CTO at NCSC Summary: week ending March 8th
NCSC advises UK organisations to take action following conflict in the Middle East
Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do.
Operationally this week NCSC advises UK organisations to take action following conflict in the Middle East
In the high-level this week:
NCSC advises UK organisations to take action following conflict in the Middle East - NCSC advises - “In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture.”
Cyber Essentials management information - Department for Science, Innovation and Technology publish -” Figures showing the number of Cyber Essentials certificates awarded, by quarter.” - now including - “The latest figures show 55,995 Cyber Essentials certificates have been awarded over the past year (January 2025 to December 2025); 42,288 at CE level and 13,707 at CE+.”
Launch of the Global Coalition on Telecoms 6G Security and Resilience Principles - Department for Science, Innovation & Technology announce - “The Global Coalition brings together the governments of the UK, US, Canada, Japan and Australia. At Mobile World Congress 2026, the Global Coalition was pleased to welcome the governments of Sweden and Finland as new members, strengthening the collective impact of this group to ensure secure, resilient and innovative telecommunication networks.” - NCSC continued in its role as the National Technical Authority for cyber security in support of the development of these principles.
President Trump’s Cyber Strategy for America - The White House publishes -
1. Shape Adversary Behavior
2. Promote Common Sense Regulation
3. Modernize and Secure Federal Government Networks
4. Secure Critical Infrastructure
5. Sustain Superiority in Critical and Emerging Technologies
6. Build Talent and Capacity
Israel says it knocked out Iran’s cyber warfare headquarters - Politico reports - “The Israel Defense Forces on Wednesday said it bombed a compound in Tehran housing Iran’s cyber warfare headquarters — but it’s unclear whether the strike will significantly kneecap Iran’s cyberattack capabilities.”
Fog, Proxies and Uncertainty: Cyber in US-Israeli Operations in Iran - RUSI think tanks - “As Operations Epic Fury and Roaring Lion develop, several dimensions of cyber activity demand attention and careful qualification.”
Assessing the Impact of Ransomware Interventions and Countermeasures: A Framework - Virtual Routes and RUSI think tank - “Counter-ransomware efforts benefit from greater clarity about what kind of change an intervention is intended to produce. Too often, interventions are discussed in terms of the tools deployed rather than the effects sought, with success assessed only retrospectively.”
FBI investigating ‘suspicious’ cyber activity on system holding sensitive surveillance information - FBI investigates - “The bureau is working to determine the scope and impact of the problem, according to a notification sent to members of Congress that says the unnamed culprit is using sophisticated techniques to exploit FBI network security controls.”
US Senate requests on TEMPEST - Senator Wyden writes a letter - “We write to request that the Government Accountability Office (GAO) conduct an investigation of the serious national security threat described in the attached unclassified report produced by the Congressional Research Service (CRS). As the CRS report notes, GAO conducted a prior review related to this issue in 1986, but that GAO review did not assess the efficacy of the government’s efforts to counter this threat, nor has GAO conducted a follow-up review since.”
Intelligence Annual Report 2026 - The Security Intelligence System of the Republic (Italy) publish - “the current Annual Report is based on the premise that technological transformation is the key to understanding the contemporary security landscape. The document does not describe individual technologies or events, but offers a unified framework for understanding the evolution of threats, identifying system vulnerabilities, and strengthening the capacity for prevention and risk management.”
Financial Stability Oversight Council Annual Report 2025 - Financial Stability Oversight Council publish - “Fourth, the Council will focus on crisis preparedness. Through this new workstream, the Council will support interagency efforts to prepare for cyberattacks or disruptions at critical service providers, including through the potential acquisition of quantum technology by threat actors. The Council’s work will also assess potential threats to financial stability from other kinds of technological advancements and geopolitical risks.”
Cyber Threat Landscape for the Nordic Financial Sector 2026 - Nordic Financial CERT publish - “In 2025, activity has increasingly centred on exploiting systemic weaknesses across interconnected ecosystems. These activities are becoming standard components of criminal intrusion playbooks rather than extraordinary tradecraft”
A New Era for Global Cybersecurity Governance: The UN’s “Global Mechanism” Launches in 2026 - Center for Cyber Diplomacy and International Security think tank - “The March organizational session will set the structural foundations of the new mechanism — its agenda, working methods, and the role of non-governmental stakeholders like civil society, the private sector, and academia. How inclusive the mechanism proves to be will say a great deal about whether it can generate legitimacy beyond governments.”
Framework cryptography policy for the Central Government - Netherlands Ministry of the Interior and Kingdom Relations publish - “This document describes the generic aspects of preparing cryptography policies within the Central Government. It is intended to provide government bodies with relevant frameworks that guide the processes, architecture, and design principles surrounding cryptography.”
SCI Semiconductor Announces First Silicon of Cybersecure MCU, ICENI™ - SCI Semiconductor announce - “SCI Semiconductor, the UK-based company pioneering cyber-resilient microcontroller (MCU) solutions for security-critical use cases, today announces first silicon availability of its ICENI cybersecure MCU family, the world's first commercial CHERI implementation in silicon.”
Reporting on/from China
Deep incursions and safe grounds. - NetAskari asserts - “It is clear over the past few years that Chinese security services are increasingly looking beyond its borders and run big data acquisition operations that feed a ever growing big-data analysis system, powered by the steady improvement in Artificial Intelligence.”
China’s new five-year plan calls for AI throughout its economy, tech breakthroughs - Reuters reports - “China chases breakthroughs in AI, chips, space, nuclear and quantum. Hopes AI will transform manufacturing, boost productivity . China to invest in basic research, building STEM talent base - China’s new five-year policy blueprint laid out its ambitions to aggressively adopt artificial intelligence throughout the world’s second-biggest economy and dominate emerging technologies such as quantum computing and humanoid robots.”
AI
Government to create new lab to keep UK in the fast lane on AI breakthroughs - Department for Science, Innovation and Technology, UK Research and Innovation and Kanishka Narayan MP announce - “
New government-backed lab will support transformational AI breakthroughs to be made in UK – with the country’s AI experts invited to pitch their biggest ideas
up to £40 million for blue sky AI research that UK researchers are perfectly placed to pursue, plus access to large-scale computing power to drive cutting-edge research
fundamental research could tackle the basic flaws that still plague AI models, like hallucinations, short memory and unpredictability – and unlock new capabilities for AI
Hardening Firefox with Anthropic’s Red Team - Mozilla show the security upside begins - “In addition to the 22 security-sensitive bugs, Anthropic discovered 90 other bugs, most of which are now fixed. A number of the lower-severity findings were assertion failures, which overlapped with issues traditionally found through fuzzing, an automated testing technique that feeds software huge numbers of unexpected inputs to trigger crashes and bugs. However, the model also identified distinct classes of logic errors that fuzzers had not previously uncovered.”
Partnering with Mozilla to improve Firefox’s security - Anthropic publish
Codex Security: now in research preview - OpenAI also show the security upside of AI begins - “Today we’re introducing Codex Security, our application security agent. It builds deep context about your project to identify complex vulnerabilities that other agentic tools miss, surfacing higher-confidence findings with fixes that meaningfully improve the security of your system while sparing you from the noise of insignificant bugs.”
Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files - CheckPoint highlight the lack of secure by design and defence in depth - “The vulnerabilities exploit various configuration mechanisms including Hooks, Model Context Protocol (MCP) servers, and environment variables -executing arbitrary shell commands and exfiltrating Anthropic API keys when users clone and open untrusted repositories.”
Brainworm - Hiding in Your Context Window - Mitchell Turner makes the case for telemetry - “promptware that infects computer-use agents like Claude Code using only natural language, and can receive natural language tasking from our C2, Praxis.”
Call for expressions of interest for testing a GDPR audit tool for AI models - ANSSI issue - “More specifically, the objective of the tool is to enable efficient and cost-effective implementation of certain technical tests for extracting information from training data that AI ecosystem actors may need to perform to assess the status of an AI model with regard to the European General Data Protection Regulation (GDPR).”
US Supreme Court declines to hear dispute over copyrights for AI-generated material - Reuters reports - “The U.S. Supreme Court declined on Monday to take up the issue of whether art generated by artificial intelligence can be copyrighted under U.S. law, turning away a case involving a computer scientist from Missouri who was denied a copyright for a piece of visual art made by his AI system.”
Emergent Intelligence: Spycraft and Intelligence in the AI Era - CIA publishes - “The concepts presented in this paper rely heavily on substantial advances in AI’s ability to process, analyze, and combine extensive and varied datasets. Furthermore, we acknowledge that concurrent progress in other related technologies will be equally important for the success of these concepts.“
Cyber proliferation
Spyware suppliers exploit more zero-days than nation states - Computer Weekly reports - “In a report titled Look what you made us patch: 2025 zero-days in review, the GTIG team said that of 42 unique zero-days it tracked in 2025, it was able to firmly attribute first exploitation of 15 to commercial surveillance vendors (CSVs), compared with 12 that were first exploited by nation-states – seven by China, and nine by financially motivated cyber criminals.”
Italian prosecutors confirm journalist was hacked with Paragon spyware - Tech Crunch report - “Italian authorities confirmed that a journalist who was alerted by WhatsApp last year of a suspected spyware attack on his phone was indeed hacked.”
Bounty Hunting
Project Compass: A project dedicated to fighting against The Com - Europol updates (Feb 26th) - “4 victims safeguarded, 30 perpetrators arrested*, 62 identified and partially identified victims, 179 identified and partially identified perpetrators, 9 joint awareness-raising activities”
Online predator pleads guilty to hacking social media accounts and extorting hundreds of teens and young adults - US Department of Justice announce - “Jamarcus Mosley pled guilty this week to charges of computer fraud, extortion, and cyberstalking after tricking hundreds of young victims into giving him control to their social media accounts, accessing their private images and videos, and threatening to release those items if they did not comply with his demands, including sending him sexually explicit material.”
United States Leads Dismantlement of One of the World’s Largest Hacker Forums - US Department of Justice announce - “According to an affidavit unsealed on March 3, the LeakBase forum had over 142,000 members and more than 215,000 messages between members.”
Global phishing-as-a-service platform taken down in coordinated public-private action - EuroPol announce - “A major phishing-as-a-service platform used to bypass multi-factor authentication (MFA) and enable large-scale account compromise has been disrupted following a coordinated international operation supported by Europol.”
Preventing the theft of 30 billion Bitcoin... Supreme Prosecutors’ Office distributes virtual asset management plan - The Joongang reports - “The Supreme Prosecutors’ Office has developed a cryptocurrency seizure management manual and distributed it to prosecutors’ offices nationwide. The goal is to prevent a recurrence of the 30 billion won Bitcoin theft incident at the Gwangju District Prosecutors’ Office. The manual requires users to only check their cryptocurrency virtual account balances using the official website and to keep their digital wallets and encryption keys separate.”
Market Incentives
MythBusters: Purchasing cyber insurance doesn’t change your risk of an attack - Marsh (an insurance broker) busts myths - “The point estimates before time 0 confirmed that the firms we wanted to compare indeed had no difference in ransomware attacks before the purchase of insurance, ensuring comparability.”
Draft Commission guidance on the Cyber Resilience Act - European Commission publish for feedback - “The guidance will help manufacturers, developers, and other stakeholders understand their obligations under the Regulation and ensure a consistent approach across the EU. It will clarify how key provisions of the CRA should be interpreted and implemented.”
Man Spent $20,000 on PlayStation Games. He Lost It All to a Security Loophole - PC Mag report - “Most disturbingly, I was able to essentially hack my own PlayStation account with ease in about 30 minutes by messaging the company's "PlayStation Online Assistant" chatbot. The registered passkey didn't matter at all.”
Reflections this week come from having spent two days in Spain for Mobile World Congress. From using cell towers as radars to detect drones, network analysis of cellular traffic to detect drones, real-time detection of SMS blasters from network telemetry, Integrated Sensing and Communication (ISAC) in 6G, to space and more space. Then there was the AI and the robotics… When you see the future you can see the inherent challenges around cyber security and ensuring the resilience of the systems against adversarial interest.
Beyond that watch Living Human Brain Cells Play DOOM on a CL1 from Cortical Labs. Hopefully it stimulates some thought about what these hybrid systems mean for cyber assurance in the future..
Finally - the death of Felix “FX” Lindner was announced this week. A reminder that time is finite yet impact can be forever..
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow
ClearSky Research Team disclose this alleged Russian operation which is noteworthy for the extremely basic initial access tradecraft.
The attack chain initiates with a phishing email containing a link to a ZIP archive. Once extracted, an initial HTA file displays a lure document written in Ukrainian concerning border crossing appeals to deceive the victim. Simultaneously, the infection triggers the download of BadPaw, a .NET-based loader. Upon establishing command-and-control (C2) communication, the loader deploys MeowMeow, a sophisticated backdoor.
https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/
UAC-0252 cyberattacks using SHADOWSNIFF and SALATSTEALER stealers
Ukraine CERT detail this alleged Russian operation which is noteworthy for actually leveraging cross-site-scripting whilst ever other aspect appears gloriously basic and rushed.
Since January 2026, CERT-UA has recorded frequent cases of distribution of emails, allegedly on behalf of central executive authorities and regional administrations, calling for updating mobile applications of widely used civilian and military systems.
The email may contain an attachment in the form of an archive containing an EXE file, or a link to a legitimate website that is vulnerable to XSS (Cross-site scripting), which, when visited, will execute JavaScript code and download the executable file to your computer. The EXE files and scripts are hosted on the legitimate GitHub service.
During January-February 2026, the use of the following software tools for implementing cyber threats was confirmed:
SHADOWSNIFF (a stiller from GitHub)
SALATSTEALER (MaaS stealer)
DEAFTICK (primitive backdoor for Go)
https://cert.gov.ua/article/6287707
Reporting on China
Silver Dragon Targets Organizations in Southeast Asia and Europe
Check Point Research detail this alleged Chinese operation which serves as a reminder of the value of great external attack surface management (see NCSC’s buyers guide). Also the face they are using Google Drive for C2 should be noted..
[We] are tracking Silver Dragon, an advanced persistent threat (APT) group which has been actively targeting organizations across Europe and Southeast Asia since at least mid-2024. The actor is likely operating within the umbrella of Chinese-nexus APT41.
Silver Dragon gains its initial access by exploiting public-facing internet servers and by delivering phishing emails that contain malicious attachments. To maintain persistence, the group hijacks legitimate Windows services, which allows the malware processes to blend into normal system activity.
As part of its recent operations, Silver Dragon deployed GearDoor, a new backdoor which leverages Google Drive as its command-and-control (C2) channel to enable covert communication and tasking over a trusted cloud service. In addition, the group deployed two additional custom tools: SSHcmd, a command-line utility that functions as a wrapper for SSH to facilitate remote access, and SliverScreen, a screen-monitoring tool used to capture periodic screenshots of user activity.
UAT-9244 targets South American telecommunication providers with three new malware implants
Asheer Malhotra and Brandon White detail an alleged Chinese full court press on telecommunications networks in South America. The use of the BitTorrent protocol is noteworthy..
[We are] disclosing UAT-9244, who we assess with high confidence is a China-nexus advanced persistent threat (APT) actor closely associated with Famous Sparrow.
Since 2024, UAT-9244 has targeted critical telecommunications infrastructure, including Windows and Linux-based endpoints and edge devices in South America, proliferating access via three malware implants.
The first backdoor, “TernDoor,” is a new variation of the previously disclosed, Windows-based, CrowDoor malware.
Talos also discovered that UAT-9244 uses “PeerTime,” an ELF-based backdoor that uses the BitTorrent protocol to conduct malicious operations on an infected system.
UAT-9244’s third implant is a brute force scanner, which Talos tracks as “BruteEntry.” BruteEntry is typically installed on network edge devices, essentially converting them into mass-scanning proxy nodes, also known as Operational Relay Boxes (ORBs) that attempt to brute force into SSH, Postgres, and Tomcat servers.
https://blog.talosintelligence.com/uat-9244/
Tracking CyberStrikeAI Usage
Will Thomas alleges an open-source artificial intelligence (AI) offensive security tool has ties to the Chinese government. Noteworthy if true..
we are diving into CyberStrikeAI, an open-source artificial intelligence (AI) offensive security tool (OST) developed by a China-based developer who we assess has some ties to the Chinese government.
..
Further, Ed1s0nZ’s GitHub activities indicate they interact with organisations that support potentially Chinese government state-sponsored cyber operations. This includes Chinese private sector firms that have known ties to the Chinese Ministry of State Security (MSS).
https://www.team-cymru.com/post/tracking-cyberstrikeai-usage
Before the Proxy: Uncovering Active PlugX Staging Infrastructure Linked to Three PRC Actors
Mike discloses a whole set of alleged Chinese malicious infrastructure whilst explaining how he surfaced it..
Recent analysis of PlugX malware samples has identified 14 domains assessed to be part of ongoing PRC espionage activity consistent with threat actors designated as Mustang Panda, UNC6384, and RedDelta. The majority of these domains have not been publicly reported as of the publication of this post.
PlugX Meeting Invitation via MSBuild and GDATA
Lab52 disclose the initial access of an alleged Chinese operation. Noteworthy for using a watering hole attack and then a whole of rather basic laydown..
In this case, during the deployment of PlugX, the G DATA antivirus executable (Avk.exe) is used to load the malicious DLL Avk.dll via DLL side-loading. In the case analysed by LAB52, the infection chain begins with a phishing email titled “Meeting Invitation” followed by a date. The content includes two links:
A URL redirecting to the Ministry of Foreign Affairs of Iceland.
A URL allowing the download of a .zip file containing two files:
Invitation_Letter_No.02_2026.csproj
Script used to download and execute artifacts.
Invitation_Letter_No.02_2026.exe
MSBuild.exe, used as a LOLBIN to execute the script that downloads and runs the software (.csproj).
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
Reporting on North Korea
APT37 Adds New Capabilities for Air-Gapped Networks
Seongsu Park details an alleged North Korean capability which is noteworthy for the store and forward nature using USB. Also noteworthy is the use of Ruby..
In December 2025, ThreatLabz discovered Ruby Jumper, a campaign orchestrated by APT37, a DPRK-backed threat group.
ThreatLabz discovered RESTLEAF, an initial implant that uses Zoho WorkDrive for C2 communications to fetch additional payloads, like SNAKEDROPPER.
ThreatLabz discovered SNAKEDROPPER, a next-stage loader that installs the Ruby runtime, establishes persistence, and drops THUMBSBD and VIRUSTASK.
ThreatLabz discovered THUMBSBD, a backdoor that uses removable media to relay commands and transfer data between internet-connected and air-gapped systems.
ThreatLabz discovered VIRUSTASK, a removable media propagation tool that infects removable media by replacing files with malicious LNK shortcuts.
ThreatLabz discovered FOOTWINE, a backdoor delivered later in the attack chain with surveillance capabilities such as keylogging and audio/video capturing.
North Korean Hackers Compromised Multiple Crypto Organisations
Ctrl-Alt-Intel disclose due to poor operational security and alleged North Korean operation run against crypto currency organisation. Noteworthy was the exploitation of known front end vulnerabilities and AWS access tokens for initial access.
Exploitation of React2Shell (CVE-2025-55182) against crypto staking platforms; use of pre-obtained valid AWS access tokens against a separate crypto-exchange AWS tenant
https://ctrlaltintel.com/threat%20research/DPRK-Crypto-Heist/
Reporting on Iran
Iranian APT Espionage Op Exposed
Ctrl-Alt-Intel show what you can find with regards to alleged Iranian operations when you are unconstrained. Of note are the list of vulnerabilities they were attempting to exploit.
We identified and dumped C2 tooling, scripts, logs, victim data, and other operational artefacts from a VPS hosted in the Netherlands. Ctrl-Alt-Intel assesses with high-confidence this server is operated by MuddyWater (also tracked as Static Kitten, Mango Sandstorm, Earth Vetala, Seedworm, TA450), a cyber espionage group attributed as a subordinate element within Iran’s Ministry of Intelligence and Security (MOIS).
This blog details the reconnaissance, initial access, command and control, and post-exploitation tradecraft observed - including 3+ developed C2s, a Tsundere Botnet using Ethereum smart contracts, and the targeting of organisations across Israel, Jordan, Egypt, the UAE, Portugal, and the United States.
MuddyWater attempted to scan and/or exploit the below CVEs:
CVE-2026-1731 - BeyondTrust RCE
CVE-2026-1281 - Ivanti Endpoint Manager Mobile (EPMM) code injection
CVE-2025-68613 - n8n expression authenticated RCE
CVE-2025-55182 - React2Shell
CVE-2025-52691 - SmarterTools SmarterMail unrestricted file upload
CVE-2025-54068 - Laravel Livewire RCE
CVE-2025-9316 - N-Central improper access control
CVE-2025-5777 - Citrix NetScaler memory leak
CVE-2025-34291 - Langflow chained account takeover + RCE
CVE-2024-55591 - Fortinet FortiOS authentication bypass
CVE-2024-23113 - Fortinet FortiOS RCE
CVE-2022-42475 - Fortinet FortiOS RCE
https://ctrlaltintel.com/threat%20research/MuddyWater/
Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company
Symantec and Carbon Black detail an alleged Iranian operation targeting interests in the US and Israel. Of note is the use of rclone to attempt to exfiltrate data…
Activity associated with Iranian APT group Seedworm has been spotted on the networks of multiple U.S. companies. The activity began in February 2026 and has continued in recent days.
A U.S. bank, airport, non-profit and the Israeli operations of a U.S. software company were among the targets.
We round up details of recent Iranian cyber threat activity and what defenders need to look out for.
…
There was also an attempt to exfiltrate data from the software company using Rclone t
https://www.security.com/threat-intelligence/iran-cyber-threat-activity-us
Dust Specter APT Targets Gov’t Officials in Iraq
Sudeep Singh details a slightly historic intrusion campaign and the implants and tradecraft on show from this alleged Iranian threat actor. Various things of note including AI being leveraged in code production, attempt evasion as well as in memory PowerShell execution.
In January 2026, ThreatLabz observed activity by a suspected Iran-nexus threat actor, tracked as Dust Specter, targeting government officials in Iraq by impersonating Iraq’s Ministry of Foreign Affairs.
Iraq government–related infrastructure was compromised and used to host malicious payloads distributed as part of this campaign.
Dust Specter used randomly generated URI paths for command-and-control (C2) communication with checksum values appended to the URI paths to ensure that these requests originated from an actual infected system. The C2 server also utilized geofencing techniques and
User-Agentverification.ThreatLabz observed several fingerprints in the codebase indicating that Dust Specter leveraged generative AI for malware development.
ThreatLabz identified two attack chains with different previously undocumented malware tooling.
The first attack chain includes SPLITDROP, a .NET-based dropper that drops TWINTASK and TWINTALK to continue the next stage of the attack.
The second attack chain uses GHOSTFORM, a .NET-based RAT that consolidates all the functionality of the first attack chain into one binary and uses in-memory PowerShell script execution.
GHOSTFORM uses creative evasion techniques such as invisible Windows forms along with timers to delay its own execution.
https://www.zscaler.com/blogs/security-research/dust-specter-apt-targets-government-officials-iraq
Fake VCs target crypto talent in a new ClickFix campaign
Moonlock Lab Team detail an another social engineering front loaded campaign allegedly from North Korea. Nothing overly of note other than the end to end was caught..
A coordinated malware campaign is targeting cryptocurrency professionals through LinkedIn social engineering, fake venture capital firms, and fraudulent video conferencing links.
The attack chain culminates in a ClickFix-style fake CAPTCHA page that tricks victims into executing clipboard-injected commands in their Terminal.
The campaign is cross-platform by design, delivering tailored payloads for both macOS and Windows.
Behavioral and operational indicators are consistent with tactics previously attributed to DPRK-aligned threat actors targeting the cryptocurrency sector, though definitive attribution remains open.
https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign
Reporting on Other Actors
Hydra Saiga: Covert Espionage and Infiltration of Critical Utilities
Pol Thill details an alleged Kazakhstani threat actor which we don’t see often in these summaries. The victimology of energy, legal and similar are of note..
Hydra Saiga (also known as Yorotrooper or ShadowSilk) has been active since at least 2021 and remains a significant, resilient threat as of late 2025.
..
The actor employs a mix of custom implants (written in Rust, Go, and Python) and “Living off the Land” techniques, recently adapting to bypass modern defenses like Chrome’s app-bound encryption.
https://www.vmray.com/hydra-saiga-covert-espionage-and-infiltration-of-critical-utilities/
InstallFix: How attackers are weaponizing malvertized install guides
Jacques Louw details an operation which is noteworthy given the likely success due to the interest in the technology.
Attackers are distributing almost identical cloned sites of popular developer tools like Claude Code with fake install instructions via malicious search engine ads — tricking victims into installing infostealer malware instead.
https://pushsecurity.com/blog/installfix/
Inside a fake Google security check that becomes a browser RAT
Stefan Dasic details an interesting campaign due to the sophistication in framing but also that Google hadn’t nuked a domain with Google in.
A website styled to resemble a Google Account security page is distributing what may be one of the most fully featured browser-based surveillance toolkits we have observed in the wild.
Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device’s contact list, real-time GPS location, and clipboard contents—all without installing a traditional app.
For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording.
Using archive.org to deliver malware
Kirk details a campaign using steganography which is always noteworthy due to the detection challenges if done well.
In late February 2026, a cross-reference between URLhaus and Tria.ge sandbox data surfaced an active campaign abusing archive.org as a payload delivery platform. The operator hides .NET injector DLLs inside 4K wallpaper JPEGs using steganography. The images render normally in any viewer; the malicious payload sits after the JPEG end-of-file marker. A daily recompile-and-upload cycle distributes fresh payloads across four Gmail-linked archive.org accounts, delivering two RAT families in parallel: Remcos and AsyncRAT.
http://www.derp.ca/research/archive-org-stego-campaign/
Discovery
How we find and understand the latent compromises within our environments.
mquire
Alessandro Gario, Dan Guido and Henrik Brodin releases this powerful capability which addresses a gap seen in other approaches.
mquire can analyze Linux kernel memory snapshots without requiring external debug symbols.
Everything needed for analysis is already embedded in the memory dump itself. This means you can analyze:
Unknown or custom kernels you’ve never seen before
Any Linux distribution without preparation
Memory snapshots where external debug symbols are unavailable or lost
https://github.com/trailofbits/mquire
MESH Forensics
Ovi, Dan Staples and Josh Hamwee from BARGHEST - a non-governmental organisation - are building capability to detect spyware. This capability is interesting for several reasons. First is the actual use case it is intended for. The second is however malicious. You can see how others may try and co-opt some of this functionality into malware.
MESH Forensics enables remote mobile forensics over an encrypted, censorship-resistant peer-to-peer mesh network.
Mobile devices are often placed behind carrier-grade NAT (CGNAT), firewalls, or restrictive mobile networks that prevent direct inbound access. Traditional remote forensics typically requires centralized VPN servers or risky port-forwarding.
MESH Forensics solves this by creating an encrypted peer-to-peer overlay and assigning each node a CGNAT-range address via a virtual TUN interface. Devices appear as if they are on the same local subnet — even when geographically distant or behind multiple NAT layers.
This enables remote mobile forensics using ADB Wireless Debugging and libimobiledevice, allowing tools such as WARD, MVT, and AndroidQF to operate remotely without exposing devices to the public internet.
https://github.com/BARGHEST-ngo/MESH
Nemesis 2.2
Will Schroeder and Lee Chagolla-Christensen, with a little help from the National Cyber Security Centre, make Nemesis a defensive power tool.
One of the meta-goals with this development cycle was to build functionality into Nemesis that would make it useful from a defensive perspective. Specifically, if a system is compromised or we get access to exfiltrated data, we want to triage all the data and determine the “risk” it represents, i.e., what kind of data does an attacker have access to and what additional access could the attacker gain using the data (e.g., credentials or lateral movement opportunities). Nemesis 2.2 can help provide answers to that, and it provides collaborative analysis workflows (as a team or with AI) to help with the triage. We want to thank the United Kingdom’s National Cyber Security Centre (NCSC) for helping to fund this development effort that produced all this great new defensive functionality!
https://specterops.io/blog/2026/02/25/nemesis-2-2/
Defence
How we proactively defend our environments.
Jailer: an eBPF-based process jailing system
David Papp inspired by the Meta work which has yet to be released implements similar functionality with this early release.
Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies on file access, network operations, and process execution.
https://github.com/gen0sec/jailer
MacNoise
v1n releases a massively powerful tool to help detection engineers ensure systems and approaches are working as intended.
MacNoise is an extensible and modular macOS system telemetry generation framework. It generates real system events (network connections, file writes, process spawns, plist mutations, TCC permission probes, and more) so security teams can validate that their EDR, SIEM, and firewall tooling detects what it is supposed to detect.
https://github.com/0xv1n/macnoise
TTPRunner
Anton releases an interesting approach which will one can expect refine over time as the frontier models continue to improve.
Autonomous TTP execution agent for purple team operations. Feed it a threat report. It builds the attack plan. You approve. It executes.
https://github.com/Antonlovesdnb/TTPRunner
What Windows Server 2025 Quietly Did to Your NTLM Relay
Decoder details a security win which should hopefully encourage upgrades..
The classic cross-DC coerce + relay to LDAPS technique, abusing a misconfigured LmCompatibilityLevel (0/1/2) to generate NTLMv1 + ESS and strip the MIC, is dead when the victim DC runs Windows Server 2025.
And it’s not just a policy change.
It’s hardcoded in msv1_0.dll.
https://decoder.cloud/2026/02/25/what-windows-server-2025-quietly-did-to-your-ntlm-relay/
ICS (Calendar invite) Phishing Toolkit
Jon Gaulding releases this tool which will be of use to various blueteams mitigate this social engineering technique.
This toolkit for remediating malicious calendar invites is designed to help teams using email security solutions that don't natively remediate these attacks.
Stack-specific standalone scripts (e.g.,
proofpoint-microsoft365.py,mimecast-google-workspace.py) are provided for each combination of these email security providers and calendar providers:Email security providers:
Proofpoint
Mimecast
Abnormal Security
Calendar providers:
Microsoft 365
Google Workspace
https://github.com/sublime-security/ics-phishing-toolkit
Android 17 Enable CT by default
Google announces a change which will potentially have an impact on security researchers requiring them to use Frida or similar.
If an app targets Android 17 or higher, certificate transparency (CT) is enabled by default. (On Android 16, CT is available but apps had to opt in.)
How to securely deploy agents that make sensitive decisions autonomously
Joshua Saxe walks through…
Incident Writeups & Disclosures
How they got in and what they did.
North Korea Tried to Hack Our CEO Through a Fake Job Interview on LinkedIn
Christian Papathanasiou details the end to end attempt here.. a warning to al CEOs and wider CxO family.. I love the idea that many CEOs have SSH keys..
A “recruiter” on LinkedIn asked me to clone a repo and open it in VS Code for a “technical assessment”
I got suspicious, told them to fuck off, then downloaded the repo in an isolated VM to investigate
It was North Korean state-sponsored malware with 3 independent infection vectors that executes the moment you open the folder
We captured and reverse-engineered 3 stages of the malware before the operators detected us and triggered a kill switch
The endgame: steal your crypto wallets, browser passwords, SSH keys, env secrets — everything
https://allsecure.io/blog/lazarus-linkedin-attack/
Vulnerability
Our attack surface.
From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)
Olivier Laflamme demonstrates that we have year to get secure by default into robotic eco-systems.
Both PoCs are triggered by pressing a keybinding on the physical controller. That was a big goal of ours and made buying the $400 controller feel worth it 😭. More importantly, the controller trigger makes the RCE persistent
https://boschko.ca/unitree-go2-rce/
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
Piotr Bazydlo details..
The vulnerabilities we discovered are:
CVE-2025-40552 / WT-2025-0099 - Authentication Bypass
CVE-2025-40553 / WT-2025-0100 - Remote Code Execution via Deserialization
CVE-2025-40554 / WT-2025-0101 - Authentication Bypass
Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)
McCaulay Hudson details..
On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 - a recently disclosed “Incorrect Permission Assignment for Critical Resource” vulnerability affecting Juniper’s Junos OS Evolved platform. This vulnerability affects only Juniper’s PTX Series of devices, apparently.
We already have enough clues to begin making this an interesting side quest:
No authentication,
The word “should” is generally pretty exciting, and
Unauthenticated
Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files
Aviv Donenfeld and Oded Vanunu show secure by default in the AI eco-system needs continued focus..
[We] discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various configuration mechanisms including Hooks, Model Context Protocol (MCP) servers, and environment variables -executing arbitrary shell commands and exfiltrating Anthropic API keys when users clone and open untrusted repositories. Following our disclosure, Check Point Research collaborated closely with the Anthropic security team to ensure these vulnerabilities were fully remediated. All reported issues have been successfully patched prior to this publication.
Delinea Protocol Handler - Return of the MSI: RCE via Custom Launcher
David Cash and Richard Warren detail this vulnerability in a cyber security product..
The Protocol Handler suffers from a Remote Code Execution vulnerability in the
sslauncher://URL handler due to improper sanitisation of server-supplied launcher data. This could be exploited by a malicious actor to execute arbitrary processes on a victim’s machine.
https://blog.amberwolf.com/blog/2026/february/delinea-protocol-handler---return-of-the-msi/
Avira: Deserialize, Delete and Escalate - The Proper Way to Use an AV
Lucas Laise details three vulnerabilities in a cyber security product..
Three vulnerabilities in Avira Internet Security, from an arbitrary file delete primitive to two distinct paths to SYSTEM privileges.
https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets
Quang Le and team detail an interesting heuristic which will have winder application..
A step-by-step guide to exploiting a 20-year-old bug in the Linux kernel to achieve full privilege escalation and container escape, plus a cool bug-hunting heuristic.
But perhaps the most interesting aspect is the bug-finding heuristic it demonstrates: when a mutex holder sleeps, the time window between lock release and the next critical operation becomes predictable and stretchable, turning otherwise unexploitable code sequences into reliable race conditions.
blog.calif.io/p/a-race-within-a-race-exploiting-cve
TimeAfterFree
Manousos releases a capability which will (or should) cause some web hosting platforms to shudder.
PHP 8 sandbox escape PoC demonstrating a
disable_functionsbypass on Unix-like systems.
https://github.com/m0x41nos/TimeAfterFree
CVE-2026-29000: Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key
Amartya Jha details a vulnerability in a component which which will require some clean-up…
pac4j-jwt, a widely used Java authentication library.
https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key
Offense
Attack capability, techniques and trade-craft.
OAuth redirection abuse enables phishing and malware delivery
Microsoft Defender Security Research Team details a technique which will
Microsoft observed phishing-led exploitation of OAuth’s by-design redirection mechanisms. The activity targets government and public-sector organizations and uses silent OAuth authentication flows and intentionally invalid scopes to redirect victims to attacker-controlled infrastructure without stealing tokens. Microsoft Defender flagged malicious activity across email, identity, and endpoint signals. Microsoft Entra disabled the observed OAuth applications; however, related OAuth activity persists and requires ongoing monitoring.
ASPX Web Shell with COFF Loader
Eugenie Potseluevskaya releases this anti-forensics capability whilst highlighting the value of being to detect in memory payloads.
This ASPX web shell enables execution of Beacon Object Files (BOFs) on a target server using a semi-interactive Python client.
https://github.com/epotseluevskaya/ASPX_WebShell_COFFLoader
Offensive DPAPI With Nemesis
Will Schroeder and Lee Chagolla-Christensen release a capability chain that teams will want to ensure they have detections for.
entire DPAPI decryption chain – from SYSTEM/user masterkeys through CNG keys to Chromium’s latest App-Bound Encryption – with robust forward as well as retroactive decryption.
https://specterops.io/blog/2026/03/04/offensive-dpapi-with-nemesis/
SynthAPT: Generate malware with AI
A capability that detection teams will want to ensure they have coverage for.
SynthAPT is a playbook-based adversary simulation framework for replicating complex attack paths. It is designed for validating advanced detections and AI-based investigation agents. The core idea is that malware behavior can be expressed in JSON and compiled into functional malware, enabling rapid development of realistic scenarios using LLMs.
…
The core implant is a shellcode payload driven by a playbook interpreter.
https://github.com/acedef/SynthAPT
Exploitation
What is being exploited..
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Google Threat Intelligence Group details of a capability they caught being used by a commercial company.
In February 2025, we captured parts of an iOS exploit chain used by a customer of a surveillance company. The exploits were integrated into a previously unseen JavaScript framework that used simple but unique JavaScript obfuscation techniques.
https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit
we also had Coruna: Inside the Nation-State-Grade iOS Exploit Kit We’ve Been Tracking
https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers
Building virtual iPhone using VPHONE600AP component of recently released PCC firmware
Hyungyu Seo walks through how to do the bring up..
It is only compatible with Apple Silicon Macs, and the devices/versions confirmed to work are as follows:
Apple M3, 16GB RAM, Sequoia 15.7.4
Apple M1 Pro, 32GB RAM, Tahoe 26.3
https://github.com/wh1te4ever/super-tart-vphone-writeup
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week, but keep an eye on the Awesome Annual Security Reports 2026 collection
SLIM: Structured Low-bandwidth Information Markup - “SLIM is a minimal, text-first authoring profile that improves resilience and usability in low-bandwidth or austere network conditions. It constrains fonts, styling, and client-side behaviors; discourages complex constructs; and prohibits tracking. This Unofficial Draft documents SLIM v1.0 requirements.”
Artificial intelligence
Fundamental
Applied non-cyber
Applied cyber specific
How to securely deploy agents that make sensitive decisions autonomously
A Decision-Theoretic Formalisation of Steganography With Applications to LLM Monitoring
Assessing Deanonymization Risks with Stylometry-Assisted LLM Agent
IETF - draft-klrc-aiagent-auth-00 - AI Agent Authentication and Authorization
Books
Nothing overly of note this week..
Events
[un]prompted 2026 - NotebookLM - an AI summary
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.





