← Carolina Clear Tech

Cyber Threat Brief

2026-02-28

Listen to this brief (16:17)

Download MP3
Show Notes

Show Notes - 2026-02-28

Stories Covered

CVEs Referenced

CVE-2025-0282, CVE-2025-40039, CVE-2025-71147, CVE-2025-71150, CVE-2025-71152, CVE-2025-71154, CVE-2025-71160, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71229, CVE-2025-71232, CVE-2025-71235, CVE-2025-71237, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23212, CVE-2026-23216, CVE-2026-23220, CVE-2026-23222, CVE-2026-23228, CVE-2026-28364

Indicators of Compromise

Hashes: 3526af9189533470bc0e90d54bafb0db7bda784be82a372ce112e361f7c7b104, 52bbc44eb451cb5e16bf98bc5b1823d2f47a18d71f14543b460395a1c1b1aeda, b1221000f43734436ec8022caaa34b133f4581ca3ae8eccd8d57ea62573f301d

IP Addresses: 154.84.63.184

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-02-28

Today: CISA confirms RESURGE malware can remain dormant on compromised Ivanti devices, using sophisticated network evasion to hide from defenders. A new RAT called Steaelite bundles ransomware and data theft in a single tool, making double extortion attacks easier for low-skill criminals. Ransomware payments dropped 8% in 2025, but attacks surged 50% as more groups piled in despite fewer victims paying.

Critical Alerts

CISA warns that RESURGE malware can be dormant on Ivanti devices (CVE-2025-0282)

CISA released updated analysis of RESURGE, a malicious implant targeting Ivanti Connect Secure devices exploited via CVE-2025-0282 since mid-December 2024. The malware is a passive command-and-control (C2) implant that waits for specific inbound TLS connections instead of beaconing, evading network monitoring. CVE-2025-0282 was added to the CISA KEV catalog with a due date of 2025-01-15 and has an EPSS score of 0.941 (100th percentile), indicating near-certain exploitation. The implant uses TLS fingerprint hashing to identify attacker connections, presents a fake Ivanti certificate for authentication, and establishes encrypted sessions using Elliptic Curve cryptography. The malware survives reboots, can create webshells, reset passwords, and escalate privileges. CISA warns that RESURGE may be dormant and undetected on devices, remaining an active threat even after the January KEV deadline.

Ransomware & Extortion

Steaelite RAT bundles data theft and ransomware in one tool

A new remote access trojan called Steaelite is being sold on cybercrime networks, marketed as "fully undetectable" and the "best Windows RAT." The malware bundles ransomware, data theft, credential harvesting, cryptocurrency stealers, live surveillance, and other capabilities in a browser-based dashboard. Steaelite automatically harvests browser-stored passwords, session cookies, and application tokens when a victim connects, before the operator issues any commands. The dashboard includes modules for remote code execution, file management, webcam and microphone access, clipboard monitoring, password recovery, and DDoS attacks. An "advanced tools" panel adds ransomware deployment, hidden RDP, Windows Defender disabling, and persistence installation. A third "developer tools" panel includes keylogging, USB spreading, bot-killing, UAC bypass, and a clipper that swaps cryptocurrency wallet addresses during copy-paste operations. An Android version is reportedly in development, which would allow a single license to cover both corporate Windows computers and mobile devices used for authentication.

Ransomware payments dropped 8% in 2025, but attacks surged 50%

Ransomware payments fell to $820 million in 2025, an 8% decline from 2024, while the number of publicly claimed attacks surged 50% to record highs. The share of victims paying ransoms dropped to an all-time low of 28%, but median ransom demands jumped from $12,738 in 2024 to $59,556 in 2025. Chainalysis reports that smaller, opportunistic groups are behind a growing share of extortion attempts, even as older groups like LockBit and BlackCat have been raided, sanctioned, or rebranded. More than 8,000 organizations were publicly named on leak sites in 2025, a sharp increase from previous years. The US leads victim counts, followed by Canada, Germany, the UK, and Western Europe. Chainalysis found that initial access brokers (IABs) received at least $14 million in on-chain payments in 2025, with spikes in IAB payments preceding ransomware payments and victim leak posts by roughly 30 days.

Business & Infrastructure Threats

Malicious Go crypto module steals passwords and deploys Rekoobe backdoor

Researchers disclosed a malicious Go module, github.com/xinfeisoft/crypto, that impersonates the legitimate golang.org/x/crypto codebase but injects code to exfiltrate secrets and deliver the Rekoobe Linux backdoor. The module modifies the ssh/terminal/terminal.go file so that every call to ReadPassword() captures passwords entered via terminal prompts and sends them to a remote endpoint. The module then fetches a shell script that appends an SSH key to /home/ubuntu/.ssh/authorized_keys, sets iptables policies to ACCEPT, and downloads additional payloads disguised with .mp5 extensions. One payload tests internet connectivity and communicates with 154.84.63.184 over TCP port 443. The second payload is Rekoobe, a Linux trojan active since at least 2015 that can download more payloads, steal files, and execute reverse shells. Rekoobe has been used by Chinese nation-state groups like APT31 as recently as August 2023. The Go security team has blocked the library as malicious, but the package remains listed on pkg.go.dev.

Windows / AD Security

Microsoft testing batch file security improvements

Microsoft is rolling out new Windows 11 Insider Preview builds (Build 26220.7934 in Beta and Build 26300.7939 in Dev) that improve security during batch file or CMD script execution. IT administrators can now enable a more secure processing mode that prevents batch files from being modified while they run by adding the LockBatchFilesInUse registry value under HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor. Policy authors can enable this mode using the LockBatchFilesWhenInUse application manifest control. This change is designed to boost performance and security in enterprise environments where admins rely heavily on scripted workflows. With code integrity enabled, signature validation will only be required once instead of per statement executed in the batch file.

General Security News

Pentagon designates Anthropic supply chain risk over AI military dispute

The Pentagon designated Anthropic as a "supply chain risk" after negotiations broke down over two exceptions Anthropic requested for the use of its Claude AI model: mass domestic surveillance of Americans and fully autonomous weapons. President Trump ordered all federal agencies to phase out Anthropic technology within six months, and the Secretary of Defense mandated that all contractors, suppliers, and partners doing business with the US military cease commercial activity with Anthropic immediately. Anthropic argued that its contracts should not facilitate mass domestic surveillance or autonomous weapons development, citing concerns that the technology is not capable or reliable enough to support them safely. The Pentagon's position is that it will only work with AI companies that allow "any lawful use" of the technology without usage policy constraints. Anthropic called the designation "legally unsound" and said a supply chain risk designation under 10 USC 3252 can only extend to Department of War contracts, not the use of Claude by other customers. The standoff has polarized the tech industry, with hundreds of Google and OpenAI employees signing an open letter supporting Anthropic.

Patch Priority

Vulnerability Disclosures

OCaml buffer over-read enables remote code execution (CVE-2026-28364)

A buffer over-read vulnerability in OCaml before 4.14.3 and 5.x before 5.4.1 enables remote code execution through a multi-phase attack chain. The vulnerability is in the Marshal deserialization function (runtime/intern.c) and stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. EPSS score is 0.000 (11th percentile).

Linux kernel ksmbd and networking CVEs

Microsoft published 33 Linux kernel CVEs, mostly affecting ksmbd (SMB server), networking, device drivers, and memory management. Notable entries include CVE-2025-71150 (ksmbd refcount leak on invalid session lookup), CVE-2026-23220 (ksmbd infinite loop in error paths), CVE-2026-23228 (ksmbd leak of active_num_conn), CVE-2025-40039 (ksmbd race condition in RPC handle list), and multiple networking and driver fixes (CVE-2025-71152, CVE-2025-71154, CVE-2025-71160, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23212, CVE-2026-23216, CVE-2026-23222, CVE-2025-71147, CVE-2025-71232, CVE-2025-71235, CVE-2025-71229, CVE-2025-71237). All have EPSS scores below 0.01 (0th to 11th percentile), indicating low likelihood of immediate exploitation.

Trends & Context

Today's stories highlight the gap between ransomware economics and attack volume. Payments are down, but attacks are up 50% as smaller groups flood the market, gambling on volume over payout rates. The emergence of all-in-one tools like Steaelite lowers the skill floor for double extortion, automating data theft before operator interaction. CISA's updated RESURGE analysis underscores the persistence challenge: passive implants can remain dormant on compromised devices, evading network monitoring until attackers reconnect.