variants), uploads a 4.7KB bash script, establishes persistence, kills competing malware, joins IRC C2 channels with cryptographically signed command verification, and begins lateral movement using Zmap and sshpass to scan 100,000 random IPs for SSH. The attack originated from an already-compromised Raspberry Pi (SSH client string: SSH-2.0-OpenSSH_8.4p1 Raspbian-5+b1).


General Security News

Kimwolf IoT Botnet Disrupts I2P Anonymity Network

The Kimwolf botnet, which has infected millions of IoT devices since late 2025, attempted to join 700,000 infected devices as nodes on the I2P anonymity network to create a takedown-resistant C2 infrastructure. This Sybil attack overwhelmed I2P's 15,000-20,000 legitimate nodes, causing widespread service disruption. The botnet operators are also experimenting with Tor as backup C2.

287 Chrome Extensions Exfiltrating Browsing History (37M Installs)

A security researcher identified 287 Chrome extensions with a combined 37.4 million installations that exfiltrate browsing history to data brokers including Similarweb, Semrush, Alibaba Group, and ByteDance. The extensions present as harmless tools while requesting access to browsing history. An automated testing pipeline confirmed data leakage to 30+ collection entities.

SSHStalker Botnet Targets Linux via IRC C2

A new botnet called SSHStalker uses IRC for command and control and targets Linux systems via legacy kernel exploits. The toolset includes log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts.

Microsoft Warns of AI Recommendation Poisoning

Microsoft's Defender team documented "AI Recommendation Poisoning," where businesses embed hidden prompts in "Summarize with AI" buttons and links on websites to manipulate AI model outputs. They identified 50+ unique malicious prompts from 31 companies across 14 industries. This extends to "AI Memory Poisoning," where injected instructions persist across future AI responses.


Trends & Context

Supply chain attacks through trusted distribution channels dominate today's brief: Notepad++ update infrastructure hijacked by state actors, an Outlook add-in weaponized via abandoned domain takeover on the official Microsoft Marketplace, and 287 Chrome extensions harvesting data at scale. All three exploit the gap between initial platform approval and ongoing content monitoring. Infostealers (LummaStealer, CastleLoader, OtterCookie, ACR Stealer) continue to rebuild and diversify delivery methods after law enforcement disruptions, with ClickFix social engineering proving especially effective at getting users to infect their own machines. The payroll redirect and JokerOTP cases reinforce that identity verification processes, not just technical controls, remain the weakest link.


Carolina Clear Tech, LLC - carolinacleartech.com