- Unrestricted file upload vulnerability in ShowDoc enabling PHP web shell execution and RCE
ThreatNoir Weekend Brief — April 19
Morning Review in IT Security — April 19, 2026
The IT security landscape continues to face mounting pressure from multiple threat vectors on April 19, 2026. Today's briefing covers critical vulnerabilities in widely deployed libraries, exploitation of legacy security gaps, advanced evasion techniques in ransomware campaigns, and coordinated malware targeting financial infrastructure across mobile platforms.
Critical Flaw in Protobuf Library Enables JavaScript Code Execution
A critical remote code execution vulnerability has been discovered in protobuf.js, the widely used JavaScript implementation of Google's Protocol Buffers. The severity of this flaw is underscored by the publication of proof-of-concept exploit code, which enables attackers to execute arbitrary code through the library. Given the ubiquitous nature of Protocol Buffers in modern application development, this vulnerability poses a significant supply chain risk affecting millions of applications globally. Source: Critical flaw in Protobuf library enables JavaScript code execution
ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers
A five-year-old vulnerability in ShowDoc, identified as CVE-2025-0520 and patched in 2020, is now being actively exploited by threat actors worldwide. Attackers are leveraging this flaw to deploy web shells on unpatched systems, achieving remote code execution and complete server takeover capabilities. The continued exploitation of this legacy vulnerability highlights the persistent challenge of patch management across global infrastructure. Source: ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers
Payouts King Ransomware Uses QEMU VMs to Bypass Endpoint Security
The Payouts King ransomware has adopted an innovative evasion technique by leveraging QEMU emulator technology to establish hidden virtual machines on compromised systems. By utilizing QEMU as a reverse SSH backdoor, the malware operates within virtualized environments that remain invisible to traditional endpoint security solutions. This campaign incorporates multiple command and control frameworks, including AdaptixC2 and Havoc C2, and exploits CVE-2025-26399 and CVE-2025-5777 to enhance its operational effectiveness. Source: Payouts King ransomware uses QEMU VMs to bypass endpoint security
New RecruitRat, SaferRat, Astrinox, Massiv Android Malware Found Targeting 800 Apps
Research from Zimperium has identified four active Android malware families—RecruitRat, SaferRat, Astrinox, and Massiv—conducting coordinated campaigns against over 800 banking applications globally. These malware families employ social engineering tactics to compromise mobile devices and gain access to financial infrastructure. The scale and coordination of these campaigns represent a significant threat to banking sector security and consumer financial accounts. Source: New RecruitRat, SaferRat, Astrinox, Massiv Android Malware Found Targeting 800 Apps
Security teams face an escalating threat environment requiring immediate attention to supply chain vulnerabilities, legacy system patching, advanced malware evasion techniques, and mobile banking security. Organizations are advised to prioritize vulnerability remediation, implement robust endpoint detection and response capabilities, and enhance mobile application security monitoring.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- SolarWinds Web Help Desk vulnerability exploited for initial access in STAC4713 campaign
- CitrixBleed 2 vulnerability in NetScaler ADC/Gateway exploited in STAC3725 campaign
- Payouts KingRansomware using QEMU VMs to bypass endpoint security
- AdaptixC2Command & control tool deployed in hidden QEMU VM
- Havoc C2C2 payload sideloaded via vcruntime140_1.dll in later attacks
- AstrinoxAndroid malware mimicking HireX business tool, distributed via fake Apple App Store page
- MassivAndroid malware with unclear distribution vector; highly obfuscated
- SaferRatAndroid malware using phishing sites promising free premium video streaming to lure users
- RecruitRatAndroid malware targeting banking apps via fake job-seeking sites; contains library of 700+ fake login pages