Weekly review

ThreatNoir Afternoon Brief — April 17

2026-04-17Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 17, 2026

The threat landscape continues to evolve with critical vulnerabilities being actively exploited and sophisticated malware campaigns targeting both critical infrastructure and software supply chains. Today's review covers emerging threats ranging from nation-state attacks on water systems to widespread exploitation of long-dormant software flaws.

New ZionSiphon Malware Discovered Targeting Israeli Water Systems

Researchers at Darktrace have identified a new malware strain called ZionSiphon that is specifically designed to target Israeli water treatment plants. This threat represents a significant concern for operational technology environments, as the malware is engineered to exploit vulnerabilities in industrial control systems and supervisory control and data acquisition (SCADA) networks. The discovery highlights the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure through specialized attack vectors including USB-based delivery and ICS protocol exploitation. Source: New ZionSiphon Malware Discovered Targeting Israeli Water Systems

Recent Apache ActiveMQ Vulnerability Exploited in the Wild

A remote code execution vulnerability in Apache ActiveMQ, tracked as CVE-2026-34197, has been actively exploited in the wild following its discovery in early April. This vulnerability represents a critical risk to organizations running affected versions of the widely-used open-source messaging platform. The active exploitation underscores the importance of rapid patching cycles for critical infrastructure components, particularly those that manage message queuing and enterprise communications. Source: Recent Apache ActiveMQ Vulnerability Exploited in the Wild

CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has officially warned that attackers are now actively exploiting a high-severity Apache ActiveMQ vulnerability that remained undetected for thirteen years before being patched earlier this month. The vulnerability, tracked as CVE-2026-34197, has become a focal point for threat actors seeking to compromise enterprise systems. Additionally, CISA noted that related vulnerabilities including CVE-2023-46604 and CVE-2016-3088 are also being leveraged in coordinated attacks, with the TellYouThePass malware being deployed as a payload in some incidents. Source: CISA flags Apache ActiveMQ flaw as actively exploited in attacks

New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files

A sophisticated malware campaign is distributing two distinct threats—CGrabber Stealer and Direct-Sys Loader—through malicious ZIP files hosted on GitHub. The attackers have employed advanced evasion techniques to bypass security tools while stealing passwords, cryptocurrency wallet credentials, and sensitive user data. The campaign utilizes multiple components including Launcher_x64.exe, msys-crypto-3.dll, and packages distributed under names such as Eclipsyn.zip to maximize infection rates and evade detection mechanisms. This supply chain attack vector demonstrates how legitimate platforms can be weaponized to distribute credential-stealing malware at scale. Source: New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files

The convergence of nation-state targeting of critical infrastructure, exploitation of long-unpatched vulnerabilities, and supply chain-based malware distribution reflects a threat environment requiring heightened vigilance across both enterprise and critical infrastructure sectors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files
Malware5
  • CGrabber Stealer
    Information stealer targeting passwords, credit cards, crypto keys, and browser data
  • Eclipsyn.zip
    ZIP archive filename used to distribute malware via GitHub attachment links
  • msys-crypto-3.dll
    Malicious DLL sideloaded as fake dependency to execute loader payload
  • Launcher_x64.exe
    Legitimate Microsoft-signed executable abused via DLL sideloading in attack chain
  • Direct-Sys Loader
    Multi-stage loader performing security tool detection and syscall-based evasion