Weekly review

ThreatNoir Weekend Brief — April 26

2026-04-26Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — April 26, 2026

April 26, 2026 brings a significant wave of cybersecurity incidents spanning multiple threat vectors, from targeted malware campaigns to large-scale data breaches affecting critical infrastructure and financial institutions worldwide. The threat landscape today reflects both sophisticated social engineering attacks and vulnerabilities in high-profile systems.

Threat Actor Deploys Multi-Stage "Snow" Malware via Microsoft Teams

The threat group UNC6692 has been observed leveraging social engineering tactics through Microsoft Teams to distribute a custom malware suite designated "Snow." The attack chain includes multiple components: a browser extension, a tunneler, and a backdoor capability. This campaign demonstrates the continued effectiveness of social engineering vectors targeting widely-used collaboration platforms. Source: Threat actor uses Microsoft Teams to deploy new "Snow" malware

AgelessRx Telehealth Platform Suffers Patient Data Breach

AgelessRx, a U.S.-based telehealth platform specializing in longevity and anti-aging medicine, has allegedly experienced a data breach exposing patient and prescription information. The compromised data is currently being offered for sale on a cybercrime forum. This incident raises significant concerns regarding HIPAA compliance and the protection of sensitive health information within the telehealth sector. Source: ‼️🇺🇸 AgelessRx, a U.S.-based telehealth platform focused on longevity and anti-aging medicine,...

Critical IDOR Vulnerability Exposes 2 Million Customer Records in Brazil

A threat actor is actively marketing a critical Insecure Direct Object Reference (IDOR) vulnerability affecting an unidentified Brazilian company on the dark web. The vulnerability allegedly provides unauthorized access to personal data belonging to approximately 2 million customers. This type of access control vulnerability represents a significant risk to organizations that fail to implement proper authorization checks. Source: ‼️🇧🇷 A threat actor is selling a critical Insecure Direct Object Reference (IDOR) vulnerability...

LAPSUS$ Group Claims Three Major Victims Across Multiple Countries

The LAPSUS$ threat group has announced successful breaches of three significant organizations: MAPFRE in Spain, Vodafone in the United Kingdom, and Checkmarx in Israel. These claims underscore the group's continued operational capability and global reach in targeting high-profile entities across diverse sectors and geographies. Source: ‼️ LAPSUS$ Group claims 3 victims

Litecoin Experiences Zero-Day Denial of Service Attack Affecting Mining Infrastructure

Litecoin has confirmed that a zero-day vulnerability enabled a denial of service attack against major mining pools. The vulnerability allowed non-updated nodes to accept invalid MWEB transactions that were subsequently pegged to third-party decentralized exchanges. Network operators implemented a 13-block reorganization to reverse the invalid transactions and prevent their inclusion in the main blockchain. Source: 🚨 Litecoin has confirmed a zero-day bug caused a DoS attack that disrupted major mining pools...

Iranian Military Database Breached and Listed for Sale on Dark Web

A threat actor operating under the alias MDGhost is allegedly selling a 3-terabyte database purportedly containing sensitive information from Oghab 44, a known Iranian underground military air base. The offering is priced at $10,000 USD on a cybercrime forum. This incident represents a significant national security concern regarding the compromise of military infrastructure data. Source: ‼️🇮🇷 A threat actor is allegedly selling a 3TB Iranian military database tied to Oghab 44...

Dubai Transport Authority Data Breach Exposes Critical Infrastructure Documentation

A threat actor operating under the alias simplex29 is marketing an alleged data breach from the Dubai Transport Authority for $800. The offering comprises 301 files totaling 877 megabytes and purportedly includes permits, engineering diagrams, technical reports, and project documentation. This breach of critical transportation infrastructure raises concerns regarding the security of essential public services. Source: ‼️🇦🇪 A threat actor operating under the alias simplex29 is selling an alleged data breach from...

Banco Falabella Subsidiary Experiences Second Data Breach in Ongoing Security Failure

Falabella Cobranza, the debt collection service operated by Banco Falabella through Conalcreditos Emergiacc Colombia, has suffered a second data breach with additional records leaked on cybercrime forums. This repeated compromise suggests inadequate remediation efforts following the initial breach and raises questions regarding the organization's incident response and security posture. Source: ‼️🇨🇴 Banco Falabella's debt collection service Falabella Cobranza...

Today's threat intelligence reveals a concerning pattern of both opportunistic exploitation of known vulnerabilities and sophisticated targeted campaigns against critical infrastructure, financial institutions, and government entities. Organizations must prioritize implementation of robust access controls, timely patching of zero-day vulnerabilities, and comprehensive incident response protocols to mitigate escalating risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Threat actor uses Microsoft Teams to deploy new “Snow” malware
Malware4
  • SnowBelt
    Malicious Chrome extension for persistence and command relay
  • Snow
    Custom malware suite including SnowBelt, SnowGlaze, and SnowBasin components
  • SnowGlaze
    WebSocket tunneler masking C2 communications with SOCKS proxy support
  • SnowBasin
    Python-based backdoor executing CMD/PowerShell commands via local HTTP server