Cyware Weekly Threat Intelligence, February 27 - March 03, 2023

Weekly Threat Briefing • March 3, 2023
Weekly Threat Briefing • March 3, 2023
The Biden administration has unveiled the much anticipated National Cybersecurity Strategy that aims at improving cyber resilience and disrupting cyber threat operations. The plan will also focus on expanding the cyber workforce and enhancing the cybersecurity of critical infrastructure. Furthermore, the CISA released an open-source tool to help defenders map attacker behavior to the MITRE ATT&CK framework.
Several major data leak events made headlines this week. For instance, the operators of darkweb marketplace BidenCash, on its first anniversary, made the stolen data of over two million people public. In other news, a security lapse in video marketing software Animaker exposed the personal details of over 700,000 users. Meanwhile, Colombian entities were hit again by the Blind Eagle APT that deployed QuasarRAT on victims’ systems.
On the new threats side, the prominence of the RIG exploit kit in the wild continues to worry security experts. It was found that the tool is being used to make roughly 2,000 intrusions daily by abusing old Internet Explorer unpatched vulnerabilities. A new sniffer malware, dubbed R3NIN, targeting e-commerce sites is also in the spotlight for stealing credit card details from customers. Additionally, a unique UEFI bootkit called BlackLotus was launched on a dark web forum; it is capable of bypassing Secure Boot defenses in Windows 11 systems.