CSO Online reported active exploitation of Ivanti Endpoint Manager Mobile (EPMM) zero-day vulnerabilities being used to seize control of mobile device management (MDM) servers, potentially enabling attackers to compromise device fleets managed through affected deployments. The coverage frames the activity as in-the-wild exploitation of previously unknown flaws impacting enterprise mobility infrastructure.
Separately, CSO Online also described Arkanix, an information-stealing malware family that combines fast data collection via Python components with stealthier C++ payloads, reflecting a modular approach to credential and data theft. Other items in the provided material (an NSFOCUS write-up on AI-related prompt-injection style incidents and a Security Affairs malware-newsletter roundup) do not provide corroborating reporting on the Ivanti EPMM exploitation or the Arkanix stealer and appear to be broader, multi-topic content rather than coverage of the same specific event.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On February 24, 2026, reporting based on Kaspersky research revealed Arkanix's dual architecture: rapid Python-based harvesting paired with stealthier native C++ payloads. The analysis also described its data theft scope, exfiltration methods, and command-and-control infrastructure.
After its brief campaign, Arkanix's affiliate program was shut down and its infrastructure, including two Cloudflare-fronted domains hosting a protected panel, was taken offline. The takedown was consistent with the malware operation's short lifespan.
By February 2026, attackers were reported to be actively exploiting zero-day vulnerabilities in Ivanti EPMM to take control of mobile device management servers. The reporting indicates live compromise of exposed MDM infrastructure.
Arkanix Stealer appeared in late 2025 as a short-lived information-stealing malware operation. Kaspersky later assessed it as likely an AI/LLM-assisted development experiment built for a rapid, limited campaign rather than a sustained criminal service.
In October 2025, operators promoted Arkanix Stealer on dark web forums as a malware-as-a-service offering. The ads described a control panel, configurable payloads, and a Discord server used as the main communications channel.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.