ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th)
2026-03-25T07:23:44Z•896a4fe43ea6b882118a3463b8079508bacb07d90ee24e95a900636a11b6f458
ArechClient2CowrieDShieldGSocketIP KVMNetSupportRATRemcosSectopSmartApeSGStealCbackdoorbash scripthoneypotmalwarerogue devicetelnet compromisethreat campaign
What happened
The ISC SANS diary cluster (Mar 18–25, 2026) describes several active threats and observations: a SmartApeSG campaign distributing multiple RATs and stealers (Remcos RAT, NetSupport RAT, StealC, and Sectop/ArechClient2); discovery of a malicious Bash script that installs a GSocket backdoor; discussion of IP KVM security issues including vulnerable and rogue IP KVM devices being abused for remote access; and honeypot (Cowrie/DShield) logs showing telnet compromise and an unusual payload marker (“MAGIC_PAYLOAD_KILLER_…iranbot_was_here”). The posts also include tool/security fixes and routine ISC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 896a4fe43ea6b882118a3463b8079508bacb07d90ee24e95a900636a11b6f458
- Enrichment time
- 2026-03-25T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.