Multi-Stage "BadPaw" Malware Campaign Targets Ukraine

2026-03-04T21:10:53Z9dd408c206820c7cbcd3077609a833a935d40596ced83329f4604589443e058b
aeternumai-powered-attacksandroid-malwarebadpawbotnetcisco-sd-wanclawjackeddeepfakesfortigatefortinetgenaigoogle-geminimalwarenpmnugetphishingpolygon-blockchainransomware','medusa','lazarus','apt37','iranian-actors','north-kredalertshai-huludsms-phishingspywaresupply-chaintrojanized-appzero-day

What happened

A concentrated wave of high-risk cyber activity is reported across multiple fronts: multi-stage malware and espionage campaigns (BadPaw, RedAlert, trojanized apps/SMS) targeting Ukraine and Israel; nation-state activity and tooling expansions (Iranian actors, North Korea’s APT37 and Lazarus/Medusa, UNC2814); supply‑chain and developer-targeted threats (malicious npm/NuGet packages, Shai‑Hulud-like worm); infrastructure and zero‑day concerns (urgent patching for a Cisco SD‑WAN zero day, the ClawJacked AI‑agent hijack bug, FortiGate exploitation); and novel operational shifts (Aeternum botnet C2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
9dd408c206820c7cbcd3077609a833a935d40596ced83329f4604589443e058b
Enrichment time
2026-03-04T21:10:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.