Fourteen Newsletters and Fifteen Winters

Published on: 
March 5, 2026

Greetings from Seattle, where “second false spring: has just arrived. It’s a thing, Google it!  Returning readers will no doubt recognize that I’m a bit obsessed with the weather here. Even after thirty years in the Emerald City, and my induction as an honorary mossback, the weather and its 12-14 micro-seasons are frequently top of mind. During my first year as an undergrad at the University of Washington, I thought about becoming a meteorologist. I took several atmospheric sciences classes, but then the advanced math got me. Instead I got a degree more suited to my natural talents: Communications 😉 

I teased this possibility last month, but now it’s official: The publication of this monthly newsletter has moved to the first Tuesday of the next month, as opposed to the last Tuesday of the month that the newsletter covers. We changed a few things up internally, and for practical reasons, this change is becoming permanent. The use of adapted song titles for each new edition is sticking around, though it might get harder if I keep up sequential numbering. I’d normally ask you to comment on this post if you recognized the song this one is based on, but GenAI kind of takes the fun out of it - Gemini for example got it on the first try 🙄

While February was a short month, the threat landscape was anything but quiet and my team was anything but bored. This edition of my newsletter focuses on a recurring phenomenon we observe in actor tradecraft: The weaponization of trust. Our headliner is a deep dive into Lotus Blossom (G0030) and their sophisticated supply chain attack targeting Notepad++. This wasn't a loud, "smash and grab" operation; it was a surgical infiltration of an update pipeline designed to stay under the radar of even the most diligent admins.

We’re also looking at the "human" side of the house with a new Security Snack on Idolized Crypto Scams. My team traced over 250 domains back to a single infrastructure cluster that uses celebrity personas and fraudulent presales to siphon assets across multiple blockchains.

We closed out February with my talk at BSides Seattle, where I spoke about my team’s research on new domains delivering SpyNote Malware, which we covered extensively last year. If you weren’t able to catch me live, my team and I will be at BSides San Francisco near the end of March, where we have two presentations on the schedule - come find us and say hi! I will be in town for RSAC as well, and would be happy to host you in our space near Moscone.

Now, without further ado, from supply chain evolution to high-velocity fraud, we’ve got plenty to get you up to speed. Let’s dive in!

Hot off the Presses

Lotus Blossom (G0030) and the NotePad++ Supply Chain Espionage Campaign

DTI researchers analyzed the sustained compromise of the Notepad++ update pipeline from late 2025 into early 2026. Rather than modifying the open-source codebase, attackers infiltrated upstream distribution infrastructure and selectively redirected update traffic for a small group of targets. This allowed them to deliver customized installers and low-noise implants to be delivered while most users continued receiving legitimate updates.Taken together, the operational choices, tooling, and victim profile support attribution, with moderate to high confidence, to the China-aligned espionage actor commonly tracked as Lotus Blossom (G0030) in concurrence with other organizations assessment. 

The Notepad++ compromise represents a clear evolution in Lotus Blossom’s tradecraft. Earlier campaigns relied heavily on spear-phishing and bespoke backdoors delivered directly to victims. Rather than compromising end-user systems through conventional infrastructure attacks, such as opportunistic abuse of widely trusted software updates, the actors shifted the locus of trust toward the developer ecosystem itself. By abusing a legitimate update mechanism relied upon specifically by developers and administrators, they transformed routine maintenance into a covert entry point for high-value access.The incident highlights how trusted software update systems can be quietly weaponized for long-term intelligence collection without causing widespread disruption.

🔍Read the full investigation here

SecuritySnack: Idolized Crypto Scams

A cryptocurrency scam operation spanning roughly 250 domains was identified across multiple themes, including fake celebrity giveaways and fraudulent token presales. The investigation began with a cluster of suspected scam domains sharing the same Google analytics tag ID and expanded through blockchain tracing, wallet analysis, and domain registration overlaps. This process revealed activity across BTC, ETH, and XRP and included impersonation of public figures, platforms, and crypto projects.

On-chain findings were mixed but revealed a well-developed supporting infrastructure. In several cases, blockchain tracing showed actor-controlled wallets funding themselves and cycling assets through multi-layer laundering pipelines. The broader infrastructure includes cross-chain scam tooling, distributed hosting across multiple jurisdictions, and hundreds of related domains. Evidence from shared wallets, infrastructure overlaps, and Russian-language artifacts indicates a single actor likely responsible for both campaigns. 

🔗Read more here

What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list will get you up to speed! 

📚Check out the full reading list here

Where We’ll Be 

- NICAR 2026, Indianapolis, IN - 04-06 March 

- BSides San Francisco, San Francisco, CA - 21-22 March

        Come see me speak on Saturday 21 March at 1:05pm, AMC Theater 13

- FIRST CTI Conference, Munich, Germany - 21-23 April

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Related Content

Newsletters
Hey Nineteen (Newsletters)

Heatwaves in Vegas, high AQI in Seattle, and fresh threat research. Inside this edition: Iran’s growing hacktivist network, Mexican document scarcity scams, and the layered crypto architecture powering IRGC financial transfers.

For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.

While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings.  After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.

The whole of July was more than packing for Summer Camp though,and  my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.

 

Hot Off the Presses 

Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Read the breakdown here

Scarcity Scams

When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods. 

Read the snack here

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities

In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.

At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Read the investigation here 

Where We’ll Be

  • ‍Boston Security Meetup, Boston, MA, 20 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Eighteen Newsletters and a Dozen Roses

June’s roundup of research - from cyberattacks on water infrastructure OT and ICS to DNS hijacking and an AiTM campaign targeting Microsoft365 users. 

June was unusually warm here in Seattle, which for a region that claims “June-uary” as a Season, is noteworthy. We made the best of it by watching Team USA defeat the Socceroos in a 2-0 victory at our beloved “Seattle Stadium” - Did you hear we have been ranked the #1 World Cup stadium this time around?. Of course it all came to an end yesterday, when the Belgian “Red Devils” (who have claimed that name for longer than Manchester United) gave the Team USA a soccer lesson they won’t soon forget. That 4-1 defeat stung, especially since it was the last game Seattle hosted this time around. Well, there are always the Mariners.

Despite heat and soccer, we still spent the month investigating emerging threats, talking about our already emerged research, and preparing for Hacker Summer Camp. We started with an investigation into an attacker-in-the-middle credential-harvesting kit targeting Microsoft365 and EntraID identities. Next our team analyzed Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. 

The team and I also attended SLEUTHCON in Arlington, VA; if you didn’t get a chance to say hi and grab a T-shirt, we will be in Las Vegas for Hacker Summer Camp next month with lots of swag. Ending the month, we published research on the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. As an added bonus, our friends at Dark Reading picked up the story and published their own article based on our research - I highly recommend giving it a read. I also had the pleasure of joining CyberWire’s Dave Bittner for an episode of his Research Saturday podcast talking about last month’s related research on the ZionSiphon OT malware sample. Now, let’s dive in and get you up to speed.  

Hot Off the Presses 

SecuritySnack - Hijacking Corporate Sessions

DTI researchers kicked off June with an investigation into a fully operational Adversary-in-the-Middle (AiTM) credential-harvesting kit targeting Microsoft 365 and Entra ID identities. The kit runs through a three-to-five stage funnel starting from financial, recruiting, and document related domain name themes. The funnels typically begin with an anti-analysis CAPTCHA gate to filter sandboxes, followed by a corporate email harvest stage that builds trust by dynamically rendering the victim's employer logo and filtering out personal email addresses. The final stage is a pixel-perfect, AiTM reverse proxy of the Microsoft sign-in page, which brokers the live authentication flow and successfully intercepts every credential, Multi-Factor Authentication (MFA) code (including Push, TOTP, and SMS), and post-authentication session cookie.

Read the snack here

Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

The DTI team pivoted to an analysis of Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. By targeting routers and bending DNS, Russian operators are able to watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Meanwhile, their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them access to messages, contacts, trusted names, and private conversations. 

Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.

Read our full analysis here

Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

To wrap up the month, our researchers took a deep dive into the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. Recent activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation. 

While each nation uses a slightly different model for these operations, they all are used as shaping tools rather than destructive actions. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.

Read the breakdown here 

Where We’ll Be

  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Edge of Seventeen (Newsletters)

We haven’t talked about the weather in Seattle for a bit. Just kidding, I ALWAYS talk about the weather here! Did you know that the Seattle Weather is officially one of the most difficult to accurately forecast? This is due (in part) to the so-called “Puget Sound Convergence Zone.” But also the fact that the area goes from sea level to 14,000 feet (4300m) within a 60 mile (97km) radius. And that we’re sandwiched between two mountain ranges and have a large patch of ocean that isn’t really the ocean because it’s a sound 🤷

In any case, today we reached 72 degrees Fahrenheit (22C), tomorrow will be 83 degrees (28C). June-uary better get here fast, I need three more weeks of gray and rain to adequately hydrate before summer starts on July 5th! But maybe the weather decided to “play along” and show the visitors that are coming to town for the FIFA World Cup a good time. Seattle is hosting four matches, including the US National Team 🇺🇸against the Socceroos 🇦🇺! And just like Matt Turner will keep close tabs on Jordan Bos and Nestory Irankunda, the DTI team has been busy keeping track of the latest threats. 

We started May (or technically ended April if we’re being specific) with a look at the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to compromise developer environments. The rest of May was spent taking a deeper dive into the Doppelganger campaigns we covered in March and looking at their operational pipeline and strategic significance. We rounded out the month with a look at the ZionSiphon malware sample, the OT malware designed to target Israeli water facilities with some critical flaws in its programming. 

Let’s dive in and get you up to speed!  

Hot Off the Presses 

Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?

DTI researchers analyzed the ZionSiphon malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. The malware is designed to target and sabotage water treatment and desalination facilities in Israel only. In our analysis, our team identified a critical bug in the malware’s geographic validation logic that prevents the malware’s payload from activating in its intended environment. Beyond the flaw in its geographic validation logic, the malware also lacks any external communication stack or command-and-control (C2) channel. 

Based on our analysis, our team determined ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool. 

Read the full technical breakdown here

Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential

After our first investigation into Doppelgänger in March, the DTI team took another deep dive into the Doppelgänger campaigns and their operational model. We broke down the narrative distribution model into four stages: content creation, telegram amplification, X/twitter injection, and narrative propagation. Our research determined the Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency. Using this analysis, our team modeled the first 72 hours of a Doppelgänger campaign during a geopolitical crisis. 

We also placed Doppelgänger in the larger doctrinal context of Russia’s “information confrontation” strategy. The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations. Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. The Doppelgänger campaign represents the digital transformation of the same strategy. 

Read our full analysis here

DPRK Contagious Interview: Developer Workflow Compromise

Our team kicked off May with an analysis of the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to induce execution of malicious code within trusted developer environments. The campaign targets software developers and technical personnel through fraudulent job interview processes conducted across platforms such as GitHub, LinkedIn, and direct messaging channels.

Read the breakdown here 

What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list will get you up to speed! 

‍📚See the full reading list here

Where We’ll Be

  • SLEUTHCON, Arlington, VA - 05 June
  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/
https://infosec.exchange/@danonsecurity

Learn More