169.40.2.68C2 server receiving exfiltrated data and delivering second-stage payloads
ThreatNoir Afternoon Brief — April 9
Afternoon Review in IT Security — April 9, 2026
The threat landscape continues to evolve rapidly as researchers uncover critical vulnerabilities across multiple domains. Today's review highlights sophisticated attacks targeting Adobe Reader users, cryptocurrency theft through supply chain compromise, and emerging security gaps in artificial intelligence systems.
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Threat actors have been actively exploiting a previously unknown zero-day vulnerability in Adobe Reader through maliciously crafted PDF documents since at least December 2025. Security researcher Haifei Li from EXPMON has detailed this highly sophisticated PDF exploit, which represents a significant risk to users who rely on Adobe Reader for document handling. The malicious artifact, identified as "Invoice540.pdf," first appeared on the VirusTotal platform on November 28, 2025, suggesting the threat may have been in circulation even earlier than initial exploitation reports indicate. Source: The Hacker News
The Long Road to Your Crypto: ClipBanker and Its Marathon Infection Chain
Threat actors are distributing a sophisticated Trojan disguised as legitimate Proxifier software, which initiates a multi-stage infection chain designed to deliver ClipBanker malware. This clipboard-hijacking malware operates by replacing cryptocurrency wallet addresses copied by users, effectively redirecting funds to attacker-controlled wallets. The attack demonstrates how supply chain compromises and social engineering can work in tandem to establish persistent threats within victim systems. Source: Securelist
Claude Code Can Be Manipulated via CLAUDE.md to Run SQL Injection Attacks
Researchers at LayerX have identified a critical vulnerability in Claude Code that allows attackers to bypass safety rules through manipulation of the CLAUDE.md configuration file. This exploit enables threat actors to execute SQL injection attacks and other malicious operations that the AI assistant's safety mechanisms were designed to prevent. The discovery highlights how AI systems can be compromised through configuration-level attacks rather than direct code manipulation. Source: Hackread
Apple Intelligence AI Guardrails Bypassed in New Attack
Researchers from RSAC have successfully bypassed Apple Intelligence's safety guardrails using a combination of the Neural Exect method and Unicode manipulation techniques. The attack demonstrates that modern AI safety mechanisms can be circumvented through prompt injection and character encoding tricks, raising concerns about the robustness of Apple's artificial intelligence implementation. Source: SecurityWeek
As organizations navigate an increasingly complex threat environment, the convergence of traditional malware campaigns, supply chain attacks, and AI-based vulnerabilities demands comprehensive security strategies that address both legacy and emerging attack vectors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- ClipBankerClipboard-hijacking malware that replaces cryptocurrency wallet addresses
- Proxifier TrojanInitial infection vector disguised as legitimate Proxifier software
hxxps://maper[.]info/2X5tF5IP Logger service pinged to confirm successful infection
- SQL injectionAttack technique demonstrated via Claude Code manipulation to dump databases and steal credentials