← Carolina Clear Tech

Cyber Threat Brief

2026-02-24

Listen to this brief (28:02)

Download MP3
Show Notes

Show Notes - 2026-02-24

Stories Covered

CVEs Referenced

CVE-2020-14979, CVE-2025-55182, CVE-2026-22769

Indicators of Compromise

IP Addresses: 6.0.3.1

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - February 24, 2026

Today: Dell RecoverPoint zero-day exploited by Chinese threat actors since mid-2024 with CISA deadline February 21. Wormable XMRig cryptojacker uses BYOVD exploit against Windows systems with time-bomb decommissioning. CrowdStrike reports average adversary breakout time dropped to 29 minutes with 82% of detections being malware-free.

Critical Alerts

Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Chinese threat cluster UNC6201 has been exploiting a maximum severity vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024. CVE-2026-22769 (CVSS 10.0) is a hard-coded credentials flaw affecting versions prior to 6.0.3.1 HF1. Attackers used the hard-coded "admin" user for the Apache Tomcat Manager instance to authenticate, upload the SLAYSTYLE web shell via the /manager/text/deploy endpoint, and execute commands as root to deploy the BRICKSTORM backdoor and its newer GRIMBOLT variant. CISA added this to KEV with a February 21 deadline. EPSS score is 0.342 (97th percentile).

Wormable XMRig Campaign (CVE-2025-55182, CVE-2020-14979)

A sophisticated cryptojacking campaign is deploying XMRig miners via pirated software bundles with wormlike propagation across removable media. The malware uses bring-your-own-vulnerable-driver (BYOVD) technique, dropping the legitimate but flawed WinRing0x64.sys driver to exploit CVE-2020-14979 (CVSS 7.8) for privilege escalation. This boosts mining performance by 15% to 50%. The binary includes a logic bomb set for December 23, 2025, after which it triggers self-destruct, terminating all components. The campaign peaked December 8, 2025, after sporadic activity throughout November. CVE-2025-55182 is CISA-KEV listed as ransomware-linked with December 12, 2025 deadline and 0.596 EPSS (98th percentile).

Vulnerability Disclosures

600+ FortiGate Devices Compromised by AI-Assisted Amateur

A Russian-speaking attacker used generative AI to compromise over 600 FortiGate firewalls, targeting credentials and backups for possible follow-on ransomware attacks. The attacker lacked traditional expertise but leveraged AI to scale operations and identify vulnerabilities in FortiGate devices.

JPEG-Embedded Malware Campaign

A new campaign is using JPEG files with embedded malicious payloads, delivered via JScript attachments in emails. The 1.17 MB JScript file contained 17,222 lines, with 17,188 identical lines as basic obfuscation. After deobfuscation, the script establishes persistence in the startup folder, then spawns a hidden PowerShell instance to download the next stage from a remote URL. The campaign appears to target Czech organizations based on spoofed sender addresses, though emails fail DMARC/SPF checks. Error messages in the script are written in Brazilian Portuguese.

Android Mental Health Apps with 14.7M Installs Riddled with Flaws

Ten mental health apps with collective 14.7 million downloads contain 1,575 security vulnerabilities, including 54 high-severity issues. Flaws include parsing user-supplied URIs without validation using Intent.parseUri(), allowing attackers to force apps to open internal activities handling authentication tokens and session data. Apps store data locally with read access to any app on the device, exposing therapy entries, CBT session notes, and health scores. Most apps lack root detection. Several use java.util.Random for session token generation instead of cryptographically secure methods. Configuration data includes plaintext backend API endpoints and hardcoded Firebase URLs.

Ransomware & Extortion

CrowdStrike 2026 Global Threat Report

Average eCrime breakout time dropped to 29 minutes in 2025, a 65% speed increase from 2024. Fastest observed breakout: 27 seconds. Adversaries using AI increased attack volume by 89% compared to 2024. 82% of detections were malware-free, with intrusions moving through authorized pathways using valid credentials, trusted identity flows, approved SaaS integrations, and inherited supply chains. Supply chain attacks were a defining tactic in 2025. PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency via trojanized software delivered through supply chain compromise, the largest single financial theft ever reported. Zero-day exploitation increased 42% year-over-year. China-nexus adversaries exploited vulnerabilities where 67% provided immediate system access and 40% targeted edge devices lacking comprehensive monitoring.

Vikor Scientific Data Breach (Everest Ransomware)

Everest ransomware group has taken credit for an attack on Vikor Scientific (now Vanta Diagnostics), affecting 140,000 individuals. The healthcare diagnostic firm confirmed the breach exposed patient health data.

ATM Jackpotting Attacks Surged in 2025

ATM jackpotting attacks cost banks more than $20 million in losses during 2025. Attackers used many of the same tools and tactics deployed for over a decade, demonstrating persistence of legacy attack methods against financial infrastructure.

Business & Infrastructure Threats

Optimizely Data Breach via Vishing Attack

Ad tech company Optimizely confirmed a data breach after threat actors compromised systems in a voice phishing attack on February 11. Attackers gained access through sophisticated vishing but could not escalate privileges, install software, or create backdoors. The breach was confined to certain internal business systems, CRM records, and limited internal documents. Stolen data includes basic business contact information from over 10,000 customer organizations including H&M, PayPal, Zoom, Toyota, Vodafone, Shell, Salesforce, and Nike. The attack is consistent with ShinyHunters extortion operation, which has claimed similar breaches at Canada Goose, Panera Bread, Betterment, SoundCloud, Figure, and Match Group in recent weeks. ShinyHunters has shifted to device code vishing, abusing OAuth 2.0 device authorization grant flow to obtain Microsoft Entra authentication tokens and access connected services including Salesforce, Microsoft 365, Google Workspace, Zendesk, Dropbox, SAP, Slack, Adobe, and Atlassian.

Anthropic Accuses Chinese AI Labs of Distillation Attacks

Anthropic identified industrial-scale campaigns by DeepSeek, Moonshot AI, and MiniMax to extract Claude's capabilities through model distillation attacks. Attackers generated over 16 million exchanges with Claude using approximately 24,000 fraudulent accounts in violation of terms of service and regional access restrictions. DeepSeek targeted reasoning capabilities and censorship-safe alternatives (150,000 exchanges). Moonshot AI targeted agentic reasoning, tool use, coding, computer-use agent development, and computer vision (3.4 million exchanges). MiniMax targeted agentic coding and tool use (13 million exchanges). Attacks relied on commercial proxy services with "hydra cluster" architectures managing massive networks of fraudulent accounts to distribute traffic. One proxy network managed more than 20,000 fraudulent accounts simultaneously. Illicitly distilled models lack necessary safeguards, creating national security risks for offensive cyber operations, disinformation campaigns, and mass surveillance.

Google Suspends Accounts for Antigravity Usage with Third-Party AI Tools

Google suspended customer accounts, including $250/month AI Ultra subscribers, for using Antigravity agent development app and Gemini services with third-party agent tools like OpenClaw and OpenCode. Account bans followed malicious usage determination, though customers argue actions were legitimate use within quota limits. Google's AI services were not priced or provisioned for heavy autonomous usage when third-party agent wrappers rely on Google AI under the hood. Terms of service did not explicitly ban OpenClaw integration. The issue reveals AI companies are selling tokens below cost to gain market share.

Google Gemini Chat Histories Disappearing

Google Gemini users reported months of conversations vanishing from both phone and desktop despite autodelete being set to keep chats for 18 months. Prompts still show in activity logs, suggesting data exists but is inaccessible. At least 15 chats disappeared with no evidence in activity logs. Recent chats disappeared from both Gemini and Google's My Activity archive. Google confirmed a bug temporarily hid chat history for a small number of users and stated chat history will be restored shortly. Complaints coincided with Gemini 3.1 rollout.

Windows / AD Security

Microsoft Classic Outlook Mouse Pointer Bug

Microsoft is investigating a bug causing the mouse pointer to disappear in classic Outlook for some users. The issue also affects OneNote and other Microsoft 365 apps to a lesser degree. Although the pointer is invisible, emails in the message list change color on hover, indicating the pointer is still functional but not rendered. Microsoft is requesting diagnostic log files from affected users. Temporary workarounds include clicking an email in the message list, switching to PowerPoint and back to Outlook, or restarting the computer.

Microsoft SharePoint "Reimagined Experience" Coming in April

Microsoft announced a reimagined SharePoint experience designed to be simple and intuitive, centered on discovering knowledge, publishing content, and building solutions. The update establishes the foundation for AI-assisted creation across the product with updated information architecture and cohesive design language. Preview launches in March with targeted release in April. Microsoft will also allow users to customize the OneDrive folder name (currently forced to "OneDrive - {organization name}") to reduce path length issues for deeply nested files.

When Identity Isn't the Weak Link, Access Still Is

Authentication confirms who a user is, but does not provide sufficient insight into how risky that access may be once device condition and context are taken into account. A legitimate user accessing systems from a secure, compliant device represents a fundamentally different risk from the same user connecting from an outdated, unmanaged, or compromised endpoint. Yet many access models grant access primarily on identity while device condition remains secondary or static. Endpoints regularly shift state as configurations drift, security controls are disabled, or updates are delayed, often long after access has been granted. Access gaps are most visible across paths outside modern conditional access coverage, including legacy protocols, remote access tools, and non-browser workflows. Attackers increasingly exploit these blind spots by reusing misplaced trust, stealing session tokens, abusing compromised endpoints, or working around MFA.

General Security News

UnsolicitedBooker Targets Central Asian Telecoms

China-aligned threat actor UnsolicitedBooker targeted telecommunications companies in Kyrgyzstan and Tajikistan with LuciDoor and MarsSnake backdoors, shifting from prior attacks on Saudi Arabian entities. Attacks used phishing emails with malicious Microsoft Office macros. Late September 2025 attacks on Kyrgyz organizations used documents displaying telecom tariff plans to drop LuciLoad, which delivers LuciDoor. Late November 2025 attacks used MarsSnakeLoader to deploy MarsSnake. January 2026 attacks on Tajikistan companies embedded links to decoy documents instead of direct attachments. Both backdoors establish C2 communication, collect system information, execute commands, and read/write files. The group used a hacked router as C2 server and mimicked Russian infrastructure in some attacks. Evidence shows MarsSnake was also used in attacks targeting China.

APT28 Operation MacroMaze Targets Europe

Russia-linked APT28 targeted specific entities in Western and Central Europe between September 2025 and January 2026 using webhook-based macro malware. The campaign relies on basic tooling and exploitation of legitimate services.

Iran's MuddyWater Debuts New Malware

Long-active Iranian threat group MuddyWater debuted various attack strains and payloads in attacks against organizations in the Middle East and Africa as geopolitical tensions mount.

Ukraine Sentences Individual for Aiding North Korean IT Fraud

Oleksandr Didenko received 5 years in US prison for selling stolen identities of US citizens, allowing North Koreans to get hired using freelance work platforms. The scheme enabled North Korean IT workers to infiltrate Western companies and generate revenue for the regime.

Spain Arrests Anonymous Fénix Hacktivists

Spanish authorities arrested four alleged members of Anonymous Fénix hacktivist group for DDoS attacks targeting government ministries, political parties, and public institutions in Spain and South America. First attacks occurred in April 2023, with peak activity after Valencia flash floods in October 2024 when the group attacked government websites claiming authorities were responsible for deaths. The group recruited volunteers via X and Telegram for cyberattacks. Spanish courts ordered seizure of X and YouTube accounts and closure of Telegram channel. The administrator and moderator were arrested in May 2025 in Alcalá de Henares and Oviedo. Two additional members were arrested in February 2026 in Ibiza and Móstoles.

Anthropic Rolls Out Claude Code Security

Anthropic launched Claude Code Security, a feature that scans codebases for vulnerabilities and suggests patches. The tool is available as a limited research preview for enterprise and team customers. Anthropic claims Claude Opus 4.6 found and validated more than 500 high-severity vulnerabilities in open source code. The tool is context-aware, reading and reasoning about code like a human security researcher, understanding component interactions and data flow. Nothing is applied without human approval. Cybersecurity stocks dropped on Friday following the announcement. Similar AI-enabled bug-fixing tools already exist from Amazon, Microsoft, Google, and OpenAI.

CrowdStrike Typosquatting Campaign Analysis

Typosquatting remains one of the most effective and underestimated attack vectors. Threat actors register misspelled or look-alike domains to phish employees or customers, harvest credentials, deliver malware, and damage organizational reputation. Adversaries have refined typosquatting techniques to a concerning degree of sophistication. Domain registration process presents numerous opportunities for threat actors to establish seemingly credible infrastructure with minimal verification. Adversaries populate WHOIS records with fabricated but convincing company information mirroring legitimate organizations. Common techniques include replacing characters with visually similar alternatives, adding common prefixes or suffixes, or exploiting common typing errors. Sophisticated actors register domains using publicly available corporate information including legitimate business addresses and contact details harvested from target organizations' public filings.

Trends & Context

Adversaries are moving faster and quieter in 2025. The shift to malware-free attacks using valid credentials and trusted pathways means detection must focus on behavioral anomalies rather than signature-based malware scanning. The 29-minute breakout time leaves minimal margin for response, demanding immediate lateral movement detection. Supply chain compromise has become a primary access vector, turning trusted software updates and developer tools into delivery mechanisms. AI-assisted attacks are scaling amateur capabilities to professional levels, as seen in the FortiGate compromises. Organizations must extend zero trust principles beyond authentication to include continuous device trust assessment and access path monitoring. The Dell RecoverPoint zero-day demonstrates that hard-coded credentials remain a critical flaw even in enterprise infrastructure products.