- APT-Q-27 malware samplesSamples signed with DigiCert certificates
ThreatNoir Weekend Brief — April 11
Afternoon Review in IT Security — April 11, 2026
The security landscape continues to evolve with significant developments spanning law enforcement surveillance capabilities, push notification vulnerabilities, advanced persistent threat operations, and state-sponsored attacks on critical infrastructure. Today's briefing covers four critical stories that underscore emerging threats to both individual privacy and national security.
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
Hungarian domestic intelligence, the national police in El Salvador, and several U.S. law enforcement and police departments have been attributed to using an advertising-based global geolocation surveillance system called Webloc. The tool was developed by Israeli company Cobwebs Technologies and is now sold by its successor Penlink following the two firms' merger in July 2023. This widespread adoption of ad-based tracking demonstrates how commercial surveillance infrastructure has become integrated into law enforcement operations globally. Source: Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
Your Push Notifications Aren't Safe From the FBI
Push notifications have emerged as a previously underappreciated vector for law enforcement access to encrypted communications and user data. Beyond push notification vulnerabilities, the week also brought reports of Iran's internet blackout exceeding the 1,000-hour mark and cryptocurrency scams resulting in record amounts of money stolen from Americans. These developments highlight how communication channels considered secure by end users may be compromised through technical means accessible to government agencies. Source: Your Push Notifications Aren't Safe From the FBI
APT-Q-27 Exploits Legitimate Code-Signing Certificates in Supply Chain Attack
Advanced persistent threat actors designated APT-Q-27 have been observed using code-signing certificates issued by DigiCert to legitimate organizations, including a Swiss software company called Brunner Informatik AG founded in 1985, to distribute malware while evading detection. The discovery came just two days after initial samples were reported, indicating the rapid pace at which these sophisticated actors operate. This technique of abusing legitimate certificate infrastructure represents a critical supply chain vulnerability that affects software distribution channels globally. Source: And it was only 2 days ago when I told @SquiblydooBlog about a sample from this APT-Q-27 actors t...
Iranian Attacks on US Critical Infrastructure Puts 3,900 Devices in Crosshairs
Censys researchers have warned that thousands of devices are exposed to the Iranian government's campaign targeting energy, water, and U.S. government services and facilities. The research identified approximately 3,900 devices vulnerable to Iranian cyber operations, with threat actors leveraging techniques including firmware update mode activation and controller tasking modification against industrial operational technology systems. The targeting of critical infrastructure sectors underscores the persistent threat posed by state-sponsored actors to essential services. Source: Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs
Today's threat landscape reflects a convergence of law enforcement surveillance capabilities, communication channel vulnerabilities, sophisticated supply chain attacks, and state-sponsored critical infrastructure targeting. Organizations and individuals must remain vigilant across multiple security domains as threats continue to evolve in complexity and scope.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- PLC exploitation for industrial automation control manipulation
- Potential device firmware compromise in OT environments