- Telegram-based malware (Iranian MOIS)Malware distributed via Telegram masquerading as Pictory, KeePass, and Telegram apps; controlled via Telegram bots
ThreatNoir Morning Brief — March 24
Morning Review in IT Security — March 24, 2026
The cybersecurity landscape continues to shift as state-sponsored actors refine their tactics and infrastructure vulnerabilities emerge across critical platforms. Today's threat landscape reflects both persistent nation-state campaigns and evolving attack methodologies that bypass traditional defenses.
FBI: Iranian Hackers Targeting Opponents with Telegram Malware
The Federal Bureau of Investigation has issued an alert regarding a sustained campaign by Iranian threat actors leveraging Telegram-based malware to target opponents. While the campaign traces back to 2023, the alert comes amid heightened tensions in the Middle East region. The malware, attributed to Iranian Ministry of Intelligence and Security (MOIS) operations, continues to pose a significant threat to dissidents and political opposition figures. Source: FBI: Iranian hackers targeting opponents with Telegram malware
North Korean Hacker Lands Remote IT Job, Caught After VPN Slip
Researchers at LevelBlue have uncovered evidence of a suspected North Korean operative who successfully obtained a remote information technology position, apparently to generate funding for national weapons programs. The individual, attributed to the Lazarus Group, was identified through operational security failures involving VPN usage while conducting interviews under the false identity "Contagious Interview." The investigation revealed the operative was utilizing infrastructure including Astrill VPN and fraudulent entities such as Willow Tree Economic Technology Exchange Centre, RB Site, and NetkeyRegister. Source: North Korean Hacker Lands Remote IT Job, Caught After VPN Slip
NetScaler ADC and NetScaler Gateway Security Vulnerabilities
Citrix has released a security bulletin addressing two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway platforms. CVE-2026-3055 involves insufficient input validation leading to memory overread with a CVSS score of 9.3, representing a severe threat to affected deployments. CVE-2026-4368 describes a race condition vulnerability that could result in user session mixup, rated at 7.7 CVSS. Organizations operating these appliances should prioritize assessment and patching of these vulnerabilities. Source: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368
The Phone Call is the New Phishing Email
Voice-based phishing has emerged as a primary attack vector in multiple intrusion campaigns that Mandiant responded to throughout the previous year. This shift in social engineering tactics represents a concerning evolution in how threat actors attempt to compromise target organizations. Campaigns attributed to groups including UNC6040 and UNC6240, as well as the Scattered Spider threat actor, have leveraged voice-based attacks in conjunction with exploitation of vulnerabilities including CVE-2025-31324, CVE-2025-61882, and CVE-2025-53770. Source: The phone call is the new phishing email
As threat actors continue to diversify their attack methodologies and exploit both human and technical vulnerabilities, security teams must remain vigilant across multiple attack surfaces. The combination of state-sponsored persistence, evolving social engineering tactics, and unpatched infrastructure vulnerabilities underscores the need for comprehensive defense strategies.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Lazarus GroupNorth Korean state-sponsored APT known to use Astrill VPN for command-and-control and exfiltration
- Contagious InterviewSubgroup of Lazarus Group; uses Astrill VPN to bypass Great Firewall and evade detection
- Insufficient input validation leading to memory overread in NetScaler ADC/Gateway (CVSS 9.3)
- Race condition causing user session mixup in NetScaler ADC/Gateway (CVSS 7.7)
- Microsoft SharePoint vulnerability exploited as initial access vector in 2025
- SAP NetWeaver vulnerability exploited as initial access vector in 2025
- Oracle E-Business Suite vulnerability exploited as initial access vector in 2025
- Threat group conducting voice-based phishing against Salesforce customers
- Threat group conducting voice-based phishing against Salesforce customers
- Scattered SpiderCybercrime collective member conducting voice-based phishing campaigns
- The ComCybercrime collective conducting voice-based phishing and social engineering attacks