# Daily Intelligence Briefing — Thursday, March 12, 2026

> On 2026-03-12, Threadlinqs published 7 new threat reports and updated 40, 25 rated critical and 22 high, spanning 214 MITRE ATT&CK techniques and 26 named threat actors. Coverage that day added 423 new detection rules and 1255 extracted indicators.

- **Edition:** 2026-03-12 (Thursday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-03-12
- **Last updated:** 2026-03-12
- **New threats:** 7 (40 updated)
- **Critical / high:** 25 critical, 22 high, 0 medium, 0 low
- **ATT&CK techniques:** 214
- **Threat actors:** 26
- **Indicators (count only):** 1255
- **New detection rules (count only):** 423

## Summary & highlights

CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication. Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign). Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft.

- [TL-2026-0216](https://intel.threadlinqs.com/threat/TL-2026-0216) — CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication
- [TL-2026-0217](https://intel.threadlinqs.com/threat/TL-2026-0217) — Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)
- [TL-2026-0218](https://intel.threadlinqs.com/threat/TL-2026-0218) — Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft
- [TL-2026-0219](https://intel.threadlinqs.com/threat/TL-2026-0219) — Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)
- [TL-2026-0214](https://intel.threadlinqs.com/threat/TL-2026-0214) — Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)

## Theme of the day

Iranian MOIS operations led the day as Void Manticore and MuddyWater ran wiper and cybercrime campaigns, joined by Lotus Blossom's Notepad++ supply-chain compromise, Mustang Panda PlugX, malicious Packagist packages, and Storm-2561 SEO poisoning.

data-exfiltration, credential-theft, lateral-movement, espionage, active-exploitation

## Threats published

- [TL-2026-0214](https://intel.threadlinqs.com/threat/TL-2026-0214) — CRITICAL — Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)
- [TL-2026-0215](https://intel.threadlinqs.com/threat/TL-2026-0215) — CRITICAL — Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
- [TL-2026-0220](https://intel.threadlinqs.com/threat/TL-2026-0220) — CRITICAL — Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack
- [TL-2026-0174](https://intel.threadlinqs.com/threat/TL-2026-0174) — CRITICAL — Coruna iOS Exploit Kit — Government-Grade 23-Exploit Arsenal Proliferates from Surveillance Vendor to Russian Espionage and Chinese Cybercriminals Targeting 42K+ Devices (update)
- [TL-2026-0175](https://intel.threadlinqs.com/threat/TL-2026-0175) — CRITICAL — Microsoft MSHTML Remote Code Execution Zero-Day (CVE-2026-21513) (update)
- [TL-2026-0176](https://intel.threadlinqs.com/threat/TL-2026-0176) — CRITICAL — Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors (update)
- [TL-2026-0177](https://intel.threadlinqs.com/threat/TL-2026-0177) — CRITICAL — Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112) (update)
- [TL-2026-0178](https://intel.threadlinqs.com/threat/TL-2026-0178) — CRITICAL — VMware Aria Operations Unauthenticated Command Injection RCE (CVE-2026-22719) (update)
- [TL-2026-0179](https://intel.threadlinqs.com/threat/TL-2026-0179) — CRITICAL — Qualcomm Adreno GPU KGSL Integer Overflow Memory Corruption Zero-Day (CVE-2026-21385) (update)
- [TL-2026-0181](https://intel.threadlinqs.com/threat/TL-2026-0181) — CRITICAL — CISA KEV: Hikvision Camera Auth Bypass (CVE-2017-7921) & Rockwell Logix Credential Exposure (CVE-2021-22681) — Active Exploitation (update)
- [TL-2026-0183](https://intel.threadlinqs.com/threat/TL-2026-0183) — CRITICAL — Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026) (update)
- [TL-2026-0185](https://intel.threadlinqs.com/threat/TL-2026-0185) — CRITICAL — Cisco Catalyst SD-WAN Manager Active Exploitation — Arbitrary File Overwrite and Credential Exposure (CVE-2026-20122, CVE-2026-20128) (update)
- [TL-2026-0186](https://intel.threadlinqs.com/threat/TL-2026-0186) — CRITICAL — Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) (update)
- [TL-2026-0193](https://intel.threadlinqs.com/threat/TL-2026-0193) — CRITICAL — BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection (CVE-2026-1731) (update)
- [TL-2026-0194](https://intel.threadlinqs.com/threat/TL-2026-0194) — CRITICAL — Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769) (update)
- [TL-2026-0195](https://intel.threadlinqs.com/threat/TL-2026-0195) — CRITICAL — UNC2814 GRIDTIDE Backdoor — China-Nexus Telecom & Government Espionage Campaign Exploiting Google Sheets API for C2 (update)
- [TL-2026-0198](https://intel.threadlinqs.com/threat/TL-2026-0198) — CRITICAL — Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure (update)
- [TL-2026-0199](https://intel.threadlinqs.com/threat/TL-2026-0199) — CRITICAL — INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory) (update)
- [TL-2026-0200](https://intel.threadlinqs.com/threat/TL-2026-0200) — CRITICAL — Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603) (update)
- [TL-2026-0201](https://intel.threadlinqs.com/threat/TL-2026-0201) — CRITICAL — Omnissa Workspace ONE UEM Pre-Auth SSRF Active Exploitation (CVE-2021-22054) (update)
- [TL-2026-0202](https://intel.threadlinqs.com/threat/TL-2026-0202) — CRITICAL — UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise (update)
- [TL-2026-0205](https://intel.threadlinqs.com/threat/TL-2026-0205) — CRITICAL — FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) (update)
- [TL-2026-0209](https://intel.threadlinqs.com/threat/TL-2026-0209) — CRITICAL — Microsoft Office Preview Pane Remote Code Execution — CVE-2026-26110 (Type Confusion) & CVE-2026-26113 (Untrusted Pointer Dereference) (update)
- [TL-2026-0210](https://intel.threadlinqs.com/threat/TL-2026-0210) — CRITICAL — GIBCRYPTO Destructive Ransomware with Snake Keylogger Shared Telegram C2 Infrastructure (update)
- [TL-2026-0211](https://intel.threadlinqs.com/threat/TL-2026-0211) — CRITICAL — Microsoft Office RCE via Preview Pane (CVE-2026-26110, CVE-2026-26113) — March 2026 Patch Tuesday (update)
- [TL-2026-0216](https://intel.threadlinqs.com/threat/TL-2026-0216) — HIGH — CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication
- [TL-2026-0217](https://intel.threadlinqs.com/threat/TL-2026-0217) — HIGH — Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)
- [TL-2026-0218](https://intel.threadlinqs.com/threat/TL-2026-0218) — HIGH — Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft
- [TL-2026-0219](https://intel.threadlinqs.com/threat/TL-2026-0219) — HIGH — Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)
- [TL-2026-0180](https://intel.threadlinqs.com/threat/TL-2026-0180) — HIGH — XWorm v6.4 Delivery Campaign — Obfuscated JavaScript/PowerShell Loaders with ProcessHollowing DLL Injection (March 2026) (update)
- [TL-2026-0182](https://intel.threadlinqs.com/threat/TL-2026-0182) — HIGH — Fake OpenClaw Installers Distributed via Bing Search Poisoning and Malicious GitHub Repos Deploy Infostealers and GhostSocks Proxy Malware (update)
- [TL-2026-0184](https://intel.threadlinqs.com/threat/TL-2026-0184) — HIGH — Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes (update)
- [TL-2026-0187](https://intel.threadlinqs.com/threat/TL-2026-0187) — HIGH — CL-UNK-1068: China-Nexus APT Targeting Critical Infrastructure via DLL Sideloading, Xnote Backdoor, ScanPortPlus Scanner, and FRP Tunneling (update)
- [TL-2026-0188](https://intel.threadlinqs.com/threat/TL-2026-0188) — HIGH — APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure (update)
- [TL-2026-0189](https://intel.threadlinqs.com/threat/TL-2026-0189) — HIGH — Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels (update)
- [TL-2026-0190](https://intel.threadlinqs.com/threat/TL-2026-0190) — HIGH — Fake Laravel Packages on Packagist Deploy Cross-Platform RAT via Supply Chain Compromise (update)
- [TL-2026-0191](https://intel.threadlinqs.com/threat/TL-2026-0191) — HIGH — UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom (update)
- [TL-2026-0192](https://intel.threadlinqs.com/threat/TL-2026-0192) — HIGH — Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users (update)
- [TL-2026-0196](https://intel.threadlinqs.com/threat/TL-2026-0196) — HIGH — VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python Runtime (update)
- [TL-2026-0197](https://intel.threadlinqs.com/threat/TL-2026-0197) — HIGH — HoneyMyte (Mustang Panda) CoolClient Backdoor Update with Browser Data Stealers Targeting Southeast Asian Government and Military (update)
- [TL-2026-0203](https://intel.threadlinqs.com/threat/TL-2026-0203) — HIGH — Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less) (update)
- [TL-2026-0204](https://intel.threadlinqs.com/threat/TL-2026-0204) — HIGH — APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509) (update)
- [TL-2026-0206](https://intel.threadlinqs.com/threat/TL-2026-0206) — HIGH — KadNap P2P Botnet — 14,000+ Asus Routers Compromised via Custom Kademlia DHT C2 (update)
- [TL-2026-0207](https://intel.threadlinqs.com/threat/TL-2026-0207) — HIGH — BoryptGrab GitHub Supply Chain Malware Campaign — 100+ Malicious Repositories Distributing Multi-Stage Stealer (update)
- [TL-2026-0208](https://intel.threadlinqs.com/threat/TL-2026-0208) — HIGH — KongTuke ClickFix Campaign — ModeloRAT Deployment via Compromised WordPress Sites and CrashFix Browser Extension (update)
- [TL-2026-0212](https://intel.threadlinqs.com/threat/TL-2026-0212) — HIGH — KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for Doppelganger Proxy Network (update)
- [TL-2026-0213](https://intel.threadlinqs.com/threat/TL-2026-0213) — HIGH — Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews (update)

## Techniques observed

[T0831](https://intel.threadlinqs.com/technique/T0831), T0875, T0879, T0889, [T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.004](https://intel.threadlinqs.com/technique/T1055.004), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1072](https://intel.threadlinqs.com/technique/T1072), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1406](https://intel.threadlinqs.com/technique/T1406), [T1407](https://intel.threadlinqs.com/technique/T1407), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1437](https://intel.threadlinqs.com/technique/T1437), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1553.006](https://intel.threadlinqs.com/technique/T1553.006), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1561](https://intel.threadlinqs.com/technique/T1561), T1561.002, T1562, T1562.001, T1562.002, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1599](https://intel.threadlinqs.com/technique/T1599), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1630](https://intel.threadlinqs.com/technique/T1630), T1632, [T1636](https://intel.threadlinqs.com/technique/T1636), [T1646](https://intel.threadlinqs.com/technique/T1646), [T1655](https://intel.threadlinqs.com/technique/T1655), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660)

## Threat actors

nhattuanbl, [Storm-2561](https://intel.threadlinqs.com/actor/Storm-2561), Mustang Panda (medium confidence), Lotus Blossom / Spring Dragon, Void Manticore / MuddyWater (MOIS), Handala Hack / Void Manticore, Mustang Panda / Earth Preta, [CL-UNK-1068](https://intel.threadlinqs.com/actor/CL-UNK-1068), APT28 / Fancy Bear, APT36 / Transparent Tribe, UAT-9244 / FamousSparrow, Arid Viper / APT-C-23, HoneyMyte / Mustang Panda, APT28 / Fancy Bear / Sednit, KongTuke / TAG-124, Famous Chollima / Tenacious Pungsan / DEV#POPPER, APT29 / Midnight Blizzard (IRON TWILIGHT cluster), Seedworm / MuddyWater, Saito Tech (Candiru), CyberAv3ngers / APT33 / MuddyWater / APT34 / Handala Hack Team / APT35, UNC6353 / UNC6691, [UNC6201](https://intel.threadlinqs.com/actor/UNC6201), UNC2814 / Gallium, MuddyWater / Seedworm, INC Ransom / GOLD IONIC, UNC4899 / Jade Sleet

Nation-state attribution: China, Iran, Russia, Pakistan, Palestine, North Korea, Israel, Russia / China

Threat categories: VULNERABILITY, SUPPLY_CHAIN, MALWARE, APT, ZERO_DAY, ICS_SCADA, RANSOMWARE

## Severity breakdown

- critical: 25
- high: 22
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1255 (file 416, network 364, behavioral 235, malware 93, infrastructure 67, tool 48, entity 13, package 11, technique 8)
- New detection rules: 423 (100% of the day’s threats covered)

## More editions

- Previous: [2026-02-16](https://intel.threadlinqs.com/debrief/2026-02-16)
- Next: [2026-05-22](https://intel.threadlinqs.com/debrief/2026-05-22)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-03-12
