- Ledger Windows Desktop SnifferWallet credential-stealing malware sold by threat actor; kills Ledger process and launches fake app
- Windows desktop wallet snifferGeneric malware family targeting hardware wallet users (Trezor and Ledger)
ThreatNoir Morning Brief — March 23
Morning Review in IT Security — March 23, 2026
The threat landscape continues to intensify as March progresses, with major entertainment platforms falling victim to insider threats, cryptocurrency users facing sophisticated wallet-targeting malware, and critical infrastructure organizations receiving extortion demands. Additionally, the underground economy shows no signs of slowing, with new bulletproof hosting services and malware setup operations actively recruiting customers.
CrunchyRoll Suffers Major Data Breach Through Compromised Helpdesk Contractor
CrunchyRoll has been compromised in a significant supply-chain attack orchestrated through a bribed third-party helpdesk contractor. The unknown threat actor successfully bribed the contractor, who then intentionally deployed malware throughout CrunchyRoll's computer network. Over 100 gigabytes of customer data was stolen in the incident, exposing sensitive information belonging to the streaming platform's user base. Source: vxunderground
Threat Actor Markets Windows Wallet Sniffers Targeting Hardware Wallet Users
A threat actor is actively selling Windows desktop wallet sniffers specifically designed to target users of Trezor and Ledger hardware wallets. The malware, dubbed the "Ledger Windows Desktop Sniffer," operates by terminating the legitimate Ledger process and launching a counterfeit application in its place. The sniffer includes Telegram notification capabilities and is compatible with Windows 10 and Windows 11 systems, presenting a serious risk to cryptocurrency users who believe they are using authentic hardware wallet software. Source: DarkWebInformer
ShinyHunters Threatens Educational and Financial Institutions
ShinyHunters has issued ransom demands against both Infinite Campus, Inc. and Ameriprise Financial, Inc., threatening to release stolen data unless payment is made. These threats represent a significant escalation targeting critical sectors including education and financial services. Source: DarkWebInformer
RawHost Bulletproof VPS Service Ignores DMCA Takedown Requests
A threat actor is advertising RawHost, a bulletproof VPS hosting service that explicitly disregards DMCA takedown requests. The service offers tiered pricing with Basic plans ranging from 1 vCPU and 2GB RAM at $6.91 per month up to 6 vCPU and 12GB RAM at $36.52 per month, alongside Elite plans beginning at 8 vCPU and 16GB RAM. The service's willingness to ignore legal takedown notices makes it an attractive infrastructure option for cybercriminals. Source: DarkWebInformer
Professional Malware Setup Service Targets Newcomers to Cybercrime
A threat actor is advertising a "Professional Malware Setup Service" designed to onboard newcomers to blackhat hacking operations. The service provides comprehensive end-to-end malware infrastructure setup and technical assistance, including consultation, remote access trojan (RAT) configuration, stealer and loader deployment, botnet establishment, and Android RAT setup. This service lowers the technical barrier for aspiring cybercriminals seeking to launch malware campaigns. Source: DarkWebInformer
Aigner Immobilien Breached via Unpatched Vulnerability
A threat actor claims to have successfully breached Aigner Immobilien, a prominent Munich-based real estate brokerage with over three decades of operational history. The attacker details the intrusion methodology as initial access through CVE-2024-7399 into a Windows 11 environment, followed by lateral movement and data exfiltration. The exploitation of this known vulnerability highlights the critical importance of timely patching in preventing unauthorized access. Source: DarkWebInformer
Brazilian Municipal Government Data Offered for Sale
Spirigatito is allegedly selling data stolen from the Prefeitura Municipal de Caieiras, the local government authority of Caieiras municipality in São Paulo state, Brazil. The compromised dataset contains 363,519 records along with 90 additional files, reportedly including full names, social names, and information about family members. This breach exposes the personal information of a significant portion of the municipality's population. Source: DarkWebInformer
Today's threat intelligence demonstrates the persistent vulnerability of organizations across sectors, from entertainment and finance to government and real estate, while simultaneously revealing an increasingly professionalized underground economy designed to support criminal operations at every technical level.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- ShinyHuntersRansomware/extortion threat actor conducting active extortion campaign
- Vulnerability used for initial access to Windows 11 environment in Aigner Immobilien breach
- SpirigatitoThreat actor selling stolen municipal government data