ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th)
2026-03-25T13:23:47Z•352151764aabdaf660e3248ad9b397172c86e7c4e33b4fd220cf48af51ab05a9
ArechClient2BashDShieldEclypsiumGSocketIOCIP-KVMIranbotNetSupportRATRemcosSectopSmartApeSGStealCbackdoorcowriedetectionhoneypotmalwareportscanrogue-KVMtelnetthreat-campaign
What happened
SANS ISC entries (Mar 18–25, 2026) highlight multiple active threats and detection guidance: a SmartApeSG campaign delivering multiple RATs (Remcos RAT, NetSupport RAT, StealC, and Sectop/ArechClient2); a malicious Bash script that installs a GSocket backdoor (delivery vector unknown); and research/discussion of IP KVM vulnerabilities and risks from rogue IP KVM devices (including documented abuse cases). Honeypot/cowrie logs show suspicious activity and an implanted message ("MAGIC_PAYLOAD_KILLER...iranbot...was here") with related portscans, Telnet successful login and web access from IP 64.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 352151764aabdaf660e3248ad9b397172c86e7c4e33b4fd220cf48af51ab05a9
- Enrichment time
- 2026-03-25T13:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.