St. Patrick's Day Threat Sweep: One Russian IP, Three Supply Chain Attacks, and a Dead Man's Switch
- Patrick Duggan
- Mar 17
- 4 min read
Updated: Aug 11
The Morning Sweep
Every day starts the same: check the feeds, check the headlines, check what broke overnight. St. Patrick's Day 2026 brought gifts.
One Russian IP Owns 83% of an Ivanti Zero-Day
CVE-2026-1281 and CVE-2026-1340. Pre-authentication remote code execution in Ivanti Endpoint Manager Mobile. The kind of vulnerability that makes patch management teams cancel lunch.
GreyNoise, Unit 42, and Rapid7 all published within hours of each other. The interesting part isn't the vulnerability — Ivanti zero-days are a recurring theme at this point. The interesting part is the attribution.
One IP address — 193.24.123.42 — is responsible for 83% of all exploitation.
346 out of 417 observed attack sessions. PROSPERO OOO, AS200593, St. Petersburg. They're installing web shells, cryptominers, and the Nezha monitoring agent. Not subtle. Not trying to be.
The other 17%? Distributed across opportunistic scanners who picked up the exploit after it went public. But PROSPERO had it first. 83% from one IP means they either found it or bought it before anyone else.
That IP is now in our STIX feed.
Three Supply Chain Attacks Walk Into Your CI/CD Pipeline
GlassWorm — 72 VS Code Extensions, 150 GitHub Repos
Aikido and The Hacker News reported GlassWorm this week. The attack uses invisible Unicode characters to encode payloads inside what look like empty strings. 72 malicious Open VSX extensions mimicking linters, formatters, and AI coding assistants. 150+ compromised GitHub repositories. Two npm packages.
You install a linter extension. The extension contains a string that looks empty. The string contains encoded shellcode. Your development environment is now someone else's.
Pattern 38 territory. We've been tracking supply chain attacks through GitHub since December 2025.
Shai-Hulud 2.0 — The Dead Man's Switch
GitLab discovered this one. Multiple infected npm packages with a new feature: if you try to remove the propagation channels, the malware threatens to destroy user data.
Read that again. The malware has a dead man's switch. Cut the supply line and it burns the host. That's not a criminal tool — that's a coercion mechanism. Someone built leverage into malware.
UNC6426 / nx npm — 72 Hours to AWS Admin
A compromised pull_request_target workflow in the nx npm package. The attacker deployed QUIETVAULT — a credential stealer that runs as a postinstall script, harvesting environment variables and tokens. From npm install to AWS administrator access in 72 hours.
The nx package has millions of weekly downloads. One poisoned workflow. Three days to kingdom.
Iran Update: New C2, New Vector
The Handala/Stryker story continues. Krebs, TechCrunch, CNN, and Check Point all published coverage. CISA launched a formal investigation.
New IOC from Unit 42: 107.189.19.52 — RedAlert APK phishing C2, associated with Handala/Void Manticore operations. Also in our feed now.
The interesting development: post-Iran internet shutdown, Iranian threat actors are migrating operations to Starlink IP ranges. Elon's satellite internet is becoming Iranian APT infrastructure. The irony writes itself.
CISA KEV: Wing FTP Server
Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →
CVE-2025-47813 — Wing FTP Server information disclosure. Added to the Known Exploited Vulnerabilities catalog yesterday (March 16). If you're running Wing FTP, patch now. If you're running Wing FTP on the internet, patch yesterday.
Chrome and Apple Zero-Days
CVE-2026-2441 — Chrome use-after-free in CSS component. RCE within sandbox. Patched, but exploited in the wild before the patch dropped.
CVE-2026-20700 — Apple iOS memory corruption in dyld. Pre-iOS 26 devices vulnerable. If your organization hasn't pushed iOS 26, you're exposed.
Both patched. Both were zero-days. Both are the kind of thing your SIEM should flag if it's pulling the right feeds.
The IOCs
All indexed in our STIX feed as of this morning:
Type | Value | Context | |
IP | 193.24.123.42 | PROSPERO OOO, 83% of Ivanti EPMM exploitation | |
IP | 107.189.19.52 | Handala/Iran RedAlert APK C2 | |
CVE | CVE-2026-1281 | Ivanti EPMM pre-auth RCE | |
CVE | CVE-2026-1340 | Ivanti EPMM pre-auth RCE | |
CVE | CVE-2026-2441 | Chrome use-after-free zero-day | |
CVE | CVE-2026-20700 | Apple iOS dyld memory corruption | |
CVE | CVE-2025-47813 | Wing FTP Server (CISA KEV Mar 16) | |
Pattern | `/mifs/c/(aft | app)store/fob/` | Ivanti EPMM exploitation log indicator |
File | /mifs/403.jsp | Web shell indicator on Ivanti EPMM |
Pull the feed: analytics.dugganusa.com/stix/pricing
What This Means
One Russian IP exploiting Ivanti. Three supply chain attacks in npm and VS Code. Iran pivoting to Starlink. A dead man's switch in malware.
This is a Monday.
If your SIEM isn't pulling threat feeds, you're reading about these on Tuesday. Your SIEM can block them on Monday.
Five minutes: dugganusa.com/post/your-siem-can-block-iranian-wipers-in-5-minutes-here-s-how-
Sláinte. Stay patched.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.
The cheapest, fastest, most accurate threat feed on the internet.
275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=st-patrick-s-day-threat-sweep-one-russian-ip-three-supply-chain-attacks-and-a-dead-man-s-switch




Comments