Attackers Hide Infostealer in Copyright Infringement Notices

2026-03-23T20:51:39Z995ea7c4e4f5498ff29060d887065d0302b0af5d7072d4e41517f3ae650679ef
C2 implantCisco firewallOracle Fusion Middlewarecryptomining/crypto-wallet-targetingespionageexploitiOS exploitinfostealermalwarephishingransomwaresupply-chainthreat-intelligencevulnerabilityzero-day

What happened

A DarkReading news roundup highlighting a surge in high-risk activity and diverse TTPs: phishing-delivered infostealers disguised as copyright infringement notices targeting healthcare, government, hospitality and education; a critical unauthenticated RCE in Oracle Fusion Middleware; Interlock ransomware exploiting a pre-disclosure Cisco firewall vulnerability; multiple zero-day iOS exploits (DarkSword) used in targeted espionage; a new C2 implant (SnappyClient) targeting crypto wallets; GlassWorm supply-chain infections in Open VSX; and expanded espionage campaigns (SideWinder, China‑Nexus).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
995ea7c4e4f5498ff29060d887065d0302b0af5d7072d4e41517f3ae650679ef
Enrichment time
2026-03-23T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers Hide Infostealer in Copyright Infringement Notices · Baitaphish