Cyware Weekly Threat Intelligence - April 04–08

Weekly Threat Briefing • April 8, 2022
Weekly Threat Briefing • April 8, 2022
The Good
Governments are increasingly looking to upgrade their cybersecurity policies to align with the changing security landscape. Taking a step in that direction, the U.S. State Department launched its Bureau of Cyberspace and Digital Policy. The Cyclops Blink botnet was killed before it could even blink a complete blink. The FBI took down the modular botnet by disrupting its infrastructure and closing external management ports.
The Bad
Despite humongous data leaks of its own internal communications, Conti remains in business. The ransomware actor leaked around 5GB of files belonging to Parker Hannifin. Just when you think a particular threat has disappeared and you can breathe a little easy, it comes and hits you hard. The same goes for the recent Magecart attack against a mattress maker, which impacted customers across 12 nations. Cadbury UK took to Twitter to warn against a scam pretending to sell free chocolates. Falling victim to it can turn pretty bitter, warned the company.
**New Threats **
Borat’s in town; not the movie though. It’s a new RAT that can conduct both ransomware and DDoS attacks, along with possessing several other capabilities. WhatsApp has once again become a favorite target for cybercriminals as a new phishing campaign abuses the platform’s voice messaging feature. The SharkBot banking trojan has resurfaced in a new campaign, biting victims across many countries.