Major Stories of the Month
Interlock Ransomware Exploits Cisco Secure FMC Zero-Day
- The Interlock ransomware gang exploited a maximum-severity (CVSS 10.0) vulnerability (CVE-2026-20131) in the Cisco Secure Firewall Management Center.
- This unauthenticated root-level remote code execution flaw was exploited starting on January 26, 2026, which was 36 days prior to its public disclosure.
- This incident demonstrates the persistent targeting of enterprise network security infrastructure, with ransomware groups maintaining sophisticated zero-day exploitation capabilities against hardened perimeter devices.
TeamPCP Orchestrates Mass CI/CD Supply Chain Compromise
- In a coordinated supply chain attack, the threat group TeamPCP (first documented by Rubrik Zero Labs in 2025) hijacked 75 of 76 GitHub version tags for the widely used Aqua Security Trivy vulnerability scanner, alongside Checkmarx KICS and LiteLLM PyPI packages.
- The attackers deployed "CanisterWorm," a self-propagating malware designed to steal AWS, GCP, Azure, SSH, and Docker credentials directly from compromised developer CI/CD pipelines.
- The malware notably included geofencing to wipe data on systems using Iran's timezone or Farsi, and it potentially affects over 10,000 downstream organizations running the compromised scanner versions.
ShinyHunters Breaches Nearly 400 Salesforce Instances
- The threat group ShinyHunters launched a massive campaign compromising nearly 400 Salesforce Experience Cloud instances.
- The attackers used a modified AuraInspector tool to exploit misconfigured guest user permissions and exfiltrate sensitive CRM data via automated scanning of publicly accessible sites.
- This marks the third major Salesforce customer breach campaign in six months, highlighting the systematic targeting of widely deployed cloud infrastructure.
Top Ransomware Groups
Note: In 2025, ransomware attack volume surged by 50-57%, yet victim payment rates dropped to a record low of 28%. In response, threat actors are increasingly shifting to "recovery denial" tactics—systematically destroying backups, targeting virtualization infrastructure like ESXi, and leveraging 90+ EDR killer tools (54 of which use BYOVD techniques) to disable endpoint security from the kernel level.
- INC Ransom - High-volume campaigns aggressively targeting the healthcare, legal, and education sectors globally. Massive disruption forced the University of Mississippi Medical Center to close 36 clinics statewide. Exfiltrated 2TB of data (237,830+ individuals) from the National Association on Drug Abuse Programs.
- Interlock - Highly sophisticated operations capable of discovering and utilizing network appliance zero-days exploited the Cisco Secure FMC CVSS 10.0 zero-day (CVE-2026-20131) starting in January 2026, granting unauthenticated root-level code execution on enterprise firewalls.
- Medusa (Lazarus Group) - North Korean state-sponsored APT (Diamond Sleet) adopted ransomware for financially motivated extortion in a critical infrastructure threat targeting U.S. healthcare and Middle Eastern organizations to fund espionage operations.
- Qilin - The active, high-volume operator has been tracked targeting manufacturing, engineering, and healthcare entities globally resulting in severe corporate data exposure. Reported victims include the manufacturing firm Southwire, CJL Engineering, and Aroostook Mental Health Services.
- The Gentlemen - This group is rapidly expanding global operations targeting hypervisors, manufacturing, fitness, and energy sectors. It has successfully breached ControlGMC in Canada, PTT Philippines energy, and SATS Nordic fitness, among others, to date.
Linux / Cloud / Identity Attacks: Top Threats
These threats were selected based on their severity scores (CVSS) and their direct, widespread impact on enterprise cloud, automation, and identity infrastructures.
1. n8n Workflow Automation Platform RCE (CVE-2025-68613)
- Type: Cloud / Automation Platform
- Impact: A critical expression injection flaw allowing unauthenticated remote code execution on the centralized automation platform.
- CVSS 9.9. An active exploitation was confirmed in the wild, exposing over 24,700 internet-facing instances, prompting its addition to the CISA KEV catalog on March 11, 2026.
2. Oracle Identity Manager Unauthenticated RCE (CVE-2026-21992)
- Type: Identity & Access Management
- Impact: A missing authentication flaw for a critical function enables complete system compromise and unauthenticated remote code execution in Oracle Identity Manager and Web Services Manager.
- CVSS 9.8. Prompted an emergency out-of-band patch with federal agencies ordered to be implemented immediately. Oracle noted possible zero-day exploitation prior to disclosure, exposing financial, government, and critical sectors.
3. VMware Aria Operations Command Injection (CVE-2026-22719)
- Type: Cloud Infrastructure Management
- Impact: An actively exploited command injection vulnerability affecting Broadcom VMware Aria Operations. Unauthenticated attackers can execute commands during support-assisted migration processes.
- CVSS 8.1. Added to the CISA KEV catalog after confirmed active exploitation, giving attackers potential access to managed cloud resources across enterprise hybrid environments.
Insights from Rubrik Zero Labs' LLM-Powered Advanced Analysis Systems
Top Threats Inside Backups: Our advanced analysis systems identify top and trending threats seen in the wild and compare that data with backup telemetry to detect stealthy malware. The following are the most prevalent families seen in the backup data that are potentially successful in bypassing first-line defenses.
Remote Access Trojans (RATs) & InfoStealers
These tools are primarily designed to spy on users, steal sensitive data, and maintain control over a victim's machine.
- Vidar: A highly adaptable information stealer that targets browser credentials, cryptocurrency wallets, and banking information, often acting as a secondary dropper for other malware.
- LummaStealer: A C-based information stealer sold on underground forums that specializes in exfiltrating two-factor authentication codes, browser data, and cryptocurrency wallet files.
- Snake Keylogger: A .NET-based credential harvester and keylogger that captures keystrokes, steals saved passwords from web browsers, and takes screenshots of the infected system.
Ransomware
Malware designed to encrypt files and demand payment for the decryption key.
- Pay2Key: A fast-acting ransomware strain that relies on compromised remote desktop access to quickly encrypt entire enterprise networks, heavily utilizing double extortion tactics.
- Interlock: A recently discovered ransomware family that targets corporate environments, systematically exfiltrating sensitive corporate data before encrypting local files and network shares.
- Qilin: A sophisticated Ransomware-as-a-Service (RaaS) operation written in Rust that specializes in highly customized, double-extortion attacks against critical infrastructure and corporate domains.
Top Threats Analysed/flagged by our Advanced malware analysis systems:
SHA256: fc1cd6ab782397871c18568a691569a3bba8a45aaed9792c560dd60a06553821(SCADA-targeting trojan with worm capabilities)
Summary: This IronGate-family SCADA malware targets industrial control systems by extracting embedded executables and searching network shares for 'move-to-operational' hot folders. It employs worm-like lateral movement and anti-sandbox detection designed specifically for operational technology environments.
First_Seen: 2026-02-27
SHA256: ccca0b988e0d828983e91228c5619a0a42e394c7c8414aeaef764501f2f00472(Linux Backdoor)
Summary: TheTick is a Linux backdoor that offers comprehensive remote access capabilities, including command execution, TCP pivoting, file operations, and HTTP downloads. It establishes persistent Command and Control (C2) connections and employs basic anti-debugging environment detection.
First_Seen: 2026-02-11
SHA256: fb4fb8b40544b9084bb3d311483626fe72e651713537280ca5fa3342eb83e573(Backdoor/Remote Access Trojan)
Summary: This MIPS-based router backdoor is disguised as PPTP/OpenVPN binaries to target embedded devices and SOHO routers running uClibc-based Linux systems. It manipulates VPN control protocols to establish persistent remote access, utilizing process name spoofing and UPX packing to evade detection.
First_Seen: 2026-03-16
SHA256: 389fc13f33d90dbb335b3ad2a9b344f0b45d782b6634577216028e209689b5bd(Credential Dumper / Post-Exploitation Tool)
Summary: KslDump is a highly sophisticated credential dumping tool that exploits the CVE-2024-26229 vulnerability in Microsoft Defender's KslD.sys driver. It performs kernel-level memory access to bypass Protected Process Light (PPL) protections and extracts credentials directly from lsass.exe physical memory.
First_Seen: 2026-03-18
SHA256: 1e6487b7fbb9a0ff4c1d7032bfecd153fa6b9cc3c523243e8183588a98168267(Multi-stage Python dropper/loader trojan)
Summary: GlassWorm is a sophisticated multi-stage Python trojan that utilizes Solana blockchain transaction memos as a novel, decentralized C2 dead drop. It implements strict geofencing to avoid Russian systems, downloads the Node.js runtime, and executes encrypted JavaScript payloads.
First_Seen: 2026-03-16
SHA256: fc3c94c62b42df24ee52a467f3a6e42d24621a59e1c61cbc6a79bae2cb2b53a8(Advanced PHP Webshell/File Manager)
Summary: Alfa TEaM Shell (Tesla v4.1) is a mature, professional-grade PHP webshell offering comprehensive remote administration and offensive capabilities. Features include database management, CMS hijacking modules, brute-forcing capabilities, file manipulation, and built-in anti-forensics.
First_Seen: 2026-03-02
SHA256: 0b24019b216493de87a2ea8f6c60b097577889a86c39095caedc9e3d212cce29(Remote Access Trojan (RAT) / Information Stealer / Dropper)
Summary: This sophisticated PowerShell-based RAT uses a browser's native messaging protocol for a covert C2 channel. It features advanced credential theft techniques that bypass Chrome and Edge App-Bound Encryption through COM elevation service exploitation and process injection.
First_Seen: 2026-03-05
SHA256: a58a27da427cfa745650fd1ef7dfeafb1720ded1f050a9c9e783d877fc4535ea(APT Simulation Framework / Training Tool)
Summary: GhostWeaver is a legitimate red team APT simulation framework designed for security training, not actual malware. It simulates sophisticated attacks across 7 phases, including sandbox evasion, process masquerading, credential harvesting, and DNS-based C2 beaconing.
First_Seen: 2026-02-18
SHA256: ea544bf1caa96e0e272d4f0c35315cd7ec211aba034613cc82816cccf4f65c7d(ELF Shared Library Payload)
Summary: This 64-bit ELF shared library acts as a modular backdoor or RAT component on Linux systems. It demonstrates professional-quality development, heavily utilizing standard POSIX and GLIBC APIs for network C2 capabilities, multi-threading, process management, and signal handling.
First_Seen: 2026-02-18
SHA256: 9f94e2df4306bb4aa9988ab18f975d0963d9fbd03b6a96a976687812f1b2612e(Exploit Kit / Mass Exploitation Tool / Botnet Recruitment)
Summary: This mass exploitation toolkit targets the GeoServer CVE-2024-36401 RCE vulnerability. It leverages the FOFA search API to automatically discover vulnerable global instances and exploit the WFS endpoint to deliver the 'angelax86' malware payload or execute DoS reboots.
First_Seen: 2026-03-06
SHA256: c6922cb0125c52f094945d28ba544deceb22c64083af24170630be89bed452f1(Ransomware) Summary: Linux/Filecoder.FU is a competent Linux ransomware that implements ChaCha20 stream cipher encryption alongside Curve25519 key exchange. It features multi-threaded file encryption driven by XML-based configurations and utilizes process name obfuscation to evade detection.
First_Seen: 2026-02-19
SHA256: 68e4d5aea249288fbdf8ea70be7b3911d1e6cf8cc6be1271fbb2aa5774c51e78(Remote Access Trojan (RAT) / Multi-platform Spyware Framework)
Summary: OmnispyRAT is a sophisticated multi-platform RAT framework written in Python, equipped with extensive spyware, persistence, and evasion modules. Its advanced features include a multi-channel C2 setup (HTTP/Telegram/DNS tunneling), multi-method keylogging, and browser credential theft with DPAPI decryption.
First_Seen: 2026-03-07
SHA256: afe9a0298d945105ee69e84bdd7c41f35dad869a44098cb7e65a6a32a01cc617(APT Reconnaissance Malware / LNK-based dropper)
Summary: Attributed to North Korean APT actors (ROKRAT), this malware is delivered via a weaponized 44KB LNK dropper containing an obfuscated PowerShell payload. It conducts environmental reconnaissance, self-identification, and executes conditionally based on location detection to bypass sandboxes.
First_Seen: 2026-03-03
LATEST BLOGS