Weekly review

ThreatNoir Morning Brief — March 26

2026-03-26Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — March 26, 2026

The cybersecurity landscape continues to evolve with significant developments spanning law enforcement actions, widespread vulnerability exploitation, and emerging malware threats. Today's review highlights critical incidents affecting e-commerce platforms, IoT infrastructure, and cryptocurrency users, underscoring the persistent challenges facing organizations across multiple sectors.

Alleged RedLine Infostealer Conspirator Extradited to US

An Armenian national accused of administering one of the world's most prevalent infostealing malware variants has been extradited to the United States to face prosecution. The defendant faces three counts related to his alleged role in operating and maintaining the RedLine infostealer, a sophisticated malware family that has compromised countless victims globally. This extradition represents a significant enforcement action in the ongoing international effort to dismantle major malware distribution networks.

Source: CyberScoop

PolyShell Attacks Target 56% of All Vulnerable Magento Stores

Active exploitation campaigns are leveraging the PolyShell vulnerability to compromise more than half of all vulnerable Magento Open Source and Adobe Commerce installations. Attackers are systematically targeting e-commerce platforms through this critical vulnerability, with some campaigns deploying WebRTC skimmers to capture sensitive transaction data. The widespread nature of these attacks demonstrates the urgent need for patch management and vulnerability remediation across the e-commerce sector.

Source: Bleeping Computer

Mirai Malware Evolves into Hundreds of Variants Driving Botnet Growth

The Mirai malware family continues to proliferate, spawning hundreds of variants including Aisuru, KimWolf, Satori, Tiny Mantis, Murdoc_Botnet, Lzrd, Resgod, JackSkid, and Mossad. These evolving variants are driving significant botnet growth and powering large-scale distributed denial-of-service attacks against vulnerable IoT devices worldwide. The continued mutation and deployment of Mirai-based threats underscore the persistent risk posed by unpatched Internet of Things infrastructure in both enterprise and consumer environments.

Source: Hackread

New Torg Grabber Infostealer Malware Targets 728 Crypto Wallets

A newly identified infostealer called Torg Grabber is actively stealing sensitive data from approximately 850 browser extensions, with over 728 of these targets being cryptocurrency wallet applications. The malware's focus on cryptocurrency assets represents a significant threat to digital asset holders, as successful infections can result in complete compromise of wallet credentials and private keys. Related threats including Underground and VoidStealer variants continue to expand the attack surface against crypto-dependent users.

Source: Bleeping Computer


Today's threat landscape reflects a multi-faceted attack environment where adversaries continue to exploit unpatched systems, develop new malware variants, and target high-value assets including cryptocurrency holdings and e-commerce platforms. Organizations must prioritize vulnerability management, maintain current security awareness training, and implement robust endpoint protection to defend against these evolving threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Mirai Malware Evolves into Hundreds of Variants Driving Botnet Growth
Malware10
  • Aisuru
    Mirai variant; part of Aisuru-KimWolf group responsible for 31.4 Tbps DDoS attacks
  • Tiny Mantis
    Mirai-based botnet variant
  • Lzrd
    Mirai-based botnet variant
  • Resgod
    Mirai-based botnet variant
  • JackSkid
    Botnet network disrupted by US DOJ
  • Mossad
    Botnet network disrupted by US DOJ
  • Murdoc_Botnet
    Mirai-based botnet variant
  • Mirai
    Infamous IoT botnet malware first identified in 2016, now 116+ variants
  • Satori
    Mirai variant that infected 260,000+ routers via D-Link DSL-2750B vulnerability
  • KimWolf
    Mirai variant targeting Android systems, mobile phones, and Smart TVs; moved to I2P after infrastructure takedown
New Torg Grabber infostealer malware targets 728 crypto wallets
Malware3
  • Torg Grabber
    Infostealer targeting crypto wallets and browser extensions; 334 samples Dec 2025–Feb 2026
  • VoidStealer
    Related infostealer using similar master encryption key extraction methods
  • Underground
    Standalone tool for extracting browser data via COM Elevation Service DLL injection