Cyware Weekly Threat Intelligence, July 18 - 22, 2022

Weekly Threat Briefing • July 22, 2022
Weekly Threat Briefing • July 22, 2022
The DOJ announced a bit of a win this week in the ongoing battle against state-sponsored ransomware campaigns. It clawed back about half a million in cryptocurrency that was paid as ransom to Maui ransomware hackers. Meanwhile, NIST has released the first draft of revised HIPAA guidelines that aims at improving the management of security risks affecting Electronic protected health information (ePHI).
Several high-profile personalities were caught in the crosshairs of spyware campaigns. While the notorious Pegasus spyware was used to infect at least 30 Thai activists, academics, lawyers, and NGO workers, the DevilsTongue spyware was used to pilfer sensitive data from journalists in the Middle East. Web skimming attacks were also reported this week after researchers discovered over 50,000 payment card details on dark web forums. These details belonged to customers who made restaurant payments through online portals of InTouchPOS, MenuDrive, and Harbortouch.
Meanwhile, Roaming Mantis has shifted its focus to France. Since February, the gang has infected over ten ten thousand Android and iOS devices via Smishing attacks. There’s also an update on new malware frameworks - Redeemer ransomware builder and Lightning Framework - that are capable of infecting a wide range of devices.