Weekly review

ThreatNoir Afternoon Brief — March 17

2026-03-17Afternoon2 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 17, 2026

The threat landscape continues to evolve across multiple vectors today, with nation-state actors leveraging social engineering tactics while consumer-facing companies grapple with data exposure incidents. These developments underscore the persistent challenges organizations face in securing both their infrastructure and customer information.

Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

North Korean threat actors attributed to the Konni hacking group have been observed conducting a sophisticated campaign that combines spear-phishing with legitimate application hijacking. Initial access was achieved through spear-phishing emails, which allowed attackers to compromise targets and gain access to the KakaoTalk desktop application. Once compromised, the attackers leveraged the messaging platform to distribute malicious payloads to specific contacts within victims' networks, effectively turning trusted communication channels into infection vectors.

The campaign demonstrates the group's continued focus on supply chain and social engineering attacks. The malware families identified in this activity include EndRAT, RemcosRAT, and RftRAT, with indicators of compromise suggesting command and control communications and persistence mechanisms typical of remote access trojans. South Korean threat intelligence firm Genians attributed this activity following analysis of the attack patterns and infrastructure. Source: The Hacker News

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears has inadvertently exposed customer conversations with its AI chatbot to public internet access, creating a significant privacy and security incident. The exposed interactions contain sensitive customer information including contact details and personal data that could be leveraged by threat actors to conduct targeted phishing attacks and commit fraud against affected individuals.

The incident highlights the security risks inherent in deploying AI-powered customer service systems without adequate access controls. Customer conversations conducted through chatbots often include information sufficient for social engineering attacks, making the exposure particularly concerning for fraud prevention. Source: Wired

These incidents reflect the dual challenge facing organizations today: defending against sophisticated nation-state threats while simultaneously maintaining secure configurations for consumer-facing digital services. Both stories underscore the importance of comprehensive security posture management across authentication, access controls, and data exposure prevention.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).