Weekly review

ThreatNoir Afternoon Brief — March 23

2026-03-23Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 23, 2026

The cybersecurity landscape continues to face significant threats as critical vulnerabilities are actively exploited, supply chain attacks expand their reach, and law enforcement agencies work to dismantle major botnet infrastructure. Today's review covers incidents spanning from enterprise systems management to container environments and state-sponsored threat actors.

Hackers Exploit CVE-2025-32975 to Hijack Unpatched Quest KACE SMA Systems

Arctic Wolf has detected active exploitation of CVE-2025-32975, a maximum-severity vulnerability with a CVSS score of 10.0 affecting Quest KACE Systems Management Appliance (SMA). The cybersecurity firm observed malicious activity beginning the week of March 9, 2026, targeting unpatched SMA systems that are exposed to the internet. Source: Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

The exploitation activity is consistent with threat actors leveraging this critical flaw in customer environments. The indicators of compromise associated with this campaign include the IP address 216.126.225.156 and the use of known attack tools including Mimikatz and runkbot.exe. Organizations running Quest KACE SMA systems should prioritize patching efforts immediately to prevent unauthorized access and lateral movement within their infrastructure.

Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper

The Trivy supply chain attack has revealed a broader compromise affecting developer environments through malicious artifacts distributed via Docker Hub. The last confirmed clean release of Trivy available on Docker Hub is version 0.69.3, while the compromised versions 0.69.4, 0.69.5, and 0.69.6 have been removed from the container image library. Source: Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper

The malicious versions distributed through this supply chain compromise included multiple threats targeting containerized environments. The TeamPCP infostealer was deployed to exfiltrate sensitive information from developer systems, while CanisterWorm propagated as a worm mechanism. Additionally, a Kubernetes wiper tool was included in the payload, capable of destroying workloads and data within Kubernetes clusters. This incident demonstrates the critical importance of verifying container image integrity and monitoring for unauthorized modifications to widely-used development tools.

Global Crackdown Dismantles Four Botnets Behind Major DDoS Attacks

International law enforcement coordinated efforts to dismantle four major botnets responsible for large-scale distributed denial-of-service attack campaigns. The operation successfully targeted the Aisuru, KimWolf, JackSkid, and Mossad botnets, which had been compromising millions of devices worldwide. Source: Global Crackdown Dismantles 4 Botnets Behind Major DDoS Attacks

The takedown of these botnet infrastructures represents a significant disruption to organized cybercriminal operations that have conducted sustained DDoS attack campaigns against critical targets globally. The successful dismantling of these four separate botnets demonstrates the effectiveness of coordinated international law enforcement efforts in combating large-scale infrastructure threats.

FBI Warns of Handala Hackers Using Telegram in Malware Attacks

The Federal Bureau of Investigation has issued a warning regarding Iranian state-sponsored threat actors linked to the country's Ministry of Intelligence and Security (MOIS) who are leveraging Telegram as a distribution channel for malware attacks. Source: FBI warns of Handala hackers using Telegram in malware attacks

The Handala threat group has been observed using multiple domains including handala-redwanted.to, handala-hack.to, justicehomeland.org, and karmabelow80.org to facilitate their malware operations. The group distributes Handala Windows malware through Telegram channels, utilizing the platform's accessibility and encryption features to evade detection. Network defenders should monitor for communications involving these identified domains and be alert to suspicious activity originating from Telegram-based distribution channels.

Closing Perspective

Today's threat landscape reflects a diverse range of attack vectors from critical infrastructure exploitation to sophisticated supply chain compromises and state-sponsored operations. Organizations must maintain vigilant patch management practices, implement robust container security measures, and monitor for emerging threats from both criminal and state-sponsored actors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE1
  • Critical authentication bypass vulnerability (CVSS 10.0) in Quest KACE SMA, actively exploited March 2026
Malware2
  • runkbot.exe
    SMA Agent background process abused to create additional administrative accounts for persistence
  • Mimikatz
    Credential harvesting tool deployed by threat actors post-exploitation
IP Address1
  • 216.126.225.156
    Malicious server used to deliver Base64-encoded payloads via curl command during exploitation
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper
MITRE ATT&CK2
  • Credentials from web browsers and cloud services harvested by infostealer.
  • Trusted relationship exploitation via Trivy supply chain compromise.
Malware4
  • TeamPCP
    Threat actor conducting supply chain attack on Trivy and Aqua Security.
  • CanisterWorm
    Self-propagating worm deployed via compromised npm packages post-Trivy attack.
  • TeamPCP infostealer
    Credential stealer embedded in Trivy malicious Docker images 0.69.4, 0.69.5, 0.69.6.
  • Kubernetes wiper (kamikaze)
    Payload targeting K8s clusters in Iran; wipes non-Iranian nodes with CanisterWorm, Iranian nodes with rm -rf.
Global Crackdown Dismantles 4 Botnets Behind Major DDoS Attacks
Malware4
  • Aisuru
    Botnet dismantled; issued 200,000+ attack commands
  • KimWolf
    Botnet dismantled; issued 25,000+ DDoS commands; targeted firewalled devices
  • JackSkid
    Botnet dismantled; launched 90,000 DDoS attacks; targeted firewalled devices
  • Mossad
    Botnet dismantled; sent 1,000 DDoS attack commands
FBI warns of Handala hackers using Telegram in malware attacks
Malware1
  • Handala Windows malware
    Malware distributed via social engineering; enables screenshot/file exfiltration
Domain4
  • handala-hack.to
    Handala hacktivist group C2 and data leak domain, seized by FBI
  • handala-redwanted.to
    Handala hacktivist group C2 and data leak domain, seized by FBI
  • justicehomeland.org
    Homeland Justice (IRGC-linked) C2 and data leak domain, seized by FBI
  • karmabelow80.org
    Karma Below threat actor C2 and data leak domain, seized by FBI