← Carolina Clear Tech

Cyber Threat Brief

2026-02-15

Show Notes

Show Notes - 2026-02-15

Stories Covered

CVEs Referenced

CVE-2025-24799, CVE-2026-1281, CVE-2026-1340, CVE-2026-21962, CVE-2026-24061

Indicators of Compromise

Domains: 193[.]24, 123[.]42, azwsappdev[.]com, healgeni[.]live, authentication-check[.]io, setuptransactioncheck[.]com

IP Addresses: 12.8.0.0, 12.5.1.0, 12.6.1.0

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - February 15, 2026

Generated: 2026-02-15 | Sources: 13 articles from 6 feeds


Critical Alerts

Single Threat Actor Driving 83% of Ivanti EPMM Exploitation (CVE-2026-1281, CVE-2026-1340, CVE-2026-24061)

GreyNoise identified a single IP address (193[.]24[.]123[.]42) hosted on bulletproof infrastructure (PROSPERO OOO, AS200593) responsible for 83% of active exploitation against two critical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile. Between February 1-9, 417 exploitation sessions were recorded from 8 unique source IPs, with a massive spike of 269 sessions on February 8 alone. CVE-2026-24061 is on the CISA KEV list with a remediation deadline of February 16 (tomorrow) and carries an EPSS of 0.839 (99th percentile). CVE-2026-1281 is also on the KEV list (deadline passed 2026-02-01, EPSS 0.543, 98th percentile). CVE-2026-1340 has an EPSS of 0.402 (97th percentile). 85% of sessions used OAST-style DNS callbacks, indicating initial access broker activity. The dominant exploitation IP is not on widely published IOC lists. The same actor is simultaneously exploiting CVE-2026-21962 in Oracle WebLogic (2,902 sessions) and CVE-2025-24799 in GLPI (EPSS 0.669, 99th percentile).


Business & Infrastructure Threats

DNS-Based ClickFix Attack Uses Nslookup for Malware Staging

Microsoft disclosed a new ClickFix variant that uses DNS lookups via nslookup to retrieve and execute second-stage payloads. The attack starts with a social engineering lure that tricks users into running a command through the Windows Run dialog. The command performs a DNS query against an attacker-controlled external nameserver (not the system's default resolver), extracts the DNS response, and executes it as a payload. This reduces dependency on traditional web requests and blends malicious activity into normal DNS traffic. The final payload downloads a ZIP from azwsappdev[.]com containing ModeloRAT, a Python-based RAT that persists via an LNK shortcut in the Windows Startup folder.

Lumma Stealer Campaign Abuses Google Groups for Distribution

CTM360 identified over 4,000 malicious Google Groups and 3,500 Google-hosted URLs distributing Lumma Stealer and a trojanized Chromium browser called "Ninja Browser." Attackers embed download links in legitimate-looking technical forum posts, using organization names and industry keywords for credibility. Windows victims receive a 950MB archive padded with null bytes to evade antivirus file-size scanning thresholds; the actual payload is ~33MB. The malware uses AutoIt-based reconstruction and executes a memory-resident Lumma Stealer payload that exfiltrates browser credentials, session cookies, and runs shell commands. C2 traffic goes to healgeni[.]live via multipart/form-data POST requests. Linux targets receive a trojanized Chromium browser with a malicious "NinjaBrowserMonetisation" extension that tracks users, injects scripts, and maintains persistence through scheduled tasks.

Over 300 Malicious Chrome Extensions Stealing User Data

Researchers identified more than 300 malicious Chrome extensions with a combined 37 million downloads that were leaking or stealing user data, exposing users to tracking and personal information theft. The scale of this campaign represents a significant browser supply chain risk for any organization without extension management controls.


General Security News

ClickFix JavaScript Attack Hijacks Crypto Swaps via Pastebin

Threat actors are posting comments across Pastebin promoting a fake "Swapzone.io arbitrage exploit." Links redirect victims to a Google Docs guide that instructs them to paste JavaScript into their browser address bar while on Swapzone.io. The injected script overrides the legitimate Next.js swap handler, replacing Bitcoin deposit addresses with attacker-controlled wallets. The script also manipulates displayed exchange rates to make the fake arbitrage appear to work. This is the first known ClickFix variant using JavaScript to alter a live web application's functionality rather than targeting OS-level command execution. Bitcoin transactions are irreversible, so funds sent to attacker wallets cannot be recovered.

Physical Mail Phishing Targets Hardware Wallet Users

Threat actors are mailing physical letters impersonating Trezor and Ledger security teams, claiming recipients must complete a mandatory "Authentication Check" or "Transaction Check" by a specific deadline. Letters include QR codes that lead to phishing sites (trezor.authentication-check[.]io, ledger.setuptransactioncheck[.]com) designed to harvest wallet recovery phrases. Victims who enter their seed phrases have their wallets drained. Targeting data likely originates from previous Trezor and Ledger data breaches that exposed customer contact information. Physical mail phishing remains uncommon but effective because it bypasses email security controls entirely.

Google and OpenAI Warn of AI Model Distillation Attacks

Google and OpenAI reported that competitors, including DeepSeek, are systematically probing frontier models to extract reasoning capabilities for replication. Google detected a campaign using over 100,000 prompts targeting Gemini's non-English reasoning and says it protected internal reasoning traces in real time. OpenAI accused DeepSeek of continuing adversarial distillation against US frontier labs, with methods evolving from basic chain-of-thought extraction to multi-stage synthetic data generation and obfuscated third-party access. Organizations deploying custom fine-tuned models should be aware that their training data and reasoning logic could be similarly targeted through API access.


Trends & Context

ClickFix is fragmenting into specialized variants at speed. Today's articles document three distinct approaches: DNS-based staging via nslookup (Microsoft disclosure), browser-side JavaScript injection targeting crypto swaps (Pastebin campaign), and traditional fake-CAPTCHA delivery for Lumma Stealer (CastleLoader). The common thread is tricking users into self-infecting, which bypasses endpoint security controls. The Ivanti EPMM exploitation is the top action item today, with the CISA KEV deadline for CVE-2026-24061 hitting tomorrow and the dominant exploitation source absent from public IOC lists.