BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Malware Roundup: BlackSanta EDR Killer, BeatBanker Android Trojan, and Zombie ZIP Evasion

Malware Roundup: BlackSanta EDR Killer, BeatBanker Android Trojan, and Zombie ZIP Evasion

March 11, 2026Malware & Threats4 min readhigh

Originally reported by BleepingComputer, Graham Cluley, Cisco Talos, Checkpoint Research, Malwarebytes Labs

#edr-evasion#android-malware#botnets#iranian-apt#patch-tuesday#sandbox-evasion#social-engineering#ai-security
Share

TL;DR

Security researchers identified multiple new malware threats including the BlackSanta EDR killer used by Russian actors against HR departments for over a year, BeatBanker Android malware posing as Starlink apps, and the Zombie ZIP technique for evading security tools. Meanwhile, Iranian MOIS actors are increasingly adopting cybercrime tools and infrastructure.

Why high?

Multiple actively deployed malware families including a sophisticated EDR killer targeting HR departments and Android banking malware using Starlink as lure, combined with new sandbox evasion techniques being actively exploited.

New BlackSanta EDR Killer Targets HR Departments

BleepingComputer reports that Russian-speaking threat actors have been deploying a new EDR evasion tool called BlackSanta against human resources departments for over a year. The malware specifically targets endpoint detection and response systems, allowing attackers to maintain persistence while avoiding security monitoring. HR departments remain attractive targets due to their access to employee data and often less stringent security controls compared to IT infrastructure.

BeatBanker Android Malware Masquerades as Starlink

A new Android banking trojan named BeatBanker is leveraging the popularity of SpaceX's Starlink service to trick victims into installation. According to BleepingComputer, the malware distributes through fake websites mimicking the official Google Play Store, offering fraudulent Starlink applications. Once installed, BeatBanker can hijack Android devices and steal banking credentials, exploiting users' trust in legitimate satellite internet services.

Zombie ZIP Technique Bypasses Security Tools

Researchers have identified a new evasion technique called "Zombie ZIP" that allows malicious payloads to bypass antivirus and EDR systems. BleepingComputer reports that this method involves specially crafted compressed files designed to exploit parsing differences between security tools and operating systems, enabling malware to slip through detection mechanisms unnoticed.

Microsoft March 2026 Patch Tuesday Addresses 79 Vulnerabilities

Microsoft's March 2026 security update addresses 79 vulnerabilities, including three marked as critical. Cisco Talos analysis highlights that the update includes fixes for two zero-day vulnerabilities and resolves an issue preventing some Windows 10 devices from shutting down properly. Microsoft also released the KB5078885 extended security update specifically for Windows 10 systems.

HPE Patches Critical AOS-CX Authentication Flaw

Hewlett Packard Enterprise addressed multiple security vulnerabilities in the Aruba Networking AOS-CX operating system, including a critical flaw allowing unauthorized admin password resets. BleepingComputer reports that the vulnerabilities encompass authentication bypasses and code execution issues that could grant attackers administrative access to network infrastructure.

KadNap Botnet Compromises ASUS Routers

A newly discovered botnet called KadNap is targeting ASUS routers and edge networking devices to create a proxy network for malicious traffic. BleepingComputer analysis shows the malware transforms compromised devices into relay points for cybercriminal operations, highlighting the continued targeting of consumer networking equipment for botnet infrastructure.

Iranian MOIS Actors Embrace Cybercrime Tools

Check Point Research reveals that Iranian Ministry of Intelligence and Security (MOIS) actors are increasingly integrating with the cybercrime ecosystem. The research indicates a shift from using cybercrime as cover to direct engagement with criminal tools, services, and operational models to support state objectives. This evolution blurs the line between nation-state activities and traditional cybercrime.

Advanced Malware Adopts Human Behavior Mimicry

The Picus Red Report 2026 shows that 80% of top attacker techniques now focus on evasion and persistence. BleepingComputer reports that modern malware employs sophisticated sandbox evasion including geometry-based cursor movement tests and CPU timing checks to prove "humanness" and avoid automated analysis environments.

Microsoft Introduces Entra Passkey Support

Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, providing phishing-resistant passwordless authentication through Windows Hello integration. This deployment aims to reduce credential-based attacks by eliminating traditional password vulnerabilities in enterprise environments.

Twitter Suspended 800 Million Accounts in 2025

Elon Musk's social media platform suspended 800 million accounts for spam and manipulation in 2025, yet state-backed influence campaigns continue to proliferate. Graham Cluley's analysis questions the effectiveness of these enforcement actions given the persistent presence of coordinated inauthentic behavior on the platform.

Cisco Talos Discusses Agentic AI Security Risks

Cisco Talos published guidance on agentic AI security, emphasizing the dual-edged nature of autonomous AI agents within organizations. The analysis highlights the need for robust risk management and threat modeling to address both operational errors and potential malicious exploitation of AI systems with autonomous decision-making capabilities.

Sources

  • https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/
  • https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/
  • https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5078885-extended-security-update/
  • https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-aos-cx-flaw-allowing-admin-password-resets/
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-brings-phishing-resistant-sign-in-to-windows/
  • https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/
  • https://www.bleepingcomputer.com/news/security/the-new-turing-test-how-threats-use-geometry-to-prove-humanness/
  • https://www.bitdefender.com/en-us/blog/hotforsecurity/twitter-suspended-800-million-accounts-last-year-so-why-does-manipulation-remain-so-rampant
  • https://blog.talosintelligence.com/agentic-ai-security-why-you-need-to-know-about-autonomous-agents-now/
  • https://blog.talosintelligence.com/spinning-complex-ideas-into-clear-docs-with-kri-dontje/
  • https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2026/
  • https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/
  • https://www.malwarebytes.com/blog/how-to/2026/03/how-to-see-your-google-search-history-and-delete-it

Originally reported by BleepingComputer, Graham Cluley, Cisco Talos, Checkpoint Research, Malwarebytes Labs

Tags

#edr-evasion#android-malware#botnets#iranian-apt#patch-tuesday#sandbox-evasion#social-engineering#ai-security

Threat Actors

🏴Play

Tracked Companies

🇺🇸X Corp
🇺🇸Google

Related Intelligence

  • Trojanized Red Alert App Targets Israeli Users via Fake Government SMS

    highMar 8, 2026
  • Velvet Tempest Links Termite Ransomware to ClickFix CastleRAT Campaign

    highMar 8, 2026
  • Malware Threats Weekly: CISA Flags Ivanti EPM Zero-Day, APT28 Leverages Covenant Framework, Meta Ad Network Powers Global Scam Operations

    criticalMar 10, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← March Patch Tuesday: Microsoft Fixes 84 Flaws Including Zero-Days, Supply Chain Attacks Surge

Next Article

DOGE Employee Allegedly Exfiltrated Social Security Data via USB Drive →