← Carolina Clear Tech

Cyber Threat Brief

2026-03-28

Listen to this brief (19:11)

Download MP3
Show Notes

Show Notes - 2026-03-28

Stories Covered

CVEs Referenced

CVE-2025-53521, CVE-2026-32187, CVE-2026-33343, CVE-2026-33413, CVE-2026-4673, CVE-2026-4677, CVE-2026-4680

Indicators of Compromise

Domains: drnatashachinn[.]com, escofiringbijou[.]com, careerscrews[.]com, careerstaffer[.]com, careersworkflow[.]com, mail[.]ru.

IP Addresses: 17.5.1.3, 16.1.6.1, 15.1.10.8, 83.142.209.203

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

March 28, 2026

Today: F5 BIG-IP vulnerability CVE-2025-53521 added to CISA KEV after active exploitation, TeamPCP supply chain attack expands to Telnyx PyPI package with WAV steganography, LAPSUS$ claims 3GB AstraZeneca breach using TeamPCP credentials. Federal agencies have until March 30 to patch F5 systems.

Critical Alerts

F5 BIG-IP APM Remote Code Execution (CVE-2025-53521)

CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog on March 27 after confirming active exploitation targeting F5 BIG-IP Access Policy Manager. The vulnerability, initially classified as a denial-of-service issue with CVSS 8.7, was reclassified to remote code execution with CVSS 9.3 after F5 obtained new information in March 2026 confirming RCE capability. The flaw allows remote code execution through malicious traffic sent to virtual servers with BIG-IP APM access policies configured. Exploitation includes webshell deployment (both disk-based and memory-only variants), modifications to system integrity checker components, and HTTP/S traffic using CSS content-type to disguise attacker activity. F5 confirmed the vulnerability has been exploited in vulnerable BIG-IP versions and published indicators of compromise including suspicious files (/run/bigtlog.pipe, /run/bigstart.ltm), modified binaries (/usr/bin/umount, /usr/sbin/httpd), and audit log entries showing local users accessing iControl REST API from localhost. Defused Cyber reports acute scanning activity targeting vulnerable F5 devices following the KEV announcement. EPSS score remains low at 0.001 (25th percentile), but active exploitation overrides probability-based prioritization.

Ransomware Claims (Last 48h)

The black nevas ransomware group posted 8 new victim claims on March 27, 2026, targeting organizations across multiple sectors and geographies. Claims tracked across multiple ransomware groups in the last 48 hours.

Group Victim Sector Country
black nevas PROMOSFERA S.R.L. Unknown Italy
black nevas Quality Data Service, Inc. Technology USA
black nevas KINAS SOLICITORS Legal UK
black nevas Paramount Health Services & Insurance TPA Pvt. Ltd Healthcare India
black nevas MST (Sanko Makina and ASKO Holding) Manufacturing Turkey
black nevas E-CON Packaging Private Limited Manufacturing India
black nevas Heng An Standard Life Insurance Financial Services China

Ransomware & Extortion

TeamPCP Supply Chain Attack Escalates: Telnyx PyPI Compromise, Vect Ransomware Partnership, and AstraZeneca Breach Claim

The TeamPCP supply chain campaign expanded significantly on March 27 with the compromise of the Telnyx Python SDK on PyPI (670,000+ monthly downloads). TeamPCP published malicious versions 4.87.1 (03:51 UTC) and 4.87.2 (04:07 UTC) using stolen PyPI credentials. The attack introduces a new technique: WAV audio file steganography. Payloads are embedded inside .wav files (hangup.wav for Windows, ringtone.wav for Linux/macOS), blending naturally with Telnyx's telecom API purpose. On Windows, the malware extracts an executable dropped to the Startup folder as msbuild.exe for persistence. On Linux/macOS, it extracts a credential harvester targeting SSH keys, cloud tokens, cryptocurrency wallets, environment variables, and Kubernetes secrets. The malware also attempts Kubernetes lateral movement by enumerating cluster secrets and deploying privileged pods across nodes. Forensic analysis confirms the same RSA-4096 public key and tpcp.tar.gz exfiltration pattern seen in the LiteLLM compromise. PyPI has quarantined both malicious versions. TeamPCP has formally partnered with Vect ransomware-as-a-service and BreachForums, with approximately 300,000 registered BreachForums users receiving personal Vect affiliate keys. This represents a fundamental shift from supply chain credential theft to industrialized ransomware deployment. LAPSUS$ publicly claims a 3GB breach of AstraZeneca using TeamPCP credentials, marking the first named victim from the TeamPCP/LAPSUS$ partnership. The claimed data includes internal code repositories, cloud infrastructure configurations (AWS, Azure, Terraform), Spring Boot configs, GitHub Enterprise user information, and employee data. LAPSUS$ is selling access via Session encrypted messaging.

Jackson County Sheriff's Office Crippled by Ransomware Attack

A ransomware attack last week completely crippled the Jackson County Sheriff's Office in Indiana, rendering all computers, Wi-Fi, and critical reporting systems unusable. The attack used a dormant malware strategy, lying inactive after initial phishing-based entry before executing lateral movement and encryption. Deputies are writing reports on standalone Microsoft Word documents. Dispatchers relocated to Seymour Police Department to use functional computer systems. Data recovery status is unclear, with critical files like the county sex offender registry depending on external hard drive backups. The incident demonstrates catastrophic operational impact on law enforcement agencies from ransomware. Financial costs include hardware replacement, IT support for rebuild, overtime for staff, and lost productivity.

Bearlyfy Pro-Ukrainian Group Evolves with GenieLocker Ransomware

Pro-Ukrainian group Bearlyfy (also known as Labubu) has conducted over 70 attacks targeting Russian companies since January 2025, recently deploying a custom Windows ransomware strain called GenieLocker. The group operates with dual objectives: extortion for financial gain and sabotage. Attacks escalated from smaller companies demanding €80,000 ransoms to major enterprises demanding hundreds of thousands of dollars. About one in five victims pay ransoms. Bearlyfy initially used LockBit 3 and Babuk encryptors, then switched to modified PolyVice (Vice Society ransomware) in May 2025, and introduced GenieLocker in March 2026. GenieLocker's encryption scheme is inspired by Venus/Trinity ransomware families. The group obtains initial access through exploitation of external services and vulnerable applications, then drops MeshAgent for remote access. Attacks are characterized by minimal preparation and swift data encryption. Ransom notes are crafted directly by attackers rather than generated by ransomware software. Bearlyfy shows overlaps with PhantomCore (another pro-Ukrainian group) and has collaborated with Head Mare.

TeamPCP Wiper Campaign Targets Iran

TeamPCP launched a wiper campaign against Iranian targets over the weekend, spreading through poorly secured cloud services (Docker APIs, Kubernetes clusters, Redis servers, React2Shell vulnerability) and wiping data on infected systems using Iran's time zone or with Farsi as the default language. This marks a shift from the group's typical financially motivated data theft and extortion operations. The motivation for targeting Iran remains unclear, raising questions about whether the group has ties to Israeli operators or has been contracted by government agencies or offensive security firms.

Russian Ransomware Operators Sentenced, RedLine Admin Extradited

The DOJ sentenced Russian national Aleksey Volkov to almost seven years in prison for acting as an initial access broker in Yanluowang ransomware attacks from 2021 to 2022. Volkov breached multiple U.S. organizations and sold network access to affiliates who deployed ransomware and demanded payments up to $15 million. Investigators tied him to over $9 million in losses. Russian citizen Ilya Angelov received two years in prison for co-managing a phishing botnet used to enable BitPaymer ransomware attacks against 72 major companies. The crime group TA551 distributed malware via massive spam campaigns from 2017 to 2021, generating over $14 million in ransom payments. Law enforcement extradited Armenian national Hambardzum Minasyan to the United States for allegedly helping operate the RedLine infostealer malware service. He managed RedLine's infrastructure including servers, domains, and cryptocurrency accounts. He faces up to 30 years in prison if convicted.

LeakBase Administrator "Chucky" Detained in Russia

Russian police detained a Taganrog resident suspected of administering LeakBase, one of the largest hacker platforms. TriTrace Investigations identified the 33-year-old Aartem Kuchumov as "Chucky" based on their investigation. LeakBase was seized on March 4. It is rare for a Russian cybercriminal to be arrested in Russia. Like many Russian threat actors, Chucky had a policy of not leaking or selling any data from Russia on LeakBase, so the reason for his arrest remains unclear.

IOCs & Detection

TeamPCP Telnyx Compromise Indicators

F5 BIG-IP CVE-2025-53521 Exploitation Indicators

Business & Infrastructure Threats

Fake VS Code Security Alerts on GitHub Spread Malware to Developers

A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code security alerts posted in the Discussions section of various projects. The spammy posts are crafted as vulnerability advisories with realistic titles like "Severe Vulnerability, Immediate Update Required," often including fake CVE IDs and urgent language. The threat actor impersonates real code maintainers or researchers. Posts are automated from newly created or low-activity accounts across thousands of repositories within minutes, triggering email notifications to tagged users and followers. Posts include links to supposedly patched VS Code extensions hosted on Google Drive. Clicking the Google link triggers a cookie-driven redirection chain leading to drnatashachinn[.]com, which runs a JavaScript reconnaissance script collecting timezone, locale, user agent, OS details, and automation indicators. The data is packaged and sent to C2 via POST request. This serves as a traffic distribution system (TDS) filtering layer, profiling targets to filter out bots and researchers, delivering second-stage payloads only to validated victims.

Open VSX Pre-Publish Scanning Bypass (Open Sesame)

Koi Security disclosed a vulnerability in Open VSX's pre-publish scanning pipeline (patched in version 0.32.0) that allowed malicious VS Code extensions to bypass security checks. The pipeline had a single boolean return value that meant both "no scanners are configured" and "all scanners failed to run," causing failed scans to be treated as passes. An attacker could flood the publish endpoint with malicious .VSIX extensions, exhausting the database connection pool and causing scan jobs to fail to enqueue. Extensions would then be marked as passed and immediately activated. The vulnerability required only a free publisher account to exploit. Open VSX serves as the extension marketplace for Cursor, Windsurf, and other VS Code forks.

European Commission Investigating Breach After Amazon Cloud Account Hack

The European Commission is investigating a security breach after a threat actor gained access to the Commission's Amazon cloud environment. The breach affected at least one of the Commission's AWS accounts. The threat actor claims to have stolen over 350 GB of data including multiple databases, and provided screenshots showing access to European Commission employee information and an email server. The threat actor told BleepingComputer they will not attempt extortion but intend to leak the data online at a later date. AWS stated they did not experience a security event and services operated as designed. This follows a February breach involving the mobile device management platform used to manage staff devices, linked to Ivanti EPMM vulnerabilities.

Windows / AD Security

Microsoft Defender High-Value Asset Protection

Microsoft published details on how Defender protects high-value assets including domain controllers, web servers, and identity infrastructure using asset-aware protection powered by Microsoft Security Exposure Management. In more than 78% of human-operated cyberattacks, threat actors successfully compromise a high-value asset to gain deeper, elevated access. Defender incorporates a critical asset framework to enrich detection with context. Security Exposure Management builds a high-confidence inventory and exposure graph of an organization's assets across devices, identities, cloud resources, and external attack surfaces, enriching asset data with contextual signals including predefined classifications and criticality levels based on system role and function. This approach enables automatic identification of critical assets and applies deeper, context-aware detections based on each asset's risk profile. Activities that may be routine on general-purpose servers can indicate compromise when observed on Tier-0 systems like domain controllers.

Microsoft Removes Trust for Non-WHCP Kernel Drivers

Microsoft is removing trust for kernel drivers that haven't been through the Windows Hardware Compatibility Program (WHCP) to further secure the Windows kernel. Cross-signed code gets the cold shoulder as Redmond tightens trust. This change aims to reduce the attack surface by ensuring only drivers that have passed compatibility and security testing can run in kernel mode.

General Security News

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Russian state-sponsored threat group TA446 (also tracked as Callisto, COLDRIVER, Star Blizzard, formerly SEABORGIUM) deployed the recently disclosed DarkSword iOS exploit kit in targeted email campaigns. The activity was attributed with high confidence based on analysis by Proofpoint and Malfors. TA446 is assessed to be affiliated with Russia's Federal Security Service (FSB). The campaign uses fake "discussion invitation" emails spoofing the Atlantic Council to deliver GHOSTBLADE dataminer malware via DarkSword. Emails were sent from compromised senders on March 26, 2026. One recipient was Leonid Volkov, a prominent Russian opposition politician. Automated analysis triggered by Proofpoint's security tools redirected to a benign decoy PDF, likely due to server-side filtering targeting only iPhone browsers. This marks the first time TA446 has targeted iCloud accounts or Apple devices. The volume of emails from the threat actor has been significantly higher in the last two weeks. Attacks also deploy MAYBEROBOT backdoor via password-protected ZIP files. A DarkSword loader uploaded to VirusTotal references escofiringbijou[.]com, a second-stage domain attributed to TA446. The targeting was much wider than usual, including government, think tank, higher education, financial, and legal entities, suggesting opportunistic use of the new capability.

Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits

Apple is sending Lock Screen notifications to iPhones and iPads running older versions of iOS and iPadOS to alert users of web-based attacks and urge them to install updates. The notification reads: "Apple is aware of attacks targeting out-of-date iOS software, including the version on your iPhone. Install this critical update to protect your iPhone." This follows the discovery of iOS exploit kits Coruna and DarkSword. Multiple threat actors have leveraged these kits over the past year to deliver malicious payloads when users visit compromised websites. Coruna targets iOS versions 13.0 to 17.2.1, while DarkSword targets iOS versions 18.4 to 18.7. Kaspersky reports Coruna is an evolution of the framework used in Operation Triangulation. The leak of DarkSword on GitHub raises concerns about democratized access to nation-state exploits. Users unable to update are advised to enable Lockdown Mode if available (iOS 16+). Apple stated they are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled device.

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion

Threat actors are using adversary-in-the-middle phishing pages to seize control of TikTok for Business accounts. The campaign uses malicious links directing victims to lookalike pages impersonating TikTok for Business or Google Careers pages with options to schedule calls. Pages perform Cloudflare Turnstile checks to block bots and automated scanners before serving malicious AitM phishing login pages. TikTok has been historically abused to distribute malicious links including multiple infostealers (Vidar, StealC, Aura Stealer) delivered via ClickFix-style instructions with AI-generated videos. Phishing pages are hosted on domains including welcome.careerscrews[.]com, welcome.careerstaffer[.]com, welcome.careersworkflow[.]com, and others. A separate campaign uses Scalable Vector Graphics (SVG) file attachments to deliver malware to targets in Venezuela, with malicious SVGs communicating with URLs that download artifacts associated with BianLian ransomware activity.

FAUX#ELEVATE Malware Targets French-Speaking Professionals via Phishing Résumés

Cyberattackers are targeting French-speaking professionals with fake résumé attachments deploying credential stealers and cryptocurrency miners. The campaign, tracked as FAUX#ELEVATE, uses heavily obfuscated VBScript files disguised as CV documents that execute silently while displaying fake error messages. The malware uses sandbox evasion, persistence techniques, and domain-check mechanisms to ensure only enterprise systems are infected. After gaining elevated privileges, the attack disables security defenses, modifies system settings, and downloads additional payloads from legitimate platforms including Dropbox, Moroccan WordPress sites, and mail[.]ru. The campaign uses a "living-off-the-land" approach, blending malicious activity with trusted services to evade detection. The entire infection chain executes in under 30 seconds. By selectively targeting domain-joined systems, attackers ensure high-value corporate credentials are harvested.

Patch Priority

Vulnerability Disclosures

etcd Authorization Bypass Vulnerabilities

Microsoft Security Update Guide published two etcd vulnerabilities. CVE-2026-33343 involves nested etcd transactions bypassing RBAC authorization checks (EPSS 0.000, 8th percentile). CVE-2026-33413 involves authorization bypasses in multiple APIs (EPSS 0.000, 15th percentile). Organizations running etcd should apply updates.

Microsoft Edge Chromium-Based Vulnerabilities

Microsoft published security updates for Chromium-based Edge addressing multiple vulnerabilities. CVE-2026-4673 is a heap buffer overflow in WebAudio (EPSS 0.001, 21st percentile). CVE-2026-4680 is a use-after-free in FedCM (EPSS 0.001, 32nd percentile). CVE-2026-4677 is an out-of-bounds read in WebAudio (EPSS 0.001, 22nd percentile). CVE-2026-32187 is a defense-in-depth vulnerability. Users should update Microsoft Edge to the latest version.

Trends & Context

Today's threat landscape shows supply chain attacks evolving with sophisticated steganography techniques (TeamPCP's WAV file payloads) and expanding into industrialized ransomware deployment through partnerships with RaaS operations and underground forums. The F5 BIG-IP vulnerability demonstrates the risk of CVE reclassification from DoS to RCE after active exploitation is discovered, emphasizing the importance of monitoring vulnerability advisories for updates even after initial patches. Nation-state iOS exploit kits are leaking to GitHub and being adopted by state-sponsored groups beyond their original operators, democratizing access to previously exclusive capabilities and expanding the mobile threat surface. The convergence of supply chain compromise, credential theft, ransomware-as-a-service, and dark web forum mobilization at the scale demonstrated by TeamPCP/Vect/BreachForums represents an unprecedented shift in threat actor capabilities and reach.