Cyware Weekly Threat Intelligence - April 18–22

Weekly Threat Briefing • April 22, 2022
Weekly Threat Briefing • April 22, 2022
The Good
Governments are realizing that multilateral collaboration, not only among private organizations, but also among different nations is the way to create a secure cyberspace. In this regard, the U.S. is partnering with six other countries to safeguard the cross-border flow of data. Cybercriminals making mistakes and leaving gaps in their malware architecture has always been a good piece of news. Due to this very reason, researchers were able to build a decryptor for the Yanluowang ransomware.
The Bad
Do not speak ill of the dead for they may come alive. It’s been almost a year since Emotet was shut down and now, it’s back from its grave and quickly rising to the forefront of the threat landscape via rapidly spreading email scams. Not only Emotet, but we also have another resurrection on our hands this week. REvil’s servers are up on the Tor network and the gang has already listed two fresh victims on its new leak site. New week, new crypto hack. A cyberattack on BeanStalk Farms resulted in the loss of millions worth of cryptocurrency.
New Threats
Since the Russian invasion of Ukraine started, the latter has had no respite from cyberattacks. The Russia-linked Gamaredon group is now launching targeted attacks using four new malware variants. Threat actors are back at spreading malware via fake Windows updates. They are propagating the 'Inno Stealer' malware through SEO poisoning tactics. There’s a new location in the cyber underground, named Industrial Spy, for the sale of stolen enterprise data.