CTO at NCSC Summary: week ending March 22nd
UK registered organisations can apply for a share of up to £5 million for collaborative projects that enable adoption of the Government's Software Security Code of Practice
Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do. A community member is doing daily AI generated podcast of the last 24hours of posts.
Operationally this week nothing of note..
In the high-level this week:
Secure Software for Resilient Growth - Innovate UK, part of UK Research and Innovation (UKRI) announce - “UK registered organisations can apply for a share of up to £5 million for collaborative projects that enable adoption of the Government's Software Security Code of Practice to drive growth of secure and resilient software supply chains.” .. “total grant funding request must be between £250,000 and £750,000.”
Smart personal assistant for security researchers - HMGCC challenge - “But before the expert analysis can begin, there’s a significant bottleneck: finding, indexing and understanding the vast amount of open-source technical information that exists about complex industrial machinery. HMGCC Co-Creation are launching this challenge to develop a software tool to Technology Readiness Level 6, that works without an internet connection and can assist a security researcher to index, search and understand vast quantities of data faster, enabling faster decision making”
UK and Ireland agree updated Memorandum of Understanding on bilateral defence cooperation - Ministry of Defence and The Rt Hon John Healey MP - “This rebooted Memorandum of Understanding modernises our framework for cooperation on areas critical to both our nations’ security, in particular to counter the growing undersea and cyber threats we share.”
Making public services work for you with your digital identity - Cabinet Office and The Rt Hon Darren Jones MP outline - “The government intends to introduce a national digital ID (identity document) system. This will sit at the heart of next-generation digital public services in the UK and support innovation in the wider economy. It will help unlock entirely new ways to offer goods and services, and be key to making people’s interactions with the state as efficient and useful as those they are accustomed to in the private sector, like online banking.”
Annual Threat Assessment of The U.S. Intelligence Community - Director of National Intelligence publishes - “Cyber actors from China, Russia, Iran, North Korea, and ransomware groups will continue to pose critical threats to U.S. networks and critical infrastructure. These global cyber actors almost certainly will continue malicious cyber activities because they gain unmatched intelligence collection value and financial incentives from these operations. These cyber adversaries also have the ability to pre-position or execute disruptive and destructive attacks against U.S. critical infrastructure and other targets. They continue to pour resources into operations to compromise U.S. systems and core global IT resources.”
Press Conference by Chief Cabinet Secretary Kihara - Prime Minister’s Office of Japan announces that it is to allow ‘proactive cyber-defense’ from October 1st
Japan to allow ‘proactive cyber-defense’ from October 1st - The Register reports - “Kihara said a government cyber-management committee will have the power to approve or deny applications to commence cyber-ops. If authorized, Japan’s police and SDF will “attack and disable” infrastructure used to run cyberattacks, while working to ensure citizens’ privacy.”
Cyber attacks inflicted $220 mln losses on Russia, says Kyiv - TVP World reports- “ Ukraine has said its offensive cyber operations last year inflicted $220 million worth of damage on Russia in direct losses. In a post on Facebook, the General Staff of the Ukrainian Armed Forces said Russia’s indirect losses as a result of the operations exceeded $1.5 billion.”
White House pours cold water on cyber ‘letters of marque’ speculation - Alexander Martin reports - “The Trump administration is not considering cyber “letters of marque” or allowing private companies to carry out cyberattacks on behalf of the U.S. government, senior White House officials said this week, pushing back on growing speculation about the role of industry in U.S. cyber operations.”
Poland says foiled cyberattack on nuclear centre may have come from Iran - Reuters reports - “Poland has foiled a cyberattack on its nuclear research centre and is examining signs that Iran may be behind it, the government said on Thursday, cautioning the indicators might be a deliberate misdirection to hide the attackers’ true location.”
Why Alignment Matters: Cyber Capabilities and Military Operational Schemes in All-Domain Operations - Cyber Defence Review publish - “When planning beforehand and assessing afterwards, alignment with an operational scheme is a key variable. Cyber capabilities and operations are not one-size-fits-all. This article offers a framework and illuminates the importance of alignment or misalignment with a brief examination of how Russia employed cyber operations in Ukraine from 2015 through the opening weeks of its 2022 full-scale invasion. We conclude that poor alignment of cyber capabilities with Russia's warfighting scheme limited the operational impact of cyber means.”
Officials worry Salt Typhoon apathy is killing momentum for tougher telecom security rules - CyberScoop reports - “Last year, a former intelligence official at the Office of the Director of National Intelligence told CyberScoop that a lack of outrage from the public following the Salt Typhoon attacks was dampening momentum for broader regulation or reforms to telecom cybersecurity.”
Resetting Cyber Relations with the United States - Carnegie Endowment for International Peace think tank - “U.S. alignment with like-minded states remains stable. Most importantly, the United States has not reopened or diluted its position that existing international law applies to cyberspace, a cornerstone of the UN cyber consensus.”
Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation - US Government Office of Accountability audit - “DOD’s initial efforts raised concerns within the DIB about the complexity of the framework, the number of requirements, and the costs of meeting those requirements. Particularly concerning were the costs for independent third-party assessments to determine if a DIB company met the requirements. Many of these concerns were held by small businesses, which represent roughly three-quarters of the DIB. In November 2021, DOD announced a refined and streamlined CMMC program framework that included estimated costs for assessments—ranging from $4,042 to $117,768 depending on the type of assessment performed—and phased implementation to allow companies time to understand the requirements and prepare.”
Belgium launches its own secure messaging app for defense and civil servants - DeMorgen reports - “Belgium has developed its own secure messaging app for the government. The app, Beam, is intended to be used by approximately 750,000 civil servants and military personnel in the long term and is meant to replace apps such as WhatsApp and Messenger for work-related communication.”
Simplifying cybersecurity reporting: The Digital Omnibus Single-Entry Point mechanism - European Parliament think tanks - “the Digital Omnibus – a legislative initiative that amends several existing EU digital rules to harmonise requirements and reduce the regulatory burden in digital governance – proposes the implementation of a Single-Entry Point (SEP) mechanism. SEP aims to streamline compliance by allowing companies to fulfil multiple mandatory reporting obligations under various EU laws through a unified process.”
Six European countries criticize plan for EU cyber incident reporting system - Mlex reports - “France, Germany, Italy, the Netherlands, Spain and Sweden have jointly pushed back against the European Commission’s proposal to set up a single EU channel for reporting cybersecurity incidents, arguing that it risks complicating the process”
NIS 2: ANSSI continues and strengthens its support dynamic - ANSSI announce - “ReCyF, the Cyber France Reference Framework, which lists the measures recommended by the Agency to achieve the security objectives set by NIS 2 and guides the implementation of good practices.”
Reporting on/from China
EU sanctions Chinese and Iranian companies for cyberattacks - Reuters reports - “The European Union on Monday imposed sanctions against two China-based and one Iranian company for cyberattacks against EU member states. The EU listed China-based Integrity Technology Group and Anxun Information Technology, and Iranian company Emennet Pasargad.”
Cyberspace Mapping and Counter-Mapping: The Offensive and Defensive Game and Evolution of Digital Territory - Cyberspace Mapping Committee of the Chinese Society for Command and Control outline - “Cyberspace surveying and counter-surveying, as core means of digital domain offense and defense, are gradually evolving into key forces for ensuring national cybersecurity and supporting the efficient operation of various digital systems.”
China’s Management of Electromagnetic Spectrum Resources - US China Economic and Security Review Commission publish - “China’s approach to managing its electromagnetic spectrum resources has generated a number of benefits, including rapid deployment of 5G technologies, a highly active spectrum research field, and expanded influence in international markets. The relative centralization of its spectrum management authorities is also likely to improve the People’s Liberation Army’s joint warfighting capabilities in the future.”
AI
Getting the Measure of AI - UK National Physical Laboratory publishes - “we hosted a Scientific Meeting at Bushy House last year, bringing together experts from government, industry and academia, to examine how we build confidence in AI through robust measurement. We have now published a report that captures the key insights and sets out a path forward.”
Measuring AI Agents’ Progress on Multi-Step Cyber Attack Scenarios - UK AI Security Institute publish - “The best single run completed 22 of 32 steps, corresponding to roughly 6 of the estimated 14 hours a human expert would need. On the industrial control system range, performance remains limited, though the most recent models are the first to reliably complete steps, averaging 1.2-1.4 of 7 (max 3).”
The Attack and Defense Landscape of Agentic AI: A Comprehensive Survey - Various Universities publish - “Our work also introduces the first systematic framework for understanding the security risks and defense strategies of AI agents, serving as a foundation for building both secure agentic systems and advancing research in this critical area.”
We Scanned 1,808 MCP Servers. 66% Had Security Findings. - AgentSeal content market - “Code execution risks were the most common. These are tools whose descriptions or configurations enable arbitrary command execution on the host machine.”
Emergent Cyber Behavior: When AI Agents Become Offensive Threat Actors - Irregular hyperbole - “But that same autonomy introduces a risk most security teams aren't modeling for: the agent itself becoming a threat actor.” - they are not threat actors, they are malfunctioning systems..
Meta Is Developing 4 New Chips to Power Its AI and Recommendation Systems - WIRED reports - “Meta partnered with Broadcom to develop its latest semiconductors, which are built on top of the open-source RISC-V architecture. They’re being fabricated by Taiwan Semiconductor Manufacturing Corporation”
Amazon wins order blocking access for Perplexity’s AI shopping ‘agent’ - Reuters reports - “U.S. District Judge Maxine Chesney said on Monday, opens new tab that Amazon can likely prove that Perplexity's tool, which utilizes automation to place online shopping orders, unlawfully accesses Amazon user accounts without its permission.”
Cyber proliferation
Convicted Spyware Dealer Links Greek Government to Surveillance Scandal - OCCRP publish - “The founder of the commercial spyware firm Intellexa, recently convicted in a landmark wiretapping trial, says his company sells its technology exclusively to governments—an admission opposition leaders claim proves the state orchestrated a massive domestic espionage campaign.”
Mythical Beasts: Investigating the role of intermediaries in the proliferation of offensive cyber capabilities - Atlantic Council publish - “The opacity of this market subsection poses policy challenges and complicates efforts to regulate these entities. This undermines transparency, accountability, compliance, and due diligence, and threatens to enable the unchecked proliferation of these capabilities to end users who abuse them.”
Bounty Hunting
FBI Seeking Victim Information in Steam Malware Investigation - FBI seeks - “The FBI’s Seattle Division is seeking to identify potential victims installing Steam games embedded with malware. The FBI believes the threat actor primarily targeted users between the timeframe of May 2024 and January 2026. In the investigation, several games have been identified to include, BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova.”
Authorities disrupt world’s largest IoT DDoS botnets responsible for record breaking attacks targeting victims worldwide - US Department of Justice announces - “During the operation, the Department of Defense Office of Inspector General’s (DoDIG) Defense Criminal Investigative Service (DCIS) executed seizure warrants which targeted multiple U.S.-registered internet domains, virtual servers, and other infrastructure allegedly engaged in cyber-enabled criminal activity, including DDoS attacks against IP’s owned by the Department of Defense Information Network (DoDIN).”
Cyber-attacks against the EU and its member states: Council sanctions three entities and two individuals - Council of the EU announces - “The Council adopted today restrictive measures against three entities and two individuals responsible for cyber-attacks carried out against EU member states and EU partners. The Council has listed Integrity Technology Group, a China-based company, that has routinely provided products used to compromise and access devices in EU members states, across Europe and worldwide. Between 2022 and 2023, through their technical and material support, more than 65,000 devices were hacked across six member states.”
Market Incentives
FSS moves to sanction Seoul Guarantee Insurance over ransomware outage - Chosun Biz reports- “The Financial Supervisory Service is preparing to refer Seoul Guarantee Insurance Company, which was unable to provide key services after a ransomware attack last year, to the sanctions review committee. Once the review is completed, the level of sanctions against Seoul Guarantee Insurance Company is expected to be decided.”
Reflections this week are around the amount of capital which is flooding into agentic cyber defence. This supports our hypothesis that cyber security will be a net beneficiary from AI due to more people wanting to do good than bad.
This week alone we saw:
AI cybersecurity startup RunSybil, founded by OpenAI’s first security hire, raises $40 million led by Khosla Ventures - “The company’s AI agent, Sybil, conducts continuous autonomous penetration tests against live applications—finding, exploiting and documenting real security vulnerabilities without humans in the loop. That’s different from other security tools currently making headlines, such as Claude Code Security, which analyzes source code in applications for known vulnerabilities before it is deployed.”
Kai Emerges from Stealth with $125M, Powering Machine-Speed Defense to Outpace AI-Enabled Adversaries - “Kai has built the first agentic AI cybersecurity platform designed to autonomously reason, act, and adapt at machine speed, transforming security teams from overwhelmed responders into superhuman proactive defenders, capable of keeping pace with AI-driven attacks.”
Armadin Secures Record-Breaking $189.9M in Seed and Series A Funding to Combat the Era of AI-Driven Hyperattacks - “Unlike tools that scan for vulnerabilities, Armadin's platform features specialized AI agents leveraging custom models in an agentic attacker swarm. These agents continuously reason, plan, and adapt like the most advanced human threat actors and provide CEOs and Boards with decision-grade proof of what can actually be exploited.”
Then when we factor in:
AI Security Startup Xbow Valued at More Than $1 Billion - “DFJ Growth and Northzone led the $120 million financing deal in Xbow, the company said Wednesday. Other participants included Alkeon Capital and Sofina, as well as previous backers Sequoia Capital, Altimeter Capital and NFDG.”
That’s a lot of capital against the problem of scaled cyber defence. Which when you then consider against the reports of:
Anthropic in Talks With Blackstone, Other PE Firms to Form AI Consulting Venture - “The partnership would aim to sell the Claude maker's technology to companies backed by the investment firms, the report said, citing a person involved in the discussions and another individual who was briefed about it.”.. “If finalised, the partnership would adopt a Palantir-style model to offer consulting services to help companies integrate Anthropic's AI into their operations, the report said.”
Hints that human-machine teaming is going to arrive, at scale, in cyber security and beyond and likely at some pace..
.. we just need to just make sure that defence in depth around these agentic systems keep pace and we don’t loose sight of the importance of identity, access management, observability and machine speed containment when the agents malfunction ..
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Russian Intelligence Services Target Commercial Messaging Application Accounts
FBI and CISA have issued this alert around alleged Russian activity which has been reported by other countries.
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are jointly issuing this public service announcement (PSA) to warn the public about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services (RIS) targeting commercial messaging applications (CMAs). RIS actors have compromised individual CMA accounts, but not CMAs' encryption or the applications themselves. The activity targets individuals of high intelligence value, such as current and former U.S. government officials, military personnel, political figures, and journalists.
https://www.ic3.gov/PSA/2026/PSA260320
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
Ctrl-Alt-Intel detail what they found on alleged Russian related infrastructure. Noteworthy for the scale.
Building on initial reported findings, Ctrl-Alt-Intel discovered a second exposed open-directory</strong> on the same server. One that contained FancyBear’s C2 source code, additional payloads, telemetry logs, exfiltrated data and evidence of further campaigns. What we found inside was staggering:
2,800+ emails exfiltrated from government and military mailboxes
240+ sets of stolen credentials, including passwords and TOTP 2FA secrets
140+ Sieve forwarding rules silently redirecting every incoming email to an attacker-controlled mailbox
11,500+ contact email addresses harvested from victim address books, mapping entire communication networks
https://ctrlaltintel.com/threat%20research/FancyBear/
related APT28 / FancyBear Phishing Framework
https://github.com/ctrlaltint3l/intelligence/tree/main/FancyBear/roundish
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency
Jyoti Karlekar, Bineesh P and Sanjay Katkar detail an alleged Russian campaign which is noteworthy due to the very real impact here for cross-site scripting. The new sanitizer API and setHTML is the answer here among other things…
Seqrite Labs identified a targeted phishing campaign that exploits a cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) to compromise a Ukrainian government entity. The phishing email has no malicious attachments, no suspicious links, no macros. The entire attack chain lives inside the HTML body of a single email, there are no malicious attachments.
https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
LAB52 detail an alleged Russian campaign which is using LNK files. Noteworthy for regional focus and victimology - but everyone should be blocking .LNK files from email..
LAB52, the intelligence team at S2 Group, has identified a new campaign targeting Ukrainian entities, attributed to actors linked to Russia. The campaign, observed during February 2026, employs various judicial and charity themed lures to deploy a JavaScript‑based backdoor that runs through the Edge browser and has been named DRILLAPP by LAB52. This artifact enables the attacker to carry out several actions on the target, such as uploading and downloading files, using the microphone, or capturing images through the webcam by leveraging the browser’s capabilities.
Reporting on China
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
Lior Rochberger and Yoav Zemah detail an alleged Chinese operation which is noteworthy due to the dwell without activity.
We identified a cluster of malicious activity targeting Southeast Asian military organizations, suspected with moderate confidence to be operating out of China. We designate this cluster as CL-STA-1087, with STA representing our assessment that the activity is conducted by state-sponsored actors. We traced this activity back to at least 2020.
The activity demonstrated strategic operational patience and a focus on highly targeted intelligence collection, rather than bulk data theft. The attackers behind this cluster actively searched for and collected highly specific files concerning military capabilities, organizational structures and collaborative efforts with Western armed forces.
The objective-oriented tool set used in the malicious activity includes several newly discovered assets: the AppleChris and MemFun backdoors, and a custom Getpass credential harvester.
..
The initial infection vector remains undetermined. Following the identification of the persistence mechanism, the environment appeared to be dormant for several months, with no observable malicious activity. We assess that the attackers deliberately maintained their foothold in the environment, waiting for an opportune moment to resume their operations.
https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/
China-nexus Threat Actor Targets Persian Gulf Region With PlugX
Sudeep Singh and Yin Hong Chang detail a campaign which is noteworthy for the regional focus although the tradecraft on show is extremely basic..
[We] observed activity by a China-nexus threat actor targeting countries in the Persian Gulf region.
The campaign used a multi-stage attack chain to deploy a PlugX backdoor variant on infected systems.
The shellcode and PlugX backdoor used obfuscation techniques such as control flow flattening (CFF) and mixed boolean arithmetic (MBA) to hinder reverse engineering.
The PlugX variant in this campaign supports HTTPS for command-and-control (C2) communication and DNS-over-HTTPS (DOH) for domain resolution.
Reporting on North Korea
StoatWaffle, malware used by WaterPlum
Rintaro Koike detail some alleged North Korean tradecraft which is a little rinse and repeat..
Team 8 leverages a project related to blockchain as a decoy. This malicious repository contains
.vscodedirectory that contains tasks.json file. If a user opens and trusts this malicious repository with VSCode, it reads this tasks.json file.
https://jp.security.ntt/insights_resources/tech_blog/stoatwaffle_malware_en/
Kimsuky malware uses the Dropbox API
Naoki Takayama details an alleged North Korean operation using LNK files which again evidences by they should be blocked via email..
In March 2026, IIJ observed an LNK file containing malware. Analysis revealed that the observed malware shared many similarities, including TTPs and implementation, with the malware used in the Kimsuky attack campaign 1 previously reported by the AhnLab Security Intelligence Center (ASEC) . The malware transmits information about infected hosts via the Dropbox API and has the capability to execute subsequent malware specified by the attacker. This article shares the detailed analysis results of the malware.
https://sect.iij.ad.jp/blog/2026/03/dropbox-api-kimsuky-malware/
Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators
Kmsec details an alleged North Korean operation which is noteworthy for victimology but also the need to up the quality of defence in source package eco-systems.
The Contagious Trader campaign is a novel tranche of malware operations I attribute to North Korea/Lazarus with high confidence
The campaign is highly active and consists of malicious cryptocurrency trading bot projects on GitHub that advertise enticing yields
These GitHub projects are designed to exfiltrate sensitive files and/or private keys using a variety of techniques, including malicious npm dependencies.
Several tactics, techniques, and procedures from Contagious Trader are consistent with North Korea and FAMOUS CHOLLIMA, however attribution to a specific actor under the nebulous Lazarus moniker is withheld
IOCs: ~30 GitHub repositories (some taken down, more to be found), 37 npm packages, 23 domains/IPs, 5 operator IPs, and more
https://kmsec.uk/blog/contagious-trader/
Reporting on Iran
Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2
Hunt.io disclose
A 15-node relay network exposed by a single TLS certificate. Pivoting on a shared certificate fingerprint surfaced 15 servers, seven hosted on Hetzner in Finland and seven registered to Iranian ISPs.
On-host compilation to dodge binary detection. Rather than pushing pre-built binaries, the operator compiled DDoS tools directly on victim machines using gcc. The compiled bot client was also renamed “hex” on infected hosts.
SSH mass deployment driven by a credential list. A Python script called ohhhh.py reads credentials in a host:port|username|password format and opens 500 concurrent SSH sessions, compiling and launching the bot client on each host automatically.
The bash history documented the full operation. The exposed .bash_history captured three distinct phases of work: standing up the tunnel network, building and testing DDoS tooling against live targets, and iterative botnet development across multiple script versions.
The same infrastructure runs censorship bypass and attack tooling. The config-client.yaml file confirms the host forwards traffic to a Hetzner exit node via KCP tunneling, while the same server staged all botnet and DDoS components.
Bots reconnect automatically after disconnection. Strings recovered from the compiled binary explicitly reference reconnection logic, meaning infected hosts should be treated as independently compromised regardless of whether the C2 is reachable.
https://hunt.io/blog/iran-botnet-operation-open-directory
Reporting on Other Actors
Operation CamelClone: Multi-Region Espionage Campaign Targets Government and Defense Entities Amidst Regional Tension
Jyoti Karlekar, Bineesh P and Sanjay Katkar detail an unattributed campaign which is noteworthy the regions of focus, victimology and its C2 and exfil infrastructure.
Industries Affected
Government agencies
Defense and military organizations
Foreign affairs and international cooperation departments
Policy and diplomatic institutions
Energy and strategic resource sectors
Geographical Focus
Algeria
Mongolia
Ukraine
Kuwait
One interesting aspect of this campaign is that the threat actor does not rely on traditional command-and-control infrastructure. Instead, the payloads are hosted on a public file-sharing service, filebulldogs[.]com, while stolen data is uploaded to MEGA storage using the legitimate tool Rclone.
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Maristel Policarpio, Junestherry Dela Cruz, Sarah Pearl Camiling, Jacob Santos, Don Ovid Ladores
Our recent monitoring revealed that the Warlock ransomware group has enhanced its attack chain, including improved methods for persistence, lateral movement, and evasion.
Warlock’s updated toolset, which includes TightVNC, and Yuze, along with a persistent BYOVD technique exploiting the NSec driver, helps it mask its spread across networks.
Based on the group’s leak site from the second half of 2025, among the most targeted industries were technology, manufacturing, and government, while the US, Germany, and Russia were the countries most targeted.
https://www.trendmicro.com/en_us/research/26/c/dissecting-a-warlock-attack.html
Katana: a Mirai variant that compiles its own rootkit on Android TV set-top boxes
Nokia Deepfield Emergency Response Team (ERT) detail a operation which is noteworthy for its size and apparent sophistication / operational considerations.
At least 30,000 active bots based on network observations (lower-end estimate). The botnet is actively operational as of March 2026, with observed attack volumes reaching 150 Gbps. For context, 30,000 bots in a single DDoS botnet would have been exceptional as recently as early 2025; the rapid growth of ADB-targeting botnets over the past year has normalized fleet sizes that were previously associated only with the largest operations.
Aggressive environment control. A locker process binds to ADB port 5555 and kills any new process not present at boot, blocking rival bots and forensic tools. The bot disables 100+ system utilities via bind-mount blocking and remaps the ADB port, locking out both competitors and device owners (who, in fairness, did not know they were offering unauthenticated root shell access to their home network).
No scanner, no credential table. External ADB exploitation scripts handle propagation entirely. This is a pure DDoS payload.
Rootkit compilation on-device. The APK ships 5 architecture-specific bot binaries plus TinyCC and rootkit source code, compiling a kernel module (
wlan_helper.ko) on each target device. The module hooks 5 syscalls to hide the bot from process listings, prevent file deletion, and block signal delivery. Mirai derivatives almost never ship kernel modules; this is a notable escalation — though we have observed rival operators successfully removing Katana from devices, suggesting the rootkit’s reach exceeds its grasp.Encrypted C2 with runtime domain rotation. Three domains are encrypted via a custom 5-step cipher; a fourth (
iloveyourweewee[.]bz) is delivered at runtime. All resolve, at the time of writing, to bulletproof hosting at Omegatech (Seychelles). The C2 can push new domains without redeploying binaries.3-day self-destruct removes all persistence if C2 is unreachable, cleaning up SysVinit scripts, cron jobs, and bot binaries.
11 DDoS attack methods including protocol-specific floods targeting FiveM game servers (CitizenFX API), SSH services (PuTTY banner spoofing), MySQL authentication, SMTP relay, IRC, FTP, LDAP, TeamSpeak 3, and Valve Source Engine.
https://github.com/deepfield/public-research/blob/main/katana/report.md
Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads
Ionut Alexandru BALTARIU and Silviu STAHIE show the advertising eco-system have more to do to up their game..
A malicious Google ad impersonated Claude Code.
The fake site mirrored official Claude Code documentation.
Windows users executed malware through mshta.exe.
macOS users downloaded a Mach-O backdoor via obfuscated shell commands.
Bitdefender detects the Windows payload as Trojan.Stealer.GJ, Trojan.Stealer.GK, IL:Trojan.MSILZilla.245316 and Gen:Variant.Barys.509034
The attackers likely abused a compromised advertiser account linked to a Malaysian company.
The fake documentation page was hosted on a Squarespace subdomain.
https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware
Vishing Campaigns Lead to Data Theft and Extortion
Unit42 detail a socially engineered led operation which should create the business case for phishing resistant authentication (i.e. FIDO2)
Since late December 2025, Unit 42 has responded to numerous incidents across various industries involving voice-based phishing (vishing) that led to data theft and extortion.
We’ve observed activity targeting organizations within the Financial Services, Manufacturing, Professional & Legal Services, and Wholesale & Retail sectors
- Based on our observations, most of this activity is likely associated with Bling Libra (aka ShinyHunters) or threat actors affiliated with the broader Scattered LAPSUS$ Hunters alliance.
In one 2025 case, we saw the threat actors move from access to impact (data exfiltration) in less than 60 minutes.
The threat actors initiate contact through highly targeted vishing, typically sourcing employee details from professional social networks.
The “Passkey” Lure: Attackers impersonate internal IT staff, greeting employees by name and citing a mandatory deadline to set up an SSO “passkey.”
Mobile Redirection: To evade corporate firewalls and URL inspection tools, victims are instructed to use a mobile device to navigate to a visually identical phishing domain.
STIR/SHAKEN Compliance: Rather than spoofing numbers, which often triggers “Potential Spam” alerts, they use legitimate numbers with fraudulent Caller Name (CNAM) records to appear as “IT Staff.”
Malware distribution using fake FileZilla sites
Alyac4 details how fake websites are being maintained in order to achieve initial access.
Discovery
How we find and understand the latent compromises within our environments.
Building a Detection Foundation: Part 3 - PowerShell and Script Logging
Carlos Perez articulates why you will want to ensure you have appropriate logging turned on proactively..
PowerShell offers three complementary logging mechanisms. I recommend enabling all of them.
1. Module Logging (Event ID 4103)
2. Script Block Logging (Event ID 4104)
3. Transcription
https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-logging
Building a Pipeline for Agentic Malware Analysis
Tim Blazytko walks through how to do it and provides a perspective on the value
As we’ve seen, agents are already changing reverse engineering in a significant way. In this post, even the unstructured run was already useful as a first triage: it recovered visible functionality, pointed to relevant code locations, and produced concrete leads for follow-up. The real improvement, however, came from giving the agent a structured workflow, persistent case state, and the right analysis tooling. This also shows where agents are already particularly strong: scaling the mechanical parts of analysis, collecting evidence, correlating artifacts, generating scripts, and producing a first structured understanding of a binary far faster than a human could.
And we are still early. Models, tools, and agentic workflows are improving quickly, and the current generation already shows how much repetitive reverse-engineering work can be automated. Over time, this will likely push human analysts away from manually performing every step themselves and more toward guiding workflows, validating results, refining assumptions, and deciding where deeper analysis is needed.
https://synthesis.to/2026/03/18/agentic_malware_analysis.html
Defence
How we proactively defend our environments.
ANSSI is launching a call for comments on the reference architectures of its new security monitoring doctrine
ANSSI is undertaking a call for comments around its security monitoring doctrine..
This call for comments is open to the entire ecosystem supported by ANSSI, including both beneficiaries and providers of security monitoring services and products. The results of this consultation will inform the ongoing drafting of the Agency's monitoring doctrine documents, specifically regarding the architectures and technical components that comprise them. The deadline for responding to this call for comments is Thursday, May 7, 2026 .
..
The Agency wishes to offer a wider variety of examples of secure monitoring architectures, taking into account in particular the current challenges of cloud hosting, service delegation and technological diversity of products
https://cyber.gouv.fr/actualites/lanssi-lance-un-appel-a-commentaires-supervision-de-securite/
CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization
CISA urges …
CISA is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.1 To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.
To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune
Incident Writeups & Disclosures
How they got in and what they did.
When Trust Becomes the Attack Vector: Analysis of the EmEditor Supply-Chain Compromise
Parth Jamodkar walks through this most fascinating case of a supply chain attack..
This is not a traditional malware delivery campaign. The distinguishing characteristics include:
Server-side conditional manipulation rather than client-side redirection
Weaponization of a legitimate MSI installer
Use of Windows Installer custom actions to execute in-memory payloads
Credential theft via named pipe injection without dropping additional executables.
Vulnerability
Our attack surface.
Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
nyxgeek highlights how even the most resourced companies are struggling with logging coverage..
By sending a specially crafted login attempt to the Azure authentication endpoint, it was possible to retrieve valid tokens without the activity appearing in the Entra ID sign-in logs. This is critical logging…logging that administrators across the world rely on to detect intrusions…logging that could be made optional.
https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found
Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)
Adiel Sol makes it feel like it is the 90s again.. or the 2000s.. or the 2010s…
The telnetd server has a buffer overflow in the LINEMODE SLC (Set Local Characters) suboption handler. An unauthenticated attacker can trigger it by connecting to port 23 and sending a crafted SLC suboption with many triplets. No login is required; the bug is hit during option negotiation, before the login prompt. The overflow corrupts memory and can be turned into arbitrary writes. In practice this can lead to remote code execution. Because telnetd usually runs as root (e.g. under inetd or xinetd), a successful exploit would give the attacker full control of the system.
https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root
Saeed Abbasi shows Qualys still has some excellent unix VR talent. Also challenges the premise of many eyes at least as a timely means of ensuring cyber security.
the flaw has existed since 2017 (version v4.11)
..
The confused deputy problem in the vulnerabilities released allows an unprivileged user to load, replace, or remove arbitrary AppArmor profiles by writing to the pseudo‑files /sys/kernel/security/apparmor/.load, .replace, and .remove.
The consequences would be as follows, for example:
Removing key profiles (e.g., rsyslogd, cupsd) removes protection against remote attackers.
Loading a “deny‑all” profile for sshd blocks legitimate SSH access.
Offense
Attack capability, techniques and trade-craft.
EDR killers explained: Beyond the drivers
Jakub Souček walks through the current state..
EDR killers are a fundamental part of modern ransomware intrusions; affiliates prefer a short, reliable window to run encryptors rather than constantly modifying payloads.
Affiliates, not operators, pick the EDR killers; larger affiliate pools lead to greater tooling diversity.
The same driver appears in unrelated tools, and the same tool can migrate between drivers. Consequently, driver-based attribution to groups is often misleading.
Packer as a service and “EDR killer as a product” increase availability, muddy attribution, and add defense complexity.
EDR killers implement defense evasion techniques, while encryptors focus purely on encryption.
We strongly suspect that AI assisted with the development of some EDR killers, and we provide a concrete example with the Warlock gang.
While BYOVD dominates, custom scripts, anti-rootkits, and driverless EDR killers are utilized as well.
https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/
Bypassing EDR in a Crystal Clear Way
Lorenzo Meacci provides a walk through which detection engineering teams will want to ensure they have coverage of.
The offensive security community is overwhelmingly focused on the delivery layer and almost completely ignores the reflective loading layer. You see posts about novel injection primitives, creative process selection, elaborate staging mechanisms. Very few people talk about what happens after the shellcode executes. That is the gap this blog is trying to close.
https://lorenzomeacci.com/bypassing-edr-in-a-crystal-clear-way
FrontHunter
Sterven releases a tool which will be of use to a number. If you know a domain can be use for domain fronting you can factor it into reputation scores if you see its use in your environment..
FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.
https://github.com/st3rven/fronthunter
VMkatz
NK releases this work aid which defence teams will want to be aware of..
Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
Decrypting and Abusing Predefined BIOCs in Palo Alto Cortex XDR
Manuel Feifel releases this research which highlights some now resolved global bypasses. Github repo appears to be been removed however..
The Windows Cortex XDR agent uses CLIPS rules for behavioral detections. These rules are shipped encrypted in content updates. We decrypted these rules and discovered numerous hardcoded exceptions including global whitelists that can be abused to bypass those rules. For example, if a process’s command-line arguments contain
:\Windows\ccmcache, it is excluded from about half of all behavioral detections. This allows an attacker, for example, to dump LSASS using simple, well-known
https://labs.infoguard.ch/posts/decrypting-and-abusing_paloalto-cortex-xdr_behavioral-rules_biocs/
Exploitation
What is being exploited..
Interlock ransomware campaign targeting enterprise firewalls
Amazon disclose active the active exploitation of what was a zero-day in an enterprise firewall by a ransomware group..
Amazon threat intelligence has identified an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device, which was disclosed by Cisco on March 4, 2026.
..
our research found that Interlock was exploiting this vulnerability 36 days before its public disclosure, beginning January 26, 2026.
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers
Fantastic unwind information and where to find them
Alessandro Magnosi does what they do best with this release..
This post presents BYOUD (Bring Your Own Unwinding Data), a new framework that works within CET’s constraints by targeting a different layer entirely: Windows unwind metadata. The techniques described here were developed to answer a simple question: can we spoof call stacks without touching return addresses at all?
https://klezvirus.github.io/posts/Byoud/
https://github.com/klezVirus/byoud
Elastic Agent Skills
Elastic release..
curated skills that are packages of instructions, context, and tooling that teach any AI agent how to correctly work with Elasticsearch, Kibana, Elastic Observability, and Elastic Security. Drop them into the agent runtime you already use, and your assistant stops using outdated patterns and starts getting it right.
https://github.com/elastic/agent-skills
YaraVM
Milankovo published this a couple of years ago but it got published today..
an IDA processor for loading and disassembling compiled yara rules.
https://github.com/milankovo/YaraVM
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week, but keep an eye on the Awesome Annual Security Reports 2026 collection
Systematic Security Analysis of the Iridium Satellite Radio Link
Artificial intelligence
Fundamental
Applied non-cyber
Applied cyber specific
The Attack and Defense Landscape of Agentic AI: A Comprehensive Survey
CacheSolidarity: Preventing Prefix Caching Side Channels in Multi-tenant LLM Serving Systems
AgenticCyOps: Securing Multi-Agentic AI Integration in Enterprise Cyber Operations
NVIDIA NemoClaw: Reference Stack for Running OpenClaw in OpenShell
Co-pilot, disengage autophish: the new phishing surface hiding inside ai email summaries
Books
Events
RE/verse - videos now online
U.S.–ROK Cyber Cooperation: Countering North Korean Cybercrime and Strengthening Active Cyber Defense - March 25th, Washington, D.C.
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.




