Cyware Weekly Threat Intelligence, July 06 - 10, 2020

Weekly Threat Briefing • Jul 10, 2020
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Jul 10, 2020
The Good
With another week coming to an end, let’s take a quick glance at all the good developments that happened this week. The US Department of Justice (DoJ) indicted the notorious Fxmsp hacker responsible for breaching networks of 135 companies between 2016 and 2019. In a different incident, German authorities took down a web server controlled by the DDoSSecrets group. The server hosted the BlueLeaks website that provided access to internal documents of police personnel.
The DoJ indicted the infamous ‘Fxmsp’ hacker for selling access to dozens of corporate networks. The hacker had breached the networks of 135 companies in 44 countries between 2016 and 2019.
Security experts released free decryption keys for the recently discovered EvilQuest ransomware that uses a custom symmetric encryption routine based on the RC2 algorithm.
Microsoft seized six domains of a threat actor group that were used in a phishing operation against Office 365 customers. The gang sent emails to companies that hosted email servers and enterprise infrastructure on Microsoft’s Office 365 cloud service.
German authorities took down a web server - belonging to the DDoSecrets hacktivist group - that hosted the BlueLeaks website. The website provided access to internal documents stolen from the US police departments.
The Bad
The week also witnessed several organizations falling victims to different cyberattacks. Attackers hijacked over 240 website subdomains of various well-known companies with an aim to redirect users to malware, X-rated content, and online gambling. Meanwhile, the DXC Technology and EDP Renewable North America (EDPR NA) disclosed being hit by ransomware attacks.
The Egypt-based ride-hailing app, SWVL, was hacked in an attack that impacted personal information of passengers. The exposed data included emails, names, and phone numbers.
Clubillion app leaked Personally Identifiable Information (PII) of millions of its users due to an unsecured Elasticsearch database. The impacted data included emails, private messages, and IP addresses.
More than 240 website subdomains belonging to different organizations were hijacked to redirect netizens to malware, X-rated material, online gambling, and other unexpected content. The affected organizations included Chevron, the Red Cross, UNESCO, 3M, Getty Images, Hawaiian Airlines, Arm, Warner Brothers, and Honeywell.
DXC Technology disclosed a ransomware attack on its subsidiary firm, Xchanging. The incident occurred on July 5.
In a notification to customers, BCycle revealed that credit card information of some of its users was impacted in a hack. The incident occurred between January 24 and April 26, 2020.
Hackers attacked the Sheriff’s Office for Cooke County, Texas, and stole some of the law enforcement agency’s data in the process. The compromised data included information of both past and current police personnel.
Brazilian health insurer, Hapvida, disclosed a cyberattack that potentially affected both personal and medical information of its customers.
All IT systems of X-FAB Group were halted following a cyberattack. The firm had also stopped production at all its six manufacturing sites as an additional measure to stop further spread of the attack.
Ragnar Locker ransomware targeted EDP Renewable North America (EDPR NA) in its latest attack campaign. The incident had occurred on May 8, 2020.
Around 15 billion credentials that could give access to individuals’ bank accounts and companies’ networks were found for sale on the dark web. These credentials were harvested from over 100,000 discrete data breaches.
Chilton county temporarily closed its computer network after being targeted in a ransomware attack. As a result of the attack, local records required by the courthouse were rendered inaccessible.
New Threats
Among the new threats discovered this week, security researchers uncovered two threat actor groups, Keeper and Cosmic Lynx, that were responsible for a large number of card-skimming and BEC attacks respectively. While the Keeper gang has hijacked over 570 e-commerce sites over the last three years, the Cosmic Lynx has launched more than 200 BEC attacks since July 2019.