ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th)

2026-03-25T07:23:44Z896a4fe43ea6b882118a3463b8079508bacb07d90ee24e95a900636a11b6f458
ArechClient2CowrieDShieldGSocketIP KVMNetSupportRATRemcosSectopSmartApeSGStealCbackdoorbash scripthoneypotmalwarerogue devicetelnet compromisethreat campaign

What happened

The ISC SANS diary cluster (Mar 18–25, 2026) describes several active threats and observations: a SmartApeSG campaign distributing multiple RATs and stealers (Remcos RAT, NetSupport RAT, StealC, and Sectop/ArechClient2); discovery of a malicious Bash script that installs a GSocket backdoor; discussion of IP KVM security issues including vulnerable and rogue IP KVM devices being abused for remote access; and honeypot (Cowrie/DShield) logs showing telnet compromise and an unusual payload marker (“MAGIC_PAYLOAD_KILLER_…iranbot_was_here”). The posts also include tool/security fixes and routine ISC

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
896a4fe43ea6b882118a3463b8079508bacb07d90ee24e95a900636a11b6f458
Enrichment time
2026-03-25T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th) · Baitaphish