Barracuda SOC Threat Radar March 2026 shows a clear increase in identity-based attacks, while new campaigns with spyware and malicious PDF files spread globally.
Below are the key insights from February 2026.
More hijacked accounts – unusual increase in suspicious logins from Romania
The number of attacks based on stolen login credentials continues to grow. In February, about one in sixteen suspicious logins came from Romania, which stands out compared to previous months.
Organizations are at particularly high risk if they use weak or reused passwords, lack multi-factor authentication, do not monitor logins, or do not block logins from locations where they do not operate.
Recommendations:
Use strong passwords, enable MFA everywhere, monitor login attempts from unexpected locations, and implement conditional access. Training in recognizing phishing is also important.
Manipulated update function in Notepad++ exploited in espionage campaign
Barracudas The Security Operations Center (SOC) discovered an attack in which attackers compromised the function used to distribute updates to the text editor Notepad++. The program itself was not hacked, but some people were redirected to a fake installer file with a custom-built spyware called Chrysalis. The campaign has been linked to a Chinese state-sponsored actor with a focus on targets in the Asia-Pacific region.
Risks increase when organizations do not control how programs are installed and updated or lack the ability to detect unusual activity.
Recommendations:
Manually update Notepad++ to version 8.9.1 from the official website and temporarily block other update paths. Ensure all downloads are from approved domains and use multi-layered protection that can stop suspicious installations.
Malicious PDF files – several campaigns spread infostealers
During the period, the SOC stopped several attacks where malicious code was spread via PDF files.
One of the tools, TamperedChef, steals sensitive information such as login credentials and cookies. The attackers run fake websites promoted through Google advertising and trick users into downloading a ”free” PDF editor that actually installs malware.
Another campaign uses Santa Stealer, a new malware sold as a service (malware-as-a-service or MaaS). It runs in memory to avoid detection and steals everything from account credentials to crypto wallet data.
This type of malware is often exploited to gain access to networks, blackmail victims, or be resold by so-called initial access brokers to ransomware groups or other actors.
Recommendations:
Use strong passwords and MFA, monitor for anomalous login attempts and suspicious remote access, educate users on safe browsing and phishing, update systems regularly, and use advanced endpoint and email protection that can stop malware in real time.
Read more here"








