Cyware Weekly Threat Intelligence - August 12–16

Weekly Threat Briefing • August 16, 2024
Weekly Threat Briefing • August 16, 2024
In a landmark move, the UN has unanimously passed its first-ever cybercrime treaty, laying the groundwork for a unified global response to cyber threats. This historic treaty, now headed to the General Assembly for final approval, empowers authorities to access electronic evidence across borders, marking a significant step toward enhanced international cybersecurity collaboration. NIST has set a new milestone by formalizing the world’s first post-quantum cryptography standards. Designed to protect against the impending quantum computing era, these standards ensure data integrity in the face of future quantum threats.
FortiGuard Labs uncovered a persistent ValleyRAT malware campaign specifically targeting Chinese-speaking users. Researchers detected a new variant of the Gafgyt botnet, which exploits machines with weak SSH passwords to expand its network and mine cryptocurrency using GPU power. Google’s Pixel devices were found to have shipped with a dormant app called Showcase.apk, which exposes them to potential security risks.
In the realm of new threats, Sophos identified the new EDRKillShifter tool being used by cybercriminals in a recent attempted ransomware attack. This tool is engineered to disable endpoint protection software by exploiting vulnerable drivers. Microsoft's August 2024 Patch Tuesday update addressed 90 vulnerabilities across various products, with seven classified as critical. CERT-UA issued a warning about a new phishing campaign that impersonates the Security Service of Ukraine to distribute the ANONVNC malware, enabling unauthorized access to infected computers.