Two campaigns broke this week that tell you everything about where attackers are spending their effort. PowMix, a previously undocumented botnet, has been quietly chewing through the Czech workforce since December 2025. Meanwhile, North Korea’s Sapphire Sleet crew has been running macOS intrusions that start with a friendly LinkedIn message and end with drained crypto wallets. Different targets, different tradecraft, same ugly truth: perimeter defenses and endpoint agents aren’t catching the initial access, and that’s exactly where ipban-style IP-level controls still earn their keep.

The 2026 attack pattern: quiet recon, loud payoff

Look at what Cisco Talos described with PowMix. Five months of operation before anyone publicly named it. A botnet aimed at a specific national workforce, not a smash-and-grab. That’s the playbook now — go slow, blend in, and harvest. The command-and-control infrastructure for operations like this eventually reaches out to IPs that show up on threat intel feeds. If you’re not ingesting and acting on those feeds at the firewall, the botnet happily beacons home from every infected workstation on your network.

PowMix botnet threat spotlight graphic
Talos disclosed PowMix after it had been operating quietly for nearly five months.

Microsoft’s writeup on Sapphire Sleet tells a parallel story on the macOS side. The DPRK operators use fake recruiter lures, user-driven execution, and bespoke tooling to sidestep Gatekeeper and TCC. Once in, they reach out to their infrastructure. Again — IPs, domains, ASNs that can be flagged, rate-limited, or outright blocked at the edge. The endpoint got owned because the user clicked. That ship has sailed. What you can still do is make sure the malware can’t phone home, and can’t brute-force its way laterally into anything else.

Why endpoint-only strategies keep failing

This week a researcher calling themselves “Chaotic Eclipse” dropped a second Microsoft Defender zero-day PoC in two weeks — this one granting SYSTEM privileges. It’s called RedSun, and the release appears to be a protest against how Microsoft handles disclosures. The politics aside, the lesson is blunt: the security tool running on your endpoints is itself an attack surface. When the AV becomes the privilege escalation path, you don’t want to be relying on it alone to stop threats.

That’s the argument for defense in depth that security teams have made for twenty years, and it’s still correct. What’s changed is the volume. Thor’s Q1 2026 vulnerability pulse flags something sysadmins already feel in their bones — legacy CVEs are still being exploited in huge numbers, and AI is accelerating both discovery and weaponization. The patch window is shrinking while the vulnerable footprint keeps growing. If you can’t patch fast enough, you need something in front of the vulnerable service that makes exploitation expensive.

IP banning isn’t a silver bullet — it’s a force multiplier

Nobody serious claims IP blocking alone solves cybersecurity. But every one of this week’s stories has a piece that IP-level controls would make harder. Brute-force attempts against exposed RDP or SSH? Block repeat offenders. Botnet beacons to known bad ASNs? Drop them. Scanners hunting for Marimo notebook instances to drop NKAbuse on? They announce themselves before they exploit, and the announcement is an IP you can ban.

Q1 2026 vulnerability pulse chart
Legacy CVEs still dominate exploitation data in Q1 2026.

The developer tool problem nobody’s talking about

The Marimo story deserves its own paragraph because it’s a trend more than a one-off. Marimo is a reactive Python notebook — exactly the kind of tool a data science team spins up on an internal server and forgets about. Attackers found a critical flaw, and they’re deploying NKAbuse malware hosted on Hugging Face Spaces. Think about that supply chain for a second: legitimate dev tool, legitimate AI platform, weaponized payload.

This is the same pattern we saw with Jupyter exposures, with Redis instances, with MongoDB. Developer-friendly services keep ending up on the public internet with weak or no authentication, and attackers scan for them constantly. The SANS ISC guest diary on compromised DVRs makes the same point from a completely different angle — low-priority devices nobody’s watching become the persistent foothold.

If your firewall isn’t actively blocking the IPs doing the scanning, you’re relying entirely on the security posture of tools built by people who weren’t thinking about hostile environments. That’s a bad bet.

The crypto inventory angle

Quick note on Microsoft’s piece about building a cryptographic inventory. Quantum-safe readiness is a real concern and worth planning for. But if you’re still exposing services to brute-force attacks from known malicious IPs, worrying about post-quantum crypto is like reinforcing the vault door while leaving the front window open. Fix the 2026 problems before you solve the 2030 problems.

What You Can Do

Here’s the playbook, in the order that actually matters:

  • Block at the edge first. Ingest reputable threat intel feeds and drop traffic from known-bad IPs before it hits your services. This alone kills a huge chunk of botnet C2 and scanner noise.
  • Rate-limit authentication endpoints. RDP, SSH, SMB, web admin panels, VPN concentrators — any of them accepting unlimited auth attempts is a gift to attackers. Fail2ban-style dynamic banning is table stakes in 2026.
  • Inventory your exposed dev tools. Jupyter, Marimo, Redis, Elasticsearch, internal wikis with weak auth. Put them behind VPN or IP allowlists. If they must be public, add brute force protection.
  • Don’t trust your endpoint agent to be infallible. The RedSun PoC is a reminder. Assume a layer will fail, and build so the next layer catches it.
  • Monitor outbound connections. Sapphire Sleet and PowMix only become a real problem when they reach their C2. Egress filtering and IP reputation on outbound traffic is just as important as inbound.

This is the niche IPBan Pro was built for — automating the IP banning and threat-protection layer so your team isn’t manually chasing log entries at 2 AM. It handles brute-force protection across Windows and Linux, ingests threat feeds, and shares ban data across your fleet. It won’t stop a user from clicking a North Korean recruiter’s PDF. Nothing will. What it will do is make sure the attacker’s infrastructure has a much harder time reaching your machines before and after that click.

Frequently Asked Questions

Does IP banning still work when attackers use residential proxies and botnets?
Yes, but not on its own. Modern IP banning works best when combined with behavioral rules, rate limiting, and threat intel feeds. Attackers using residential proxies still burn IPs faster than they’d like, and each ban raises their operational cost. The goal isn’t perfection — it’s friction.
How is IPBan Pro different from built-in Windows account lockout?
Windows account lockout locks the account, which creates a denial-of-service risk and doesn’t stop the attacker from pivoting to other accounts. IPBan Pro blocks the source IP at the firewall level, so the attacker can’t keep probing, and it coordinates bans across multiple servers automatically.
Should I block entire countries or ASNs?
If you don’t do business in a region, geo-blocking at the firewall is a reasonable coarse filter that eliminates a lot of scanner traffic. ASN-level blocking is more surgical — blocking known bulletproof hosting providers rarely affects legitimate users. Just monitor for false positives.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.