```html ```
top of page

St. Patrick's Day Threat Sweep: One Russian IP, Three Supply Chain Attacks, and a Dead Man's Switch

  • Writer: Patrick Duggan
    Patrick Duggan
  • Mar 17
  • 4 min read

Updated: Aug 11


The Morning Sweep


Every day starts the same: check the feeds, check the headlines, check what broke overnight. St. Patrick's Day 2026 brought gifts.





One Russian IP Owns 83% of an Ivanti Zero-Day


CVE-2026-1281 and CVE-2026-1340. Pre-authentication remote code execution in Ivanti Endpoint Manager Mobile. The kind of vulnerability that makes patch management teams cancel lunch.


GreyNoise, Unit 42, and Rapid7 all published within hours of each other. The interesting part isn't the vulnerability — Ivanti zero-days are a recurring theme at this point. The interesting part is the attribution.


One IP address — 193.24.123.42 — is responsible for 83% of all exploitation.


346 out of 417 observed attack sessions. PROSPERO OOO, AS200593, St. Petersburg. They're installing web shells, cryptominers, and the Nezha monitoring agent. Not subtle. Not trying to be.


The other 17%? Distributed across opportunistic scanners who picked up the exploit after it went public. But PROSPERO had it first. 83% from one IP means they either found it or bought it before anyone else.


That IP is now in our STIX feed.





Three Supply Chain Attacks Walk Into Your CI/CD Pipeline



GlassWorm — 72 VS Code Extensions, 150 GitHub Repos


Aikido and The Hacker News reported GlassWorm this week. The attack uses invisible Unicode characters to encode payloads inside what look like empty strings. 72 malicious Open VSX extensions mimicking linters, formatters, and AI coding assistants. 150+ compromised GitHub repositories. Two npm packages.


You install a linter extension. The extension contains a string that looks empty. The string contains encoded shellcode. Your development environment is now someone else's.


Pattern 38 territory. We've been tracking supply chain attacks through GitHub since December 2025.



Shai-Hulud 2.0 — The Dead Man's Switch


GitLab discovered this one. Multiple infected npm packages with a new feature: if you try to remove the propagation channels, the malware threatens to destroy user data.


Read that again. The malware has a dead man's switch. Cut the supply line and it burns the host. That's not a criminal tool — that's a coercion mechanism. Someone built leverage into malware.



UNC6426 / nx npm — 72 Hours to AWS Admin


A compromised pull_request_target workflow in the nx npm package. The attacker deployed QUIETVAULT — a credential stealer that runs as a postinstall script, harvesting environment variables and tokens. From npm install to AWS administrator access in 72 hours.


The nx package has millions of weekly downloads. One poisoned workflow. Three days to kingdom.





Iran Update: New C2, New Vector


The Handala/Stryker story continues. Krebs, TechCrunch, CNN, and Check Point all published coverage. CISA launched a formal investigation.


New IOC from Unit 42: 107.189.19.52 — RedAlert APK phishing C2, associated with Handala/Void Manticore operations. Also in our feed now.


The interesting development: post-Iran internet shutdown, Iranian threat actors are migrating operations to Starlink IP ranges. Elon's satellite internet is becoming Iranian APT infrastructure. The irony writes itself.





CISA KEV: Wing FTP Server


Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →


CVE-2025-47813 — Wing FTP Server information disclosure. Added to the Known Exploited Vulnerabilities catalog yesterday (March 16). If you're running Wing FTP, patch now. If you're running Wing FTP on the internet, patch yesterday.





Chrome and Apple Zero-Days


CVE-2026-2441 — Chrome use-after-free in CSS component. RCE within sandbox. Patched, but exploited in the wild before the patch dropped.


CVE-2026-20700 — Apple iOS memory corruption in dyld. Pre-iOS 26 devices vulnerable. If your organization hasn't pushed iOS 26, you're exposed.


Both patched. Both were zero-days. Both are the kind of thing your SIEM should flag if it's pulling the right feeds.





The IOCs


All indexed in our STIX feed as of this morning:



Type

Value

Context

IP

193.24.123.42

PROSPERO OOO, 83% of Ivanti EPMM exploitation

IP

107.189.19.52

Handala/Iran RedAlert APK C2

CVE

CVE-2026-1281

Ivanti EPMM pre-auth RCE

CVE

CVE-2026-1340

Ivanti EPMM pre-auth RCE

CVE

CVE-2026-2441

Chrome use-after-free zero-day

CVE

CVE-2026-20700

Apple iOS dyld memory corruption

CVE

CVE-2025-47813

Wing FTP Server (CISA KEV Mar 16)

Pattern

`/mifs/c/(aft

app)store/fob/`

Ivanti EPMM exploitation log indicator

File

/mifs/403.jsp

Web shell indicator on Ivanti EPMM


Pull the feed: analytics.dugganusa.com/stix/pricing





What This Means


One Russian IP exploiting Ivanti. Three supply chain attacks in npm and VS Code. Iran pivoting to Starlink. A dead man's switch in malware.


This is a Monday.


If your SIEM isn't pulling threat feeds, you're reading about these on Tuesday. Your SIEM can block them on Monday.


Five minutes: dugganusa.com/post/your-siem-can-block-iranian-wipers-in-5-minutes-here-s-how-




Sláinte. Stay patched.




Her name was Renee Nicole Good.


His name was Alex Jeffery Pretti.



The cheapest, fastest, most accurate threat feed on the internet.

275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.


Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=st-patrick-s-day-threat-sweep-one-russian-ip-three-supply-chain-attacks-and-a-dead-man-s-switch



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page