Isometric network nodes highlighting Ivanti exploits and physical crypto theft.

Daily Cybersecurity News - February 15, 2026

Single Actor Dominates Ivanti Exploits

Executive Summary

A single threat actor, operating from bulletproof hosting, is reportedly responsible for 83% of exploitation attempts against critical remote code execution (RCE) vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). The campaign focuses on compromising unpatched servers to gain initial access for potential follow-on attacks.

Key TTPs

  • Initial Access: Exploiting unauthenticated code injection vulnerabilities in public-facing EPMM appliances.
  • Execution: Chaining vulnerabilities to achieve remote code execution and deploy web shells for persistent access.

Campaign Analysis

The high concentration of attacks from one source suggests a well-resourced, automated campaign to identify vulnerable systems at scale. This activity is consistent with an initial access broker cataloging compromised devices for future sale or exploitation.

Targeting & Infrastructure

  • Target Profile: European government and judicial agencies (e.g., European Commission, Dutch AP), and decentralized infrastructure (I2P network) currently under Sybil attack by the Kimwolf botnet.
  • Infrastructure: The majority of attacks originate from a single IP address (193[.]24[.]123[.]42) hosted on bulletproof infrastructure.

Relevant Terms

  • Remote Code Execution (RCE): A vulnerability that allows an attacker to execute arbitrary commands on a target system over a network.
  • Bulletproof Hosting: A service provided by a web hosting company that is resilient to takedown requests, often used for malicious activities.

Attackers Use Physical Mail To Steal Crypto

Executive Summary

Threat actors are sending physical letters to users of Trezor and Ledger hardware wallets, impersonating the manufacturers to steal cryptocurrency. The letters create a false sense of urgency, directing users to malicious websites via QR codes to trick them into exposing their wallet recovery phrases.

Key TTPs

  • Initial Access: Social engineering through physical mail, using letters with official-looking branding to establish legitimacy.
  • Execution: Victims are pressured to scan a QR code leading to a phishing website, where they are prompted to enter their recovery phrase to "authenticate" their device.

Campaign Analysis

This campaign marks a notable shift from purely digital attacks by blending a low-tech, physical delivery method with a modern crypto-theft objective. This hybrid approach is designed to bypass conventional email security filters and exploit user trust in official-looking postal mail.

Targeting & Infrastructure

  • Target Profile: Users of Ledger and Trezor cryptocurrency hardware wallets, likely identified from previous company data breaches that exposed customer contact information.
  • Infrastructure: Phishing websites designed to impersonate the official setup and verification pages of Trezor and Ledger.

Actionable Intelligence

  • Domains: trezor.authentication-check[.]io, ledger.setuptransactioncheck[.]com

Relevant Terms

  • Hardware Wallet: A physical device that stores a user's private keys offline, providing a secure environment for managing cryptocurrencies away from online threats.
  • Recovery Phrase: A list of 12-24 words that serves as the master backup for a cryptocurrency wallet, allowing the user to restore access to their funds on a new device.