Daily Drop (1284)
04-26-26
Sunday, Apr 26, 2026 // (IG): BB // Ghostwire
China-Backed Hackers Are Industrializing Botnets
Bottom Line Up Front (BLUF): CISA, NCSC-UK, NSA, FBI, and international partners warn that China-nexus cyber actors are increasingly using large-scale covert networks of compromised devices to hide and route cyber operations. These networks are built mostly from compromised SOHO routers, IoT devices, smart devices, firewalls, cameras, video recorders, and NAS appliances, giving Chinese state-backed operators a low-cost, deniable way to conduct reconnaissance, deliver malware, maintain command-and-control, and exfiltrate data.
Analyst Comments: The advisory says China-nexus actors have shifted away from individually procured infrastructure and toward externally provisioned covert networks made up of compromised devices. NCSC assesses that the majority of China-nexus threat actors are using these networks, and that multiple actors may use the same covert network. Volt Typhoon has used covert infrastructure to pre-position offensive capabilities on critical national infrastructure, while Flax Typhoon used a separate network for cyber espionage. CISA and partner agencies highlighted Raptor Train, a covert network that infected more than 200,000 devices worldwide in 2024 and was controlled by Chinese company Integrity Technology Group. The FBI also assessed Integrity Technology Group as responsible for intrusion activity attributed to Flax Typhoon. The advisory also notes the KV Botnet used by Volt Typhoon, largely made up of vulnerable Cisco and NetGear routers, especially end-of-life devices no longer receiving security patches.
READ THE STORY: CISA
Harvester APT Hides Linux GoGra Backdoor Traffic Inside Outlook Mailboxes
Bottom Line Up Front (BLUF): The nation-state-linked Harvester APT has developed a Linux variant of its GoGra backdoor that abuses Microsoft Graph API and real Outlook mailboxes for command-and-control. The campaign appears focused on espionage in South Asia, with VirusTotal submissions tied to India and Afghanistan and decoy documents tailored to regional targets.
Analyst Comments: This is another reminder that “trusted cloud traffic” is now attacker infrastructure. Harvester is not trying to hide behind some sketchy C2 domain; it is blending into Microsoft 365 workflows that many organizations already allow by default. That makes perimeter detection weak unless defenders are watching identity, OAuth activity, mailbox behavior, and endpoint execution together. The Linux angle matters too. A lot of enterprise monitoring is still Windows-heavy, while Linux endpoints and servers often get lighter EDR coverage. Security teams should treat unusual Microsoft Graph API calls from Linux systems, unexpected systemd user services, and decoy “PDF” files that are actually ELF binaries as serious hunting leads.
READ THE STORY: CSN
FIRESTARTER Malware Can Persist on Patched Cisco Firewall Devices
Bottom Line Up Front (BLUF): CISA published a malware analysis report on FIRESTARTER, malware affecting Cisco Firepower and Secure Firewall products running Adaptive Security Appliance or Firepower Threat Defense software. The report says an advanced persistent threat actor exploited CVE-2025-20333 and CVE-2025-20362 in Cisco ASA firmware to gain access and deploy the malware, with CISA warning that patching compromised firmware may not remove an existing actor.
Analyst Comments: The key issue here is persistence. FIRESTARTER is not just a patch-and-move-on problem if the device was already compromised. Edge security appliances are high-value targets because they sit at the boundary of the network, often have privileged visibility, and are harder to monitor than standard endpoints. For defenders, the priority is forensic validation before assuming remediation worked. Affected organizations should identify exposed Cisco Firepower and Secure Firewall devices, collect forensic data, apply vendor updates, and hunt for signs of post-patching persistence. Federal agencies have mandatory steps under the updated emergency directive, but private-sector organizations running the same products should treat the guidance as operationally relevant.
READ THE STORY: CISA
GopherWhisper APT Abuses Cloud Tools to Spy on Mongolian Government
Bottom Line Up Front (BLUF): A newly disclosed China-aligned APT, tracked as GopherWhisper, has been targeting Mongolian government systems since at least November 2023. ESET researchers found the group backdoored 12 systems inside one Mongolian government institution, with evidence suggesting additional victims. The actor relies on multiple custom backdoors that abuse legitimate cloud services, including Slack, Discord, Microsoft Outlook, and file.io, for command-and-control and exfiltration.
Analyst Comments: This newly minted APT “GopherWhisper” uses a cluster of custom tools, including LaxGopher, JabGopher, CompactGopher, RatGopher, BoxOfFriends, FriendDelivery, and SSLORDoor. Each tool supports the operation in different ways, with LaxGopher abusing Slack, RatGopher using Discord, BoxOfFriends communicating through Microsoft Outlook email drafts, and CompactGopher handling file exfiltration through file.io. Researchers noted that while the group is productive, its tooling suggests the operators may be relatively new to malware development.
READ THE STORY: Security Week // DR
Russia-Linked Actor Highly Likely involved in Signal Phishing Campaign Targeting German Politicians
Bottom Line Up Front (BLUF): German and foreign security services warned that lawmakers and senior officials are being targeted through phishing messages on Signal, with the German government reportedly assessing the campaign was likely run from Russia. Victims are tricked into entering a PIN, opening a link, or scanning a QR code, potentially giving attackers access to messages, chat groups, photos, files, and the ability to impersonate compromised users.
Analyst Comments: Signal is widely treated as a safer communications channel, so users may lower their guard when a message appears to come from “support” or from a known contact. Once an account is compromised, the attacker does not just get data—they get credibility inside political, diplomatic, and media networks. The defensive lesson is straightforward: encrypted messaging does not fix identity compromise. High-risk users need phishing-resistant account recovery, strict device-linking controls, rapid revocation procedures, and training that treats QR-code and PIN requests as red flags. The desktop client question also matters because linked devices can become a weak point on managed government systems.
READ THE STORY: EURO NEWS
Pre-Stuxnet ‘fast16’ Malware Rewrites Cyber Sabotage Timeline
Bottom Line Up Front (BLUF): Fast16, a Lua-based malware framework dating back to 2005 that appears designed for cyber sabotage against engineering and simulation software. SentinelOne assesses the malware predates Stuxnet by roughly five years and targeted high-precision calculation tools to quietly alter results, potentially corrupting scientific, civil engineering, physics, or physical process simulations.
Analyst Comments: This is a big historical find, not just another old malware sample. Fast16 suggests advanced operators were already building modular cyber-sabotage frameworks aimed at physical-world effects years before Stuxnet became the public reference point for digital weapons. The most concerning part is the target logic: not crashing systems, not wiping files, but subtly manipulating calculations. That kind of attack is harder to notice and potentially more damaging over time. If the output of trusted engineering software becomes unreliable, defenders may not see “malware” first—they may see failed models, bad research, flawed designs, or unexplained degradation.
READ THE STORY: THN
OpenAI Apologizes for Not Alerting Police About ChatGPT Account Tied to Canadian Mass Shooting Suspect
Bottom Line Up Front (BLUF): Sam Altman apologized to the community of Tumbler Ridge, British Columbia, saying the company was “deeply sorry” it did not alert law enforcement after banning a ChatGPT account later linked to accused mass shooter Jesse Van Rootselaar. OpenAI reportedly said the account had been banned for problematic use but did not meet the company’s threshold for referral to police because it lacked a credible or imminent plan for serious physical harm.
Analyst Comments: This story sits at the intersection of AI safety, platform trust, and public-safety reporting thresholds. The hard question is not whether companies should report every disturbing interaction—they cannot responsibly do that at scale without creating major privacy and false-positive problems. The harder question is where the line sits when violent ideation, planning behavior, or target-specific content appears in AI system logs.
READ THE STORY: BBC
Cyber Experts Plead Guilty in BlackCat-Linked Ransomware Insider Scheme
Bottom Line Up Front (BLUF): Former ransomware negotiator Angelo Martino pleaded guilty after prosecutors said he abused his role at DigitalMint to help a cybercriminal gang maximize ransom payments from U.S. victims. Prosecutors allege Martino shared confidential client negotiation details, including payment strategy, while he and co-defendants Kevin Tyler Martin and Ryan Clifford Goldberg were accused of participating in ransomware activity against victim organizations.
Analyst Comments: This is an ugly insider-risk case for the ransomware response industry. Victims hire negotiators because they are under pressure, short on options, and need someone who understands the criminal ecosystem. When that trusted intermediary feeds strategy back to the attacker, the victim is not just compromised technically—they are compromised operationally. The bigger lesson is incentive control. Any firm handling ransom negotiations needs strict separation of duties, audit trails, peer review, conflict checks, and visibility into employee communications around active cases. Paying ransoms is already messy. Letting a negotiator operate as a black box makes it worse.
READ THE STORY: AOL
Cyberattack Pressure Eases Across African Organizations, but Regional Risk Remains High
Bottom Line Up Front (BLUF): African organizations are reportedly seeing a decline in cyberattack pressure, according to Dark Reading. The shift suggests some easing after sustained targeting across the region, though reduced activity should not be mistaken for reduced risk.
Analyst Comments: A slowdown in observed attacks is good news, but defenders should treat it as breathing room, not a trend they can bank on. African organizations remain attractive targets because many sectors are still expanding digital services, cloud adoption, and mobile-first infrastructure faster than security programs can mature. Threat actors may also be shifting tactics, changing targeting patterns, or pausing between campaigns rather than walking away.
READ THE STORY: DR
DARPA Pushes Deep-Ocean Drone Program as Autonomous Warfare Spending Surges
Bottom Line Up Front (BLUF): DARPA is seeking proposals for Deep Thoughts, a program to build compact autonomous undersea vehicles that can reach full-ocean depths faster, smaller, and cheaper than current deep-ocean AUV systems. The effort is framed around “responsive and scalable access” to the deep ocean, giving the program clear strategic and military relevance rather than purely scientific ambition.
Analyst Comments: This is the undersea version of the drone race. The Pentagon is trying to compress development timelines from years to months or weeks, which tells you where autonomous systems are headed: cheaper, faster, more distributed, and deployable across air, land, sea, and undersea domains. The security angle is not just about submarines. AUVs touch maritime surveillance, seabed infrastructure, cable security, mine warfare, intelligence collection, and contested logistics. As NATO and adversaries focus harder on undersea cables and maritime chokepoints, low-cost autonomous systems become a strategic force multiplier. The risk is that procurement moves faster than doctrine, testing, cyber assurance, and command-and-control safeguards.
READ THE STORY: The Register
Russia-Linked Actor Highly Likely involved in Signal Phishing Campaign Targeting German Politicians
Bottom Line Up Front (BLUF): German and foreign security services warned that lawmakers and senior officials are being targeted through phishing messages on Signal, with the German government reportedly assessing the campaign was likely run from Russia. Victims are tricked into entering a PIN, opening a link, or scanning a QR code, potentially giving attackers access to messages, chat groups, photos, files, and the ability to impersonate compromised users.
Analyst Comments: Signal is widely treated as a safer communications channel, so users may lower their guard when a message appears to come from “support” or from a known contact. Once an account is compromised, the attacker does not just get data—they get credibility inside political, diplomatic, and media networks. The defensive lesson is straightforward: encrypted messaging does not fix identity compromise. High-risk users need phishing-resistant account recovery, strict device-linking controls, rapid revocation procedures, and training that treats QR-code and PIN requests as red flags. The desktop client question also matters because linked devices can become a weak point on managed government systems.
READ THE STORY: EURO NEWS
Microsoft Taps Anthropic’s Mythos to Push AI Deeper Into Secure Software Development
Bottom Line Up Front (BLUF): Anthropic’s Mythos AI model into its Secure Development Lifecycle (SDL) to strengthen early-stage secure coding and vulnerability detection. The move signals that frontier AI models are moving from experimental security research into core software engineering workflows used by major technology vendors.
Analyst Comments: Static scanners and traditional code review are not going away, but frontier models like Mythos are starting to operate closer to the developer workflow, where vulnerabilities are introduced in the first place. That matters because the security bottleneck has never just been finding bugs—it is finding them early enough, with enough context, to fix them before they become production risk. There is a catch. The same model class that helps defenders find exploitable flaws faster can also shorten the window for attackers to move from bug discovery to exploit development. Security teams should expect AI-assisted vulnerability research to become normal on both sides. The practical takeaway: organizations need stronger secure coding pipelines, faster triage, and human review for novel vulnerabilities that models may miss or misclassify.
READ THE STORY: Freebuf
Items of interest
FCC Adds More Chinese Tech Firms to National Security Risk List
Bottom Line Up Front (BLUF): The FCC has reportedly added more China-linked technology companies to its national security risk list, expanding U.S. scrutiny of foreign telecom and technology suppliers. The move signals continued pressure on Chinese vendors tied to communications infrastructure, surveillance technology, and potential state influence.
Analyst Comments: This is less about one product and more about supply-chain exposure. Once a company lands on the FCC’s covered list, U.S. organizations should treat that vendor as high-risk for procurement, compliance, and infrastructure planning. For telecoms, MSPs, critical infrastructure operators, and government contractors, the practical question is simple: do we have any of this equipment, software, or services in the environment? The bigger trend is clear. Washington is continuing to narrow the space for Chinese technology inside U.S. networks, especially where vendors touch communications, routing, surveillance, or sensitive data flows. Security teams should expect more vendor reviews, more procurement restrictions, and more pressure to prove where hardware and software originate.
READ THE STORY: The Register
FCC move: Could Chinese labs be banned from testing US electronics? (Video)
FROM THE MEDIA: The Federal Communications Commission is taking significant steps to address national security concerns regarding electronic device testing. With a scheduled vote on April 30th, the agency plans to propose a total ban on Chinese labs testing electronics meant for the U.S. market.
Rep. Mast: Why are these allies selling crucial technology to China? (Video)
FROM THE MEDIA: If U.S. companies won’t sell out to China, we should expect our closest allies’ companies like Dutch chip equipment manufacturer, ASML, to follow our lead. That’s what true partnership means.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


