- infostealer malware (unspecified family)Credentials for Stryker administrator accounts harvested via infostealer logs; months to years old
ThreatNoir Afternoon Brief — March 18
Afternoon Review in IT Security — March 18, 2026
The threat landscape continues to evolve across multiple fronts today, with nation-state actors intensifying campaigns against critical infrastructure and healthcare systems, while new vulnerabilities and malware variants demand immediate attention from security teams worldwide.
Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach
Medtech giant Stryker has been working to restore systems following a cyberattack attributed to the Handala group, a threat actor with Iranian connections. The attackers appear to have leveraged infostealer malware to obtain legitimate credentials before conducting their breach, allowing them to move laterally through the company's infrastructure with valid authentication. Source: Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach
The SOC Files: Time to "Sapecar". Unpacking a new Horabot campaign in Mexico
Kaspersky's Security Operations Center has uncovered a sophisticated Horabot campaign targeting Mexico with complex attack chains designed to evade detection and establish persistence. The campaign utilizes multiple infrastructure components including domains such as evs.grupotuis.buzz and pdj.gruposhac.lat, along with malicious HTA files and command-and-control endpoints to deliver the Horabot malware payload. Security teams can leverage the detailed analysis and hunting techniques provided to identify and respond to this emerging threat. Source: The SOC Files: Time to "Sapecar". Unpacking a new Horabot campaign in Mexico
Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit
A high-severity vulnerability tracked as CVE-2026-3888 with a CVSS score of 7.8 affects Ubuntu Desktop versions 24.04 and later on default installations. The flaw exploits a timing issue in systemd cleanup processes, allowing unprivileged local attackers to escalate privileges to full root access and seize complete control of vulnerable systems. This vulnerability poses significant risk to Ubuntu users and requires immediate patching. Source: Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit
SideWinder Espionage Campaign Expands Across Southeast Asia
The suspected India-linked threat group SideWinder continues to expand its espionage operations across Southeast Asia, targeting government agencies, telecommunications companies, and critical infrastructure sectors. The group employs spear-phishing tactics, exploits known vulnerabilities, and maintains rapidly rotating infrastructure to sustain persistent access to compromised networks while evading attribution and detection. Source: SideWinder Espionage Campaign Expands Across Southeast Asia
Organizations across healthcare, government, and critical infrastructure sectors face mounting pressure to strengthen their defensive postures as nation-state actors and sophisticated threat groups demonstrate increased operational tempo and technical sophistication in their campaigns.
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
Source: The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
Kaspersky SOC uncovered and analyzed a complex Horabot campaign in Mexico. In this article we share insights into how it is unleashed and how to hunt for this threat.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- HorabotBanking trojan bundle with email spreader and complex attack chain
evs.grupotuis.buzzMalicious domain hosting fake CAPTCHA page and HTA stagerpdj.gruposhac.latC2 domain hosting polymorphic VBScript payloads
hxxps://pdj[.]gruposhac[.]lat/g1/ld1/VBScript payload delivery with server-side polymorphismhxxps://pdj[.]gruposhac[.]lat/g1/Secondary polymorphic VBScript loader stagehxxps://evs[.]grupotuis[.]buzz/0capcha17/Fake CAPTCHA page used for initial social engineering lurehxxps://evs[.]grupotuis[.]buzz/0capcha17/DMEENLIGGB[.]htaMalicious HTA file loader retrieved via mshta command
- High-severity privilege escalation in Ubuntu Desktop via snap-confine and systemd-tmpfiles timing race condition