Aryaka Threat Research reported that the BlackSanta malware campaign is targeting recruitment workflows, using job-related lures to reach victims and then attempting to neutralize endpoint protection with EDR-killing functionality. The operation was described as a stealthy intrusion chain designed to blend into normal hiring activity while weakening host defenses early in execution, increasing the likelihood of follow-on compromise and persistence.
Separately, Censys published an advisory on GNU Inetutils telnetd remote authentication bypass tracked as CVE-2026-24061, highlighting a flaw that could allow unauthorized access to exposed services. Together, the reports underscore concurrent risks from both socially engineered malware delivery and internet-exposed remote access software vulnerabilities, with defenders urged to review recruitment-related security controls, validate endpoint protection tamper resistance, and identify any externally reachable telnetd instances requiring remediation.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Aryaka Threat Research published a report describing the BlackSanta malware campaign, which it said targeted recruitment workflows and attempted to disable endpoint security tools.
Censys published an advisory for CVE-2026-24061 affecting GNU Inetutils telnetd. The topic indicates the advisory was issued on January 27, documenting a remote authentication bypass vulnerability.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
censys.com
Open sourcearyaka.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.