Weekly review

ThreatNoir Weekend Brief — March 28

2026-03-28Afternoon5 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 28, 2026

The cybersecurity landscape on March 28, 2026 continues to reflect heightened threat activity across multiple fronts, from critical infrastructure vulnerabilities under active exploitation to nation-state campaigns targeting high-value individuals. Today's review covers reconnaissance efforts against Citrix systems, active exploitation of F5 infrastructure, state-sponsored iOS targeting, and emerging Mac-focused malware campaigns.

Citrix NetScaler Under Active Reconnaissance for CVE-2026-3055

A critical memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway is currently experiencing active reconnaissance attempts in the wild. The flaw, identified as CVE-2026-3055 with a CVSS score of 9.3, stems from insufficient input validation that could allow attackers to leak sensitive information from affected systems. Security researchers at Defused Cyber and watchTowr have documented this reconnaissance activity, indicating that threat actors are actively probing for vulnerable instances. Source: Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog following confirmed evidence of active exploitation in the field. The vulnerability affects F5 BIG-IP Access Policy Manager and carries a CVSS v4 score of 9.3, enabling remote code execution when successfully exploited. Despite patches being available, threat actors continue to actively target F5 BIG-IP systems, prompting CISA's inclusion on the KEV list to raise awareness among critical infrastructure operators. Source: CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Russian state-sponsored threat group TA446, also tracked under the designations Callisto and other monikers, has been observed deploying the DarkSword iOS exploit kit in highly targeted spear-phishing campaigns. Proofpoint researchers disclosed that the threat actors are leveraging the recently disclosed exploit kit to compromise iOS devices belonging to high-value targets. The campaign demonstrates the continued focus by nation-state actors on targeting individuals through sophisticated social engineering and exploit delivery mechanisms. Source: TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

A new variant of the ClickFix attack leverages Cloudflare branding to deceive macOS users into executing malicious commands. The infection chain begins with a fake CAPTCHA page that directs victims to execute a Bash script, which in turn deploys a Nuitka loader and the Python-based Infiniti Stealer infostealer. This attack demonstrates the continued targeting of macOS systems through social engineering tactics that exploit user trust in legitimate service providers. Source: Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

High-Profile Account Compromise Linked to Password Reuse and Missing Two-Factor Authentication

Security researchers have reconstructed how the Handala malware was used to compromise a high-profile personal Gmail account, revealing that the victim's credentials were exposed in a previous database dump and reused across multiple platforms. The compromise was further facilitated by the absence of two-factor authentication on the legacy email account. This incident underscores the persistent security risks posed by password reuse practices and the critical importance of enabling multi-factor authentication across all accounts. Source: I believe Mr. Moyal has successfully reconstructed how Handala compromised Kash Patel's personal...

As threat actors continue to exploit both infrastructure vulnerabilities and human factors, organizations and individuals must prioritize patch management, implement robust authentication mechanisms, and maintain vigilance against sophisticated social engineering campaigns targeting their users and systems.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
MITRE ATT&CK1
  • Spear-phishing with spoofed Atlantic Council emails for credential harvesting
Malware3
  • MAYBEROBOT
    Backdoor deployed by TA446 via password-protected ZIP files
  • GHOSTBLADE
    Dataminer malware deployed via DarkSword in phishing emails
  • DarkSword
    iOS exploit kit leveraged by TA446 for credential harvesting and remote code execution
Domain1
  • escofiringbijou.com
    TA446-controlled second-stage domain serving DarkSword exploit kit components
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Malware2
  • Infiniti Stealer
    Python-based infostealer targeting macOS, deployed via ClickFix campaign. Steals browser credentials, Keychain data, cryptocurrency wallets, and developer secrets.
  • ClickFix
    Social engineering technique using fake CAPTCHA pages to trick users into executing malicious commands. Originally used against Windows, now adapted for macOS.