Cyware Weekly Threat Intelligence, February 15 - 19, 2021

Weekly Threat Briefing • Feb 19, 2021
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Feb 19, 2021
The Good
North Korean hackers have run amok for a number of years and caused damage wherever they could. But, this week the U.S. Department of Justice (DoJ) charged three men who are, allegedly, part of the state-backed Lazarus APT group. Brace yourself for one of the best news of the week. The data leak site of Egregor was brought down by French, Ukrainian, and U.S. law enforcement agencies. We are hoping that it would act as a major deterrent for ransomware affiliates.
The U.S. DoJ indicted three North Korean (DPRK) state-sponsored hackers for stealing cryptocurrency and funds from banks worth $1.3 billion. In another indictment, a Canadian man was arrested for helping the DPRK in money-laundering.
French and Ukrainian Police, along with U.S. law enforcement, detained some individuals for providing logistical and financial support to the gang behind the Egregor Ransomware-as-a-Service (RaaS).
A Nigerian national has been sentenced to 10 years in prison for reportedly coordinating an international spear-phishing campaign, resulting in a loss of $11 million. The scheme lasted from 2015 to 2019 and targeted Unatrac Holding Limited.
The Center for Internet Security is launching Malicious Domain Blocking and Reporting, a no-cost ransomware protection service, available for every healthcare facility through the MS-ISAC.
The Bad
Every week some new detail keeps popping up about the SolarWinds attack. Apparently, 100 organizations were breached and they might be targeted in the future. Following the recent Oldsmar water treatment plant attack, the FBI has warned against the use of outdated software. So, people listen to the FBI.
Singtel has revealed that 129,000 customers were impacted by a recently disclosed breach. This also includes some employees, partners, and corporate customers.
A new report from the White House has revealed that the SolarWinds hack had breached almost 100 U.S. companies, making them potential targets for follow-up attacks. Moreover, it has been revealed that more than 1,000 hackers rewrote around 4,000 of the millions of lines of code in the SolarWinds Orion update to launch the attack.
Kia Motors America has suffered a ransomware attack by the DoppelPaymer gang. Following the attack, the gang has demanded a ransom of $20 million to decrypt files and not leak them online.
Russian internet giant Yandex has revealed a data breach after a malicious insider got access to the accounts of thousands of its customers. The incident has affected around 4,887 mailboxes.
The FBI has warned federal government agencies and private companies about the potential threats posed due to the use of outdated Windows 7 systems and TeamViewer software.
The Cuba ransomware gang launched an attack against the Automatic Funds Transfer Services (AFTS) leading to several data breach notifications from agencies in Washington and California.
Russian-linked threat actor group Sandworm has been linked to a three-year-long stealthy operation that targeted several French entities. The intrusion, which started in late 2017 and lasted until 2020, was carried out by exploiting an IT monitoring tool called Centreon.
Cyberattack on Dutch Research Council (NWO) has forced the organization to suspend its research grants. The attackers had compromised servers and made the networks inaccessible.
The website of the U.K cryptocurrency exchange EXMO was knocked offline following a DDoS attack. This had affected the whole network infrastructure, including the website, API, Websocket API, and exchange charts.
The FBI, CISA, and Department of Treasury have released a joint alert highlighting the threats posed to cryptocurrency by North Korean hackers. These hackers are targeting companies and individuals alike through the propagation of cryptocurrency trading platforms.
New Threats
Mac malware has always been less ubiquitous than its Windows counterpart. However, it’s not the case anymore. Hackers have come up with a malware customized for execution on Apple’s new M1 chips. No one’s on the high chair anymore. Anyhoo, macOS wasn’t the only one that got a malware, Windows did too. Heard about the WatchDog botnet before? No? Now you will. Keep your cryptocurrency guarded.