Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)
2026-04-02T01:23:50Z•d92973ae20ea0254b70b741661146e7262ba25c73f8bc846f1dd41bf9cc36ead
AstraZenecaCowrieDShieldDatabricksPyPITeamPCPTelnyxVectapplication-control-bypasscloud-enumerationdata-exfiltrationfileless-malwarehoneypotpost-compromiseransomwareregistry-persistencesupply-chainsupply-chain-campaignthreat-intel
What happened
SANS ISC diary (Mar 27–Apr 1, 2026) aggregates multiple security notes: a rapidly evolving TeamPCP supply‑chain campaign (Telnyx PyPI compromise, Databricks investigation, dual ransomware operations including Vect affiliate activity, AstraZeneca data release, first confirmed victim disclosure, and post‑compromise cloud enumeration) plus posts on a malicious “fileless” script using the registry for persistence/ADS removal, application‑control bypass techniques enabling data exfiltration, and DShield/Cowrie honeypot session analysis. The primary operational risk is active supply‑chain compromise
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- d92973ae20ea0254b70b741661146e7262ba25c73f8bc846f1dd41bf9cc36ead
- Enrichment time
- 2026-04-02T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.