Weekly review

ThreatNoir Afternoon Brief — March 26

2026-03-26Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 26, 2026

The threat landscape continues to evolve across multiple attack vectors today, with state-sponsored actors maintaining persistent access to critical infrastructure while supply chain threats proliferate through compromised developer accounts. Meanwhile, law enforcement actions and the reuse of sophisticated exploit code underscore the ongoing sophistication of modern cyber operations.

Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure

State-sponsored threat actors have been discovered operating at the deepest levels of telecom backbone infrastructure, deploying kernel implants and passive backdoors designed to enable long-term, high-level espionage operations. The malware families involved in this campaign include BPFdoor, CrossC2, and TinyShell, which collectively provide attackers with persistent access and command-and-control capabilities. Source: Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure

The attack chain leverages exploitation techniques tracked under MITRE ATT&CK frameworks T1190 (Exploit Public-Facing Application), T1098 (Valid Accounts), and T1547.014 (Kernel Modules and Extensions). This discovery highlights the critical need for telecommunications providers to implement comprehensive security monitoring and patch management protocols across their infrastructure.

Suspected Hijacked Developer Accounts Spread npm Malware

Sonatype has uncovered a sophisticated malware campaign that exploits compromised npm developer accounts to distribute malicious packages capable of stealing API keys and passwords from development environments. The campaign leverages hijacked credentials to gain trust within the open-source ecosystem, allowing attackers to distribute packages containing the sbx-mask and touch-adv malware families. Source: Suspected Hijacked Developer Accounts Spread npm Malware

This supply chain attack demonstrates the vulnerability of development environments when authentication controls are insufficient. Organizations relying on npm packages must implement strict dependency verification processes and monitor for suspicious package updates from previously trusted sources.

Suspected RedLine Infostealer Malware Admin Extradited to US

An Armenian national has been extradited to the United States to face criminal charges for allegedly serving as an administrator of RedLine, one of the most prolific infostealer malware operations in recent years. RedLine operates as a malware-as-a-service platform alongside related threats including Torg Grabber and Arkanix Stealer, which have collectively compromised hundreds of thousands of user credentials. Source: Suspected RedLine infostealer malware admin extradited to US

The extradition represents a significant enforcement action against organized cybercrime infrastructure and demonstrates international cooperation in combating malware-as-a-service operations that pose substantial risks to enterprise security.

Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks

Kaspersky researchers have identified that the Coruna iOS exploit kit, recently discovered in mass attack campaigns, contains kernel exploit code that is derived from the Operation Triangulation campaign conducted in 2023. The Coruna kit incorporates updated versions of exploits targeting CVE-2023-32434 and CVE-2023-38606, alongside the PlasmaLoader (PLASMAGRID) and DarkSword components. Source: Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks

The reuse of previously developed exploit code across campaigns demonstrates how sophisticated threat actors maintain and evolve their toolkits over extended periods. The exploitation techniques tracked under MITRE ATT&CK T1190 and T1203 continue to pose significant risks to iOS users, particularly those operating unpatched devices.

Today's threat landscape reflects the persistent sophistication of state-sponsored actors, the vulnerability of supply chain ecosystems, and the ongoing evolution of exploit techniques across multiple platforms. Organizations must prioritize patch management, credential security, and supply chain visibility to mitigate these converging threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure
MITRE ATT&CK3
  • Kernel Modules and Extensions - BPFdoor deployed in Linux kernel
  • Valid Accounts - abused for initial access during intrusions
  • Exploit Public-Facing Application - targeting Ivanti, Cisco, Fortinet, VMware, Palo Alto Networks
Malware3
  • BPFdoor
    Stealthy Linux kernel-level backdoor using Berkeley Packet Filter for packet inspection and remote shell spawning
  • TinyShell
    Open source passive backdoor framework deployed for persistence in telecom infrastructure
  • CrossC2
    Cobalt Strike-derived beacon framework used by Chinese APTs for staging, command execution, and lateral movement
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks
CVE2
  • Zero-day vulnerability exploited in Operation Triangulation and reused in Coruna kernel exploit
  • Zero-day vulnerability exploited in Operation Triangulation and reused in Coruna kernel exploit
MITRE ATT&CK2
  • Exploitation for Client Execution; kernel exploit delivery via Safari
  • Exploit Public-Facing Application; watering hole attacks via compromised websites
Malware3
  • Coruna
    iOS exploit kit targeting Apple iPhones; contains 5 full exploit chains and 23 total exploits
  • PlasmaLoader (PLASMAGRID)
    Data-stealing malware delivered via Coruna in mass exploitation campaigns using fake Chinese gambling/cryptocurrency websites
  • DarkSword
    New version of iPhone exploit kit leaked on GitHub; raises concern of wider threat actor adoption