← Carolina Clear Tech

Cyber Threat Brief

2026-04-02

Listen to this brief (18:21)

Download MP3
Show Notes

Show Notes - 2026-04-02

Stories Covered

CVEs Referenced

CVE-2025-14174, CVE-2025-31277, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529, CVE-2025-53521, CVE-2026-20700, CVE-2026-2436, CVE-2026-2441, CVE-2026-33216, CVE-2026-3502, CVE-2026-3909, CVE-2026-3910, CVE-2026-4897, CVE-2026-5119, CVE-2026-5121, CVE-2026-5281

Indicators of Compromise

Domains: sfrclak[.]com, cert-ua[.]tech, 237[.]92., ukr[.]net, cert-ua[.]tech.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-04-02

Today: Google patches the fourth Chrome zero-day of 2026 (CVE-2026-5281, CISA KEV deadline April 15). Axios npm compromise attributed to North Korean state actor Sapphire Sleet with platform-specific RATs. Over 14,000 F5 BIG-IP APM instances remain exposed despite CVE-2025-53521 RCE attacks and federal patching deadline.

Critical Alerts

Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

Google released emergency patches for CVE-2026-5281, a use-after-free vulnerability in Dawn (WebGPU implementation) actively exploited in the wild. This is the fourth Chrome zero-day patched in 2026, following CVE-2026-3909, CVE-2026-3910, and CVE-2026-2441. CISA added CVE-2026-5281 to the KEV catalog on April 1 with a remediation deadline of April 15, 2026 for federal agencies. The vulnerability allows remote code execution through crafted HTML pages after compromising the renderer process. EPSS score is currently low (0.000, 11th percentile), but active exploitation confirms real-world risk.

F5 BIG-IP APM RCE Attacks Ongoing (CVE-2025-53521)

Over 14,000 F5 BIG-IP APM instances remain exposed to CVE-2025-53521 RCE attacks despite CISA's March 31 federal remediation deadline. Originally disclosed in October as a DoS vulnerability, this flaw was reclassified as an RCE bug in March 2026 after F5 confirmed active exploitation. Unauthenticated attackers can achieve remote code execution on unpatched BIG-IP APM systems with access policies configured on virtual servers. EPSS score is 0.414 (97th percentile), indicating extremely high predicted exploitation likelihood. F5 has published IOCs and advises checking device logs, terminal history, and disk contents for compromise. Systems should be rebuilt from known-good sources rather than UCS backups, as persistent malware may exist in backups created after initial compromise.

Axios npm Supply Chain Attack Attributed to North Korean Sapphire Sleet

Microsoft Threat Intelligence attributed the Axios npm compromise to Sapphire Sleet, a North Korean state actor. On March 31, malicious versions 1.14.1 and 0.30.4 were released after a maintainer's npm account was hijacked. The compromised packages inject a hidden dependency ([email protected]) that executes platform-specific remote access trojans (RATs) for Windows, macOS, and Linux via postinstall hooks. The RAT connects to C2 infrastructure at sfrclak[.]com:8000, performs reconnaissance, establishes persistence (Windows registry Run keys, macOS LaunchAgent, Linux cron), and includes self-destruct capabilities for evasion. Microsoft confirms sectors affected include business services, financial services, high tech, healthcare, media, and retail across the US, Europe, Middle East, South Asia, and Australia. AI recruiting startup Mercor confirmed it was breached via this supply chain attack, with LAPSUS$ claiming 4TB of exfiltrated data including biometric identity verification documents.

TrueConf Zero-Day CVE-2026-3502 Exploited in Southeast Asia Government Attacks

Check Point discovered CVE-2026-3502, a zero-day in TrueConf conference servers exploited since early 2026 by suspected Chinese threat actor in "TrueChaos" campaign targeting government entities in Southeast Asia. The medium-severity flaw stems from missing integrity checks in the software's update mechanism, allowing attackers who control on-premises TrueConf servers to replace legitimate updates with arbitrary executables that deploy to all connected clients. The attack chain includes DLL sideloading, reconnaissance tools, UAC bypass via iscicpl.exe, and Havoc C2 implant deployment. TrueConf is used by over 100,000 organizations including military forces, government agencies, oil and gas corporations, and air traffic management companies. Fixed in version 8.5.3 (March 2026). EPSS is minimal (0.000, 1st percentile) but confirmed exploitation makes this critical for TrueConf users.

Apple iOS 18 DarkSword Exploit Kit Protection Expanded

Apple expanded iOS 18.7.7 availability to more devices on April 1 to protect against the DarkSword exploit kit targeting six vulnerabilities (CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520). All six are on CISA's KEV catalog with remediation deadlines between January 2026 and April 3, 2026. DarkSword was used by Turkish commercial surveillance vendor PARS Defense, threat actor UNC6748, and suspected Russian espionage group UNC6353 to deploy GhostBlade infostealer, GhostKnife backdoor, and GhostSaber malware. Previously, only iPhone XS/XR received iOS 18 updates, leaving newer devices on iOS 18 unpatched. The DarkSword exploit kit was published on GitHub in March 2026, making it accessible to additional threat actors.

Ransomware Claims (Last 48h)

6 claims tracked across 3 groups in the last 48 hours.

Group Victim Sector Country
Netrunner Jordan India Fertilizer Company Manufacturing/Agriculture Jordan
Netrunner Harman Fitness Retail/Fitness United States
Netrunner Nippon Medical School Musashi Kosugi Hospital Healthcare Japan
Netrunner Shiraume Hospital Healthcare Japan
Netrunner GEG Telecomunicazioni Telecommunications Italy
Netrunner Seoyon E-Hwa Summit Manufacturing South Korea

Additional claims tracked: Threatmarket claims Lockheed Martin (no details provided), Krybit claims BJ Grupo and kramer-nsc.at.

Sources: RansomLook | RansomLook | RansomLook

Ransomware & Extortion

Qilin Ransomware Dominates Japan in 2025, Targets Healthcare and Manufacturing

Cisco Talos reports Qilin ransomware was responsible for 22 of 134 ransomware incidents in Japan in 2025 (16.4%), four times more than the second-most active group. Total ransomware incidents in Japan increased 17.5% year-over-year. Qilin primarily targets manufacturing (28% of victims), automotive (8%), trading companies (7%), IT (6%), and education (5%), with small and medium-sized enterprises accounting for 57% of victims. The group emphasizes post-compromise activities after gaining initial access via stolen credentials purchased on Telegram and Breach Forums. Qilin affiliates demonstrate high operational maturity with evidence of detailed attack manuals and awareness of penetration testing methodologies. In October 2025, Qilin's leak site listed over 200 victim organizations globally. Healthcare and social assistance sectors are particular targets due to the severe operational impact of ransomware-induced disruptions. Some Qilin affiliates have suspected ties to post-Soviet countries including Baltic states.

Business & Infrastructure Threats

TeamPCP Supply Chain Campaign: Mercor AI First Confirmed Victim, AWS Enumeration Documented

SANS ISC published Update 005 on the TeamPCP supply chain campaign, confirming AI recruiting startup Mercor as the first official victim of the LiteLLM compromise (originally infiltrated via compromised Tailscale VPN credential). LAPSUS$ claims approximately 4TB of exfiltrated data including 939GB source code, 211GB user database, and 3TB of biometric identity verification documents (passports). This has GDPR, CCPA, and potentially HIPAA implications. Wiz Cloud Incident Response Team documented TeamPCP's post-compromise cloud operations: the group uses TruffleHog to programmatically validate stolen AWS access keys, Azure secrets, and SaaS tokens, then transitions to discovery operations within 24 hours. AWS enumeration focuses on IAM roles, EC2 instances, Lambda functions, RDS databases, S3 buckets, and ECS clusters, with conspicuous resource names like "pawn" and "massive-exfil." Flare threat intelligence shows TeamPCP's cloud targeting is 61% Azure and 36% AWS (97% combined).

EvilTokens PhaaS Fuels Microsoft Device Code Phishing at Scale

Sekoia discovered EvilTokens, a malicious phishing-as-a-service kit sold on Telegram that integrates device code phishing to hijack Microsoft accounts. The kit abuses OAuth 2.0 device authorization flow, tricking victims into authorizing malicious devices via QR codes or hyperlinks in emails impersonating financial documents, meeting invitations, logistics orders, or shared documents (DocuSign, SharePoint). Victims are redirected to legitimate Microsoft device login pages where attackers receive short-lived access tokens and refresh tokens for persistent access to email, files, Teams data, and SSO impersonation across Microsoft services. The kit is under continuous development with plans to support Gmail and Okta phishing. Campaigns have global reach with highest impact in the US, Canada, France, Australia, India, Switzerland, and UAE. The variety of campaigns suggests EvilTokens is already being used at scale by phishing and BEC threat actors. Russian groups Storm-237, UTA032, UTA0355, UNK_AcademicFlare, TA2723, and ShinyHunters have previously used device code phishing.

CERT-UA Impersonation Campaign Distributes AGEWHEEZE RAT to 1 Million Emails

Ukraine's CERT-UA disclosed a phishing campaign by threat actor UAC-0255 that impersonated the agency itself to distribute AGEWHEEZE remote access trojan. Emails sent March 26-27 from "incidents@cert-ua[.]tech" targeted state organizations, medical centers, security companies, educational institutions, financial institutions, and software development companies. The ZIP file ("CERT_UA_protection_tool.zip") hosted on Files.fm delivered a Go-based RAT that communicates over WebSockets to 54.36.237[.]92. AGEWHEEZE supports command execution, file operations, clipboard modification, mouse/keyboard emulation, screenshots, and process/service management. Persistence is established via scheduled tasks, registry modifications, or Startup directory. The campaign was largely unsuccessful with only a few infected personal devices identified. The bogus website "cert-ua[.]tech" was likely generated with AI tools, with HTML source including comment "С Любовью, КИБЕР СЕРП" (With Love, CYBER SERP). Threat actor Cyber Serp claims the phishing emails reached 1 million ukr[.]net mailboxes with over 200,000 devices compromised (CERT-UA disputes this). Cyber Serp previously claimed responsibility for breach of Ukrainian cybersecurity company Cipher.

Windows / AD Security

Classic Outlook Email Delivery Failures Linked to Permission Errors

Microsoft is investigating a known issue preventing some Classic Outlook users from sending emails via Outlook.com accounts. Affected users receive non-delivery reports (NDR) with error "You do not have the permission to send the message on behalf of the specified user. Error is [0x80070005-0x0004dc-0x000524]." The issue occurs more frequently when the Outlook.com account is a profile linked to another Exchange account, or when the sender's account has an Exchange Online mail contact with the same SMTP address. Workarounds include removing the M365 account Address Book so Outlook doesn't check it during sends, hiding the Outlook.com contact from the M365 Global Address List, creating a new classic Outlook profile with only the affected account, or using New Outlook client or Outlook.com web interface. Microsoft fixed two other known issues in the last two weeks including Classic Outlook crashes with Teams Meeting Add-in and 0x800CCC0F/0x80070057 sync errors for Gmail and Yahoo accounts.

Patch Priority

Vulnerability Disclosures

CVE-2026-5281 Google Chrome Dawn Use-After-Free (High Severity)

CISA added CVE-2026-5281 to Known Exploited Vulnerabilities catalog on April 1. Use-after-free in Dawn component allows remote code execution via crafted HTML page after compromising renderer process. EPSS 0.000 (11th percentile) but confirmed active exploitation. Fixed in Chrome 146.0.7680.177/178. Federal remediation deadline April 15, 2026.

Source: CISA

CVE-2025-53521 F5 BIG-IP APM Remote Code Execution (Critical Severity)

Originally disclosed in October as DoS vulnerability, reclassified as RCE in March 2026 after confirmed exploitation. Affects BIG-IP APM instances with access policies on virtual servers. EPSS 0.414 (97th percentile). CISA KEV deadline was March 30, but over 14,000 instances remain exposed. Shadowserver tracks 17,100 IPs with BIG-IP APM fingerprints.

Source: BleepingComputer

CVE-2026-3502 TrueConf Zero-Day Update Mechanism Bypass (Medium Severity)

Missing integrity check in TrueConf server update mechanism allows arbitrary file execution on all connected clients. Exploited since early 2026 by suspected Chinese threat actor in TrueChaos campaign targeting Southeast Asia government entities. Affects versions 8.1.0-8.5.2. Fixed in version 8.5.3. EPSS 0.000 (1st percentile).

Source: BleepingComputer

CVE-2025-43529, CVE-2025-43520, CVE-2025-14174, CVE-2025-31277, CVE-2025-43510, CVE-2026-20700 iOS DarkSword Exploit Kit

Six iOS vulnerabilities exploited by DarkSword kit targeting iOS 18.4-18.7. Used by Turkish surveillance vendor PARS Defense, UNC6748, and suspected Russian group UNC6353. All six on CISA KEV catalog with remediation deadlines between January 2 and April 3, 2026. Exploit kit publicly released on GitHub in March 2026. Fixed in iOS 18.7.7 (expanded device availability April 1).

Source: BleepingComputer

Microsoft Security Update Guide CVEs

Microsoft published information on several new vulnerabilities:

Sources: MSRC | MSRC | MSRC | MSRC | MSRC

General Security News

Casbaneiro Banking Trojan Targets Latin America and Europe via Dynamic PDF Lures

Brazilian threat actor Augmented Marauder (Water Saci) is conducting multi-pronged phishing campaigns targeting Spanish-speaking users in Latin America and Europe to deliver Casbaneiro (Metamorfo) banking trojan via Horabot malware. The campaigns use dynamic PDF lures tailored to the targeted organizations.

Source: The Hacker News

Malicious Script Removes Alternate Data Streams to Evade Detection

SANS ISC handler documented malicious script that removes Windows :Zone.Identifier alternate data stream (ADS) to evade DFIR investigations. After copying itself to %APPDATA%\Microsoft\Windows\Templates\dwm.cmd and creating Run key persistence, the script uses PowerShell to remove the ADS that indicates file origin (0=My Computer, 1=Local intranet, 2=Trusted sites, 3=Internet, 4=Restricted sites). Contrary to some LLM outputs, Windows copy operations do preserve ADS. The script later deploys DonutLoader via PowerShell.

Source: SANS ISC

CrowdStrike Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management

CrowdStrike announced Falcon for IT now supports Windows Secure Boot certificate lifecycle management, helping organizations maintain Secure Boot integrity across their Windows device fleets.

Source: CrowdStrike

Trends & Context

Supply chain attacks dominate today's threat landscape with two major campaigns: Axios npm compromise by North Korean Sapphire Sleet demonstrates nation-state actors weaponizing trusted JavaScript libraries with platform-specific RATs, while the ongoing TeamPCP/LiteLLM campaign continues expanding with Mercor as the first confirmed victim and documented AWS enumeration TTPs. Zero-day exploitation remains consistent with four Chrome zero-days patched since January and TrueConf zero-day targeting government infrastructure. Healthcare and manufacturing sectors face disproportionate ransomware pressure from Qilin and Netrunner groups, with Japan experiencing 17.5% year-over-year increase in incidents. Federal patching deadlines for Chrome (April 15) and F5 BIG-IP (already passed March 30) create urgency, yet over 14,000 BIG-IP instances remain vulnerable.