← Carolina Clear Tech

Cyber Threat Brief

2026-02-19

Listen to this brief (12:00)

Download MP3
Show Notes

Show Notes - 2026-02-19

Stories Covered

CVEs Referenced

CVE-2026-2329

Indicators of Compromise

Domains: trustconnectsoftware[.]com

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - February 19, 2026

Today: A new RAT-as-a-service called TrustConnect is masquerading as a legitimate RMM tool, using EV certificate abuse to bypass endpoint defenses and targeting IT environments at $300/month. A critical unauthenticated root access bug (CVE-2026-2329) in Grandstream VoIP gear exposes SMB phone infrastructure to call interception and toll fraud. The Adidas third-party breach, claimed by Scattered Lapsus$ Hunters, confirms 815,000 rows of data stolen and reinforces the ongoing supply chain targeting pattern against major brands.


Critical Alerts

TrustConnect: RAT Disguised as a Legitimate RMM Tool

Proofpoint identified TrustConnect as a new malware-as-a-service (MaaS) Remote Access Trojan, sold at $300/month, that impersonates a legitimate RMM platform called "TrustConnect Agent." The threat actor behind it is assessed with moderate confidence to be a former prominent Redline stealer operator. The malware's infrastructure included a fake business website used to obtain an Extended Validation (EV) certificate from a real CA, allowing it to sign malware and bypass signature-based detections. Proofpoint, in collaboration with The Cert Graveyard, had the EV cert revoked on February 6, but revocation was not backdated, leaving already-distributed signed binaries valid. Infrastructure was partially disrupted, but the actor pivoted quickly, with a successor site advertising a similar tool called DocConnect appearing before publication.


Vulnerability Disclosures

Critical Grandstream VoIP Bug (CVE-2026-2329) Enables Unauthenticated Root Access

CVE-2026-2329 is a critical unauthenticated vulnerability in Grandstream VoIP devices that grants root-level access to attackers without any credentials. Exploitation allows call interception, toll fraud, and user impersonation. Grandstream VoIP hardware is widely deployed in SMB phone systems, and these devices are frequently internet-facing or on flat networks with minimal segmentation, making them an easy pivot point. Dark Reading notes this highlights the broader SMB security blind spot around unmanaged IP phone infrastructure.


Ransomware & Extortion

Adidas Third-Party Breach: Lapsus$ Collaboration Claims 815,000 Records

Adidas confirmed it is investigating a breach at one of its independent licensing partners after someone claiming to represent Scattered Lapsus$ Hunters posted on BreachForums on February 16. The claimed stolen data includes 815,000 rows: names, email addresses, passwords, birthdays, company names, and technical data from the partner's extranet. Adidas says its own IT infrastructure and consumer data are unaffected. This is the second third-party security incident affecting Adidas in under a year, the first occurring in May 2025 via a customer service provider. Scattered Lapsus$ Hunters is the combined operation of Lapsus$, Scattered Spider, and ShinyHunters who merged in mid-2025.


Business & Infrastructure Threats

Massiv Android Banking Trojan Distributed via Fake IPTV Apps

A new Android banking malware named Massiv is being distributed through fake IPTV dropper apps via SMS phishing. Once installed, it requests accessibility permissions and enables full device takeover: screen streaming via MediaProjection API, keylogging, SMS interception, fake overlays on banking apps, and remote control via a UI-tree mode that bypasses screen capture protections. ThreatFabric researchers confirmed cases where new bank accounts were opened in victims' names for money laundering. One campaign specifically targeted Portugal's gov.pt digital identity app (Chave Móvel Digital) to bypass KYC verification. Fake IPTV apps as malware lures have increased significantly over the past eight months, primarily targeting users in Spain, Portugal, France, and Turkey. Dropper package names observed: hfgx.mqfy.fejku (IPTV24) and hobfjp.anrxf.cucm (masquerades as Google Play).

CrowdStrike Insider Threat Analytics: New Dashboard Capabilities

CrowdStrike released new Insider Threat Analytics and User Activity Investigation dashboards in Falcon Next-Gen SIEM. These correlate identity risk scores, data egress patterns, endpoint telemetry, and HR context (new hires, departing employees) to detect malicious insiders and negligent users. Highlights include first-seen analysis for new data egress destinations, USB device monitoring, and cross-layer correlation across identity, data protection, and endpoint layers.

Deutsche Bahn DDoS Attack Disrupts Rail Systems

Germany's Deutsche Bahn was hit by a large-scale DDoS attack that disrupted information and booking systems for several hours. No attribution or specific threat actor has been confirmed. Critical infrastructure DDoS attacks against European transportation continue as a pattern, consistent with pro-Russian hacktivist activity targeting NATO-aligned nations.

CRESCENTHARVEST Campaign Uses DLL Sideloading and Chrome Key Theft

An unattributed campaign, likely Iran-aligned, is targeting Farsi-speaking supporters of Iran's ongoing protests with spear-phishing RAR archives. The attack chain uses LNK files disguised as protest images/videos, PowerShell to pull down additional payloads, and DLL sideloading via a legitimate Google-signed binary (software_reporter_tool.exe). The two rogue DLLs deliver: a C++ implant that extracts Chrome's app-bound encryption keys via COM (ChromElevator overlap), and CRESCENTHARVEST itself, which steals browser credentials, Telegram desktop data, keystrokes, and system metadata while communicating via WinHTTP APIs. This campaign's primary relevance for SMBs is the Chrome credential theft component, which is increasingly used across threat actor toolkits regardless of geopolitical targeting.

Nigerian Cybercriminal Sentenced for Tax Fraud via RAT-Delivered Phishing

Matthew Abiodun Akande was sentenced to 8 years for a five-year scheme targeting U.S. tax preparation firms via phishing emails that delivered Warzone RAT. The crew filed over 1,000 fraudulent tax returns claiming $8.1M in refunds, obtaining $1.3M. Four Massachusetts tax prep firms were listed as victims.


General Security News

Poland Bans Chinese-Made Cars from Military Bases Over Surveillance Risks

Poland's Ministry of Defence has banned Chinese-manufactured vehicles and any vehicle with embedded position, image, or audio recording capabilities from protected military facilities. The ban also prohibits connecting work phones to infotainment systems in Chinese-made cars. Poland describes this as consistent with NATO standards. Enforcement is complicated by European automakers like Volvo and Polestar manufacturing some models in China.

Gemini Chatbot Abused in Fake "Google Coin" Crypto Scam

A phishing/fraud campaign has built a convincing fake cryptocurrency presale site for "Google Coin" that uses a Gemini-branded AI chatbot to engage victims with sales pitches and funnel payments to attackers. This is a social engineering abuse of AI chatbot interfaces, not a vulnerability in Google's systems.

OpenClaw Ongoing Security Issues; SecureClaw Open Source Tool Debuts

OpenClaw continues to face security vulnerabilities and misconfiguration risks despite rapid patching and its transition to an OpenAI-backed foundation. A new open-source alternative, SecureClaw, has debuted in response.


Trends & Context

Today's feed is dominated by the theme of trusted-component abuse: TrustConnect abuses RMM familiarity and EV certificate trust chains, CRESCENTHARVEST abuses a legitimate Google-signed binary for DLL sideloading, and Massiv abuses Android's accessibility services. Attackers are systematically co-opting trusted software ecosystems rather than building novel attack infrastructure. The Adidas third-party breach and the tax prep firm RAT campaign both reinforce that supply chain and third-party access remain the most reliable SMB entry vector, with the targeting of trusted intermediaries (service providers, licensing partners, tax preparers) a consistent pattern heading into Q1 2026.