Weekly review

ThreatNoir Morning Brief — March 23

2026-03-23Morning7 articles
Audio
Listen to the episode

Morning Review in IT Security — March 23, 2026

The threat landscape continues to intensify as March progresses, with major entertainment platforms falling victim to insider threats, cryptocurrency users facing sophisticated wallet-targeting malware, and critical infrastructure organizations receiving extortion demands. Additionally, the underground economy shows no signs of slowing, with new bulletproof hosting services and malware setup operations actively recruiting customers.

CrunchyRoll Suffers Major Data Breach Through Compromised Helpdesk Contractor

CrunchyRoll has been compromised in a significant supply-chain attack orchestrated through a bribed third-party helpdesk contractor. The unknown threat actor successfully bribed the contractor, who then intentionally deployed malware throughout CrunchyRoll's computer network. Over 100 gigabytes of customer data was stolen in the incident, exposing sensitive information belonging to the streaming platform's user base. Source: vxunderground

Threat Actor Markets Windows Wallet Sniffers Targeting Hardware Wallet Users

A threat actor is actively selling Windows desktop wallet sniffers specifically designed to target users of Trezor and Ledger hardware wallets. The malware, dubbed the "Ledger Windows Desktop Sniffer," operates by terminating the legitimate Ledger process and launching a counterfeit application in its place. The sniffer includes Telegram notification capabilities and is compatible with Windows 10 and Windows 11 systems, presenting a serious risk to cryptocurrency users who believe they are using authentic hardware wallet software. Source: DarkWebInformer

ShinyHunters Threatens Educational and Financial Institutions

ShinyHunters has issued ransom demands against both Infinite Campus, Inc. and Ameriprise Financial, Inc., threatening to release stolen data unless payment is made. These threats represent a significant escalation targeting critical sectors including education and financial services. Source: DarkWebInformer

RawHost Bulletproof VPS Service Ignores DMCA Takedown Requests

A threat actor is advertising RawHost, a bulletproof VPS hosting service that explicitly disregards DMCA takedown requests. The service offers tiered pricing with Basic plans ranging from 1 vCPU and 2GB RAM at $6.91 per month up to 6 vCPU and 12GB RAM at $36.52 per month, alongside Elite plans beginning at 8 vCPU and 16GB RAM. The service's willingness to ignore legal takedown notices makes it an attractive infrastructure option for cybercriminals. Source: DarkWebInformer

Professional Malware Setup Service Targets Newcomers to Cybercrime

A threat actor is advertising a "Professional Malware Setup Service" designed to onboard newcomers to blackhat hacking operations. The service provides comprehensive end-to-end malware infrastructure setup and technical assistance, including consultation, remote access trojan (RAT) configuration, stealer and loader deployment, botnet establishment, and Android RAT setup. This service lowers the technical barrier for aspiring cybercriminals seeking to launch malware campaigns. Source: DarkWebInformer

Aigner Immobilien Breached via Unpatched Vulnerability

A threat actor claims to have successfully breached Aigner Immobilien, a prominent Munich-based real estate brokerage with over three decades of operational history. The attacker details the intrusion methodology as initial access through CVE-2024-7399 into a Windows 11 environment, followed by lateral movement and data exfiltration. The exploitation of this known vulnerability highlights the critical importance of timely patching in preventing unauthorized access. Source: DarkWebInformer

Brazilian Municipal Government Data Offered for Sale

Spirigatito is allegedly selling data stolen from the Prefeitura Municipal de Caieiras, the local government authority of Caieiras municipality in São Paulo state, Brazil. The compromised dataset contains 363,519 records along with 90 additional files, reportedly including full names, social names, and information about family members. This breach exposes the personal information of a significant portion of the municipality's population. Source: DarkWebInformer

Today's threat intelligence demonstrates the persistent vulnerability of organizations across sectors, from entertainment and finance to government and real estate, while simultaneously revealing an increasingly professionalized underground economy designed to support criminal operations at every technical level.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).