Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)

2026-04-02T01:23:50Zd92973ae20ea0254b70b741661146e7262ba25c73f8bc846f1dd41bf9cc36ead
AstraZenecaCowrieDShieldDatabricksPyPITeamPCPTelnyxVectapplication-control-bypasscloud-enumerationdata-exfiltrationfileless-malwarehoneypotpost-compromiseransomwareregistry-persistencesupply-chainsupply-chain-campaignthreat-intel

What happened

SANS ISC diary (Mar 27–Apr 1, 2026) aggregates multiple security notes: a rapidly evolving TeamPCP supply‑chain campaign (Telnyx PyPI compromise, Databricks investigation, dual ransomware operations including Vect affiliate activity, AstraZeneca data release, first confirmed victim disclosure, and post‑compromise cloud enumeration) plus posts on a malicious “fileless” script using the registry for persistence/ADS removal, application‑control bypass techniques enabling data exfiltration, and DShield/Cowrie honeypot session analysis. The primary operational risk is active supply‑chain compromise

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d92973ae20ea0254b70b741661146e7262ba25c73f8bc846f1dd41bf9cc36ead
Enrichment time
2026-04-02T01:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.