Cyware Weekly Threat Intelligence - February 20–24

Weekly Threat Briefing • Feb 24, 2023
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Feb 24, 2023
Building robust and resilient cybersecurity amidst growing sophisticated cyber threats calls for pragmatic investments in the right areas. Keeping this in mind, the U.K. government has announced a fund of around $22 million to foster new research and development in Northern Ireland’s cybersecurity industry. Meanwhile, Google is exploring new ways to improve security across the Android ecosystem. This in-depth defense strategy will be applicable at the firmware level to reduce the impact of cyberattacks on Android devices.
The cybersecurity of GoDaddy is in chaos as attackers ran amok across its infrastructure for three-long years, only to be discovered recently. The relentless menace by the LockBit ransomware continues as threat actors added a water utility firm in Portugal to its leak site. The gang has further threatened to leak the stolen data if the firm fails to meet its ransom demand. The security concerns associated with open-source software are also in the limelight as researchers uncovered a series of phishing attacks involving over 15,000 malicious npm packages.
Web hosting giant GoDaddy disclosed that it was a victim of a multi-year security breach that started in May 2020. The same attackers stole the source code for Managed WordPress (MWP) in November 2021 and, later in December 2022, infected the cPanel hosting server with malware.
The LockBit ransomware group took credit for an attack on the water utility at Águas e Energia do Porto, Portugal. The attack occurred on February 8; however, the security team was able to limit the extent of the damage. Meanwhile, the gang added the company to its leak site on February 18, and has threatened to publish the stolen data if the ransom demand is not fulfilled by March 7.
Researchers came across multiple phishing attempts launched via malicious npm packages. Over 15,000 spam packages were dropped with tempting descriptions that promised free resources, game cheats, and likes on social media platforms. These packages were generated automatically using a Python script and hence closely resembled one another.
A ransomware attack forced agricultural and food production giant Dole to shut down its food packaging and distribution operations across North America, The incident took place earlier this month, and even after two weeks, the company’s operations are still down across the U.S.
Telus, one of the biggest telecommunications companies in Canada, became aware of a security breach after a threat actor uploaded private source code and employee data to the dark web for sale. The company has begun investigating the matter and has so far not found evidence of corporate or retail customer data being stolen.
Android voice chat app, OyeTalk, had inadvertently leaked unencrypted data through its unprotected Google Firebase instance. The leaked data includes usernames and cellphone IMEI numbers. It is believed that malicious actors could have deleted the dataset, resulting in a permanent loss of users’ private messages.
Lehigh Valley Health Network revealed that it suffered an attack by the BlackCat ransomware group. The unauthorized activity was detected on February 6 and involved a computer system used for patient images for radiation oncology treatment. The investigation to understand the full scope of the attack is underway.
Australia-based retail firm, The Good Guys, confirmed that its customer data was compromised in a third-party breach at My Rewards. The affected data included names, email addresses, and phone numbers of customers.
Unknown hackers stole internal data from the gaming giant Activision and published them on dark web forums. According to the firm, the hackers stole information such as full names, email addresses, phone numbers, salaries, work addresses, and home addresses of employees.
The growing traction of the recently launched ChatGPT chatbot is also accompanied by its popularity among cybercriminals as an attack vector. In one such incident, the hackers were found using fake ChatGPT apps to push a variety of malware such as RedLine stealer and Lumma stealer. In another news, a particular ransomware operator has updated its malware with a unique extortion tactic that puts pressure on the victim organization’s insurance company to pay up. A new threat group, named Hydrochasma, is also on the radar of researchers as it actively targets medical labs and shipping companies in Asia.