ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th)

2026-03-19T13:23:47Zeddc187f7d905e0e4ccab6978aabb99c24c5fcfaac05cece58d600dffc856c10
EmailJSIPv4-mapped-IPv6RATReactRemcosSmartApeSGadminercowriecredential-thefthoneypotindicator:64.89.161.198magic_payload_stringmalware-campaignphishingphpmyadminportscanproxy-scanstelnetweb-application-scanning

What happened

SANS ISC diary roundup (Mar 13–19, 2026): multiple honeypot and incident reports including Cowrie logs showing an echo command containing the string "MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here" and activity tied to source IP 64.89.161.198 (portscans, successful Telnet login). Wide scanning activity targeting web management tools (phpMyAdmin/adminer) and proxy endpoints was observed, with some attackers using IPv4-mapped IPv6 addresses possibly to obfuscate origin. A SmartApeSG campaign used a ClickFix page to distribute the Remcos RAT, and a React-based phishing page was foundex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
eddc187f7d905e0e4ccab6978aabb99c24c5fcfaac05cece58d600dffc856c10
Enrichment time
2026-03-19T13:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th) · Baitaphish