SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91

2026-04-05T20:51:47Zd4312e55b638b7cccff7688132652937cbceeab027fdd808f4252a46eaaf3da5
CVE-2026-3502CrystalX-RATDriftHandalaHasbroMaaSPSK-WindQilin-ransomwareTeamPCPTrueConfWebSocket-implantaxioscloud-breachcryptocurrency-heistknown-exploited-vulnerabilitymacOS-infostealermaldocmalicious-emailmalwarenonce-multisignpmransomwaresupply-chain

What happened

This roundup highlights multiple high-impact incidents and new malware activity: a $285M cryptocurrency heist likely linked to North Korea using nonce/multisig manipulation to drain Drift; a European Commission cloud breach attributed to TeamPCP that exposed data from ~30 EU entities; and CISA adding TrueConf Client flaw CVE-2026-3502 (CVSS 7.8) to its Known Exploited Vulnerabilities catalog. New and evolving malware/malware-as-a-service activity includes CrystalX RAT (Telegram-based MaaS with spyware/stealer/RAT features), Infiniti Stealer targeting macOS, RoadK1ll (WebSocket-based pivoting/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d4312e55b638b7cccff7688132652937cbceeab027fdd808f4252a46eaaf3da5
Enrichment time
2026-04-05T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91 · Baitaphish