logo

Intelligence Insights: March 2026

ID: 896e70b7-d5f1-5221-b4b0-bf4e031e0884

STIX ID: report--896e70b7-d5f1-5221-b4b0-bf4e031e0884

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

Highlights from February: Red Canary’s monthly prevalence report notes ScreenConnect topping the list due to phishing-delivered remote access misuse (sometimes via other RMM tools), a four-way tie for second including ClearFake and Scarlet Goldfinch which use drive-by and paste-and-run techniques, and appearances by infostealers such as Atomic Stealer, MacSync Stealer, and Vidar; the report emphasizes delivery TTPs (phishing, paste-and-run, RMM abuse) and relative prevalence across customer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.