- DarkSwordiOS exploit kit adopted by Star Blizzard for credential harvesting and RCE
- GhostBladeDarkSword-linked malware delivered in Star Blizzard email campaign
ThreatNoir Afternoon Brief — March 30
Afternoon Review in IT Security — March 30, 2026
The threat landscape continues to evolve with state-sponsored actors refining their tactics, critical infrastructure vulnerabilities entering active exploitation, and supply chain threats targeting widely-used development tools. Today's review covers significant developments affecting government, financial, and technology sectors worldwide.
Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
The state-sponsored Russian APT group Star Blizzard has integrated the DarkSword iOS exploit kit into its operational arsenal, expanding its capability to target mobile platforms. The campaign has focused on government, higher education, financial, and legal entities, as well as think tanks across multiple sectors. This development represents an escalation in the group's sophistication, combining traditional targeting methodologies with advanced mobile exploitation techniques.
Source: Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
Critical F5 BIG-IP APM Vulnerability Under Active Exploitation
A critical unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager has transitioned from theoretical risk to active exploitation in the wild. The vulnerability, tracked as CVE-2025-53521, has been reclassified from denial-of-service severity to critical remote code execution status as attackers deploy webshells on unpatched devices. The UK National Cyber Security Centre is urging organizations to immediately mitigate this flaw, which allows attackers to gain complete control of affected systems without requiring authentication credentials.
Source: Vulnerability affecting F5 BIG-IP APM
Source: Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now
Telnyx Targeted in Expanding TeamPCP Supply Chain Attack
The TeamPCP supply chain attack campaign has expanded its scope to target Telnyx, with malicious versions of the Telnyx Python SDK uploaded to the PyPI package registry. Two compromised SDK versions, 4.87.1 and 4.87.2, were distributed alongside malicious versions of the Trivy GitHub Action, affecting Windows, macOS, and Linux environments. The attack demonstrates the persistent threat posed by compromised development tools and package repositories, with the potential to compromise any organization relying on these dependencies.
Source: Telnyx Targeted in Growing TeamPCP Supply Chain Attack
Closing Perspective
The convergence of state-sponsored mobile exploitation, critical infrastructure vulnerabilities in active use, and supply chain compromises underscores the multifaceted nature of today's threat environment. Organizations must prioritize patching critical F5 infrastructure, review their software supply chain dependencies, and implement comprehensive mobile device security controls to address these emerging risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Unauthenticated remote code execution in F5 BIG-IP Access Policy Manager; actively exploited in the wild
- Critical RCE in F5 BIG-IP APM; actively exploited to deploy webshells
- Trivy GitHub Action (malicious versions)Initial TeamPCP target; 470+ repositories identified running malicious versions
- Telnyx Python SDK v4.87.2Malicious package version uploaded to PyPI
- LiteLLM PyPI package (compromised)Previous TeamPCP target in supply chain campaign
- TeamPCPThreat actor conducting multi-week supply chain campaign targeting open source ecosystems
- Telnyx Python SDK v4.87.1Malicious package version uploaded to PyPI