- MetaInfostealer malware derived from RedLine; targeted in Operation Magnus 2024
- RedLineInfostealer malware variant used to steal credentials and access devices; widely distributed via affiliate network
ThreatNoir Morning Brief — March 26
Morning Review in IT Security — March 26, 2026
The cybersecurity landscape continues to evolve with significant developments spanning law enforcement actions, widespread vulnerability exploitation, and emerging malware threats. Today's review highlights critical incidents affecting e-commerce platforms, IoT infrastructure, and cryptocurrency users, underscoring the persistent challenges facing organizations across multiple sectors.
Alleged RedLine Infostealer Conspirator Extradited to US
An Armenian national accused of administering one of the world's most prevalent infostealing malware variants has been extradited to the United States to face prosecution. The defendant faces three counts related to his alleged role in operating and maintaining the RedLine infostealer, a sophisticated malware family that has compromised countless victims globally. This extradition represents a significant enforcement action in the ongoing international effort to dismantle major malware distribution networks.
Source: CyberScoop
PolyShell Attacks Target 56% of All Vulnerable Magento Stores
Active exploitation campaigns are leveraging the PolyShell vulnerability to compromise more than half of all vulnerable Magento Open Source and Adobe Commerce installations. Attackers are systematically targeting e-commerce platforms through this critical vulnerability, with some campaigns deploying WebRTC skimmers to capture sensitive transaction data. The widespread nature of these attacks demonstrates the urgent need for patch management and vulnerability remediation across the e-commerce sector.
Source: Bleeping Computer
Mirai Malware Evolves into Hundreds of Variants Driving Botnet Growth
The Mirai malware family continues to proliferate, spawning hundreds of variants including Aisuru, KimWolf, Satori, Tiny Mantis, Murdoc_Botnet, Lzrd, Resgod, JackSkid, and Mossad. These evolving variants are driving significant botnet growth and powering large-scale distributed denial-of-service attacks against vulnerable IoT devices worldwide. The continued mutation and deployment of Mirai-based threats underscore the persistent risk posed by unpatched Internet of Things infrastructure in both enterprise and consumer environments.
Source: Hackread
New Torg Grabber Infostealer Malware Targets 728 Crypto Wallets
A newly identified infostealer called Torg Grabber is actively stealing sensitive data from approximately 850 browser extensions, with over 728 of these targets being cryptocurrency wallet applications. The malware's focus on cryptocurrency assets represents a significant threat to digital asset holders, as successful infections can result in complete compromise of wallet credentials and private keys. Related threats including Underground and VoidStealer variants continue to expand the attack surface against crypto-dependent users.
Source: Bleeping Computer
Today's threat landscape reflects a multi-faceted attack environment where adversaries continue to exploit unpatched systems, develop new malware variants, and target high-value assets including cryptocurrency holdings and e-commerce platforms. Organizations must prioritize vulnerability management, maintain current security awareness training, and implement robust endpoint protection to defend against these evolving threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- WebRTC skimmerNovel payment card skimmer using DTLS-encrypted UDP via WebRTC to exfiltrate data and bypass CSP controls
- PolyShellCritical vulnerability in Magento 2 REST API enabling RCE and account takeover via polyglot file uploads
- AisuruMirai variant; part of Aisuru-KimWolf group responsible for 31.4 Tbps DDoS attacks
- Tiny MantisMirai-based botnet variant
- LzrdMirai-based botnet variant
- ResgodMirai-based botnet variant
- JackSkidBotnet network disrupted by US DOJ
- MossadBotnet network disrupted by US DOJ
- Murdoc_BotnetMirai-based botnet variant
- MiraiInfamous IoT botnet malware first identified in 2016, now 116+ variants
- SatoriMirai variant that infected 260,000+ routers via D-Link DSL-2750B vulnerability
- KimWolfMirai variant targeting Android systems, mobile phones, and Smart TVs; moved to I2P after infrastructure takedown
- Torg GrabberInfostealer targeting crypto wallets and browser extensions; 334 samples Dec 2025–Feb 2026
- VoidStealerRelated infostealer using similar master encryption key extraction methods
- UndergroundStandalone tool for extracting browser data via COM Elevation Service DLL injection