Weekly review

ThreatNoir Afternoon Brief — March 20

2026-03-20Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 20, 2026

The cybersecurity landscape continues to face significant threats as law enforcement takes action against major botnet operations while new malware campaigns and zero-day exploits emerge across multiple sectors. Today's briefing covers critical disruptions, supply-chain attacks, and active exploitation campaigns affecting organizations worldwide.

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

The U.S. Department of Justice announced a major law enforcement operation targeting command-and-control infrastructure used by several Internet of Things botnets including AISURU, Kimwolf, JackSkid, and Mossad. The coordinated effort involved authorities from Canada and Germany working alongside private sector partners to dismantle the networks responsible for record-breaking distributed denial-of-service attacks. The operation represents a significant blow to threat actors operating large-scale botnet infrastructure that has been leveraged for some of the most devastating DDoS campaigns on record.

Source: DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

New Stealit Campaign Abuses Node.js Single Executable Application

FortiGuard Labs has identified a new Stealit campaign that exploits Node.js Single Executable Application technology to deliver obfuscated malware payloads. The campaign demonstrates attackers' continued evolution in leveraging legitimate development frameworks to evade detection and distribute the Stealit RAT across target systems. The threat actors have registered domains including iloveanimals.shop and stealituptaded.lol to facilitate command and control operations, with communications originating from accounts associated with @deceptacle.

Source: New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs

Critical Langflow Vulnerability Exploited Hours After Public Disclosure

A critical vulnerability in Langflow has been actively exploited in the wild within hours of its public disclosure, enabling unauthenticated remote code execution through attacker-supplied flow data in public flows. Tracked as CVE-2026-33017, the vulnerability poses an immediate threat to organizations running vulnerable instances of the open-source platform. Threat actors have already developed and deployed exploit toolkits targeting the flaw, demonstrating the rapid weaponization of publicly disclosed vulnerabilities.

Source: Critical Langflow Vulnerability Exploited Hours After Public Disclosure

Thousands of Magento Sites Hit in Ongoing Defacement Campaign

An ongoing defacement campaign targeting Magento e-commerce platforms has impacted thousands of sites globally, affecting e-commerce platforms, multinational brands, and government services since February 27. The attacks leverage multiple vulnerabilities including PolyShell and SessionReaper to compromise and deface affected websites. The campaign continues to expand, underscoring the persistent threat to organizations running vulnerable versions of popular e-commerce software.

Source: Thousands of Magento Sites Hit in Ongoing Defacement Campaign

Today's threat landscape reflects both the effectiveness of coordinated law enforcement action against established botnet infrastructure and the persistent challenge of rapidly weaponized vulnerabilities and supply-chain attacks. Organizations should prioritize immediate patching of known vulnerabilities, enhanced monitoring of Node.js deployments, and review of Magento security postures to mitigate current threats.

New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs

Source: New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs

A new Stealit campaign uses Node.js Single Executable Application (SEA) to deliver obfuscated malware. FortiGuard Labs details tactics and defenses. Learn more.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
MITRE ATT&CK2
Malware4
  • Kimwolf
    IoT botnet variant; issued >25,000 DDoS attack commands; responsible for 31.4 Tbps attack in November 2025; exploited residential proxy networks
  • Mossad
    IoT botnet variant; issued >1,000 DDoS attack commands; Mirai variant
  • AISURU
    IoT botnet variant; issued >200,000 DDoS attack commands; part of disrupted C2 infrastructure
  • JackSkid
    IoT botnet variant; issued >90,000 DDoS attack commands; targeted firewalled devices including DVRs and cameras
New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs
Malware1
  • Stealit RAT
    Remote Access Trojan sold as commercial service; targets Windows and Android with file extraction, webcam control, screen monitoring, and ransomware capabilities
Domain2
  • iloveanimals.shop
    Current Stealit C2 server and malware panel hosting commercial website
  • stealituptaded.lol
    Original Stealit C2 panel and command-and-control server (now inaccessible)
Email1
  • [@]deceptacle
    Telegram handle of main contact person for Stealit service
Thousands of Magento Sites Hit in Ongoing Defacement Campaign
CVE2
  • October 2025 Magento vulnerability; similarities noted with current defacement campaign exploitation techniques
  • Unauthenticated file upload vulnerability in Magento/Adobe Commerce REST API affecting versions up to 2.4.9-alpha2; allows executable uploads without authentication
Malware1
  • Typical Idiot Security
    Threat actor handle used in defacement campaign; account used on Zone-H to report incidents