SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91
2026-04-05T20:51:47Z•d4312e55b638b7cccff7688132652937cbceeab027fdd808f4252a46eaaf3da5
CVE-2026-3502CrystalX-RATDriftHandalaHasbroMaaSPSK-WindQilin-ransomwareTeamPCPTrueConfWebSocket-implantaxioscloud-breachcryptocurrency-heistknown-exploited-vulnerabilitymacOS-infostealermaldocmalicious-emailmalwarenonce-multisignpmransomwaresupply-chain
What happened
This roundup highlights multiple high-impact incidents and new malware activity: a $285M cryptocurrency heist likely linked to North Korea using nonce/multisig manipulation to drain Drift; a European Commission cloud breach attributed to TeamPCP that exposed data from ~30 EU entities; and CISA adding TrueConf Client flaw CVE-2026-3502 (CVSS 7.8) to its Known Exploited Vulnerabilities catalog. New and evolving malware/malware-as-a-service activity includes CrystalX RAT (Telegram-based MaaS with spyware/stealer/RAT features), Infiniti Stealer targeting macOS, RoadK1ll (WebSocket-based pivoting/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d4312e55b638b7cccff7688132652937cbceeab027fdd808f4252a46eaaf3da5
- Enrichment time
- 2026-04-05T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.