Cookie Settings

This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.

Cyware Weekly Threat Intelligence - June 10–14

Cyware Weekly Threat Intelligence - June 10–14 - Featured Image

Weekly Threat Briefing Jun 14, 2019

The Good

We’re back with the most interesting threat intel of the week. The past week witnessed several cybersecurity advancements, security incidents, as well as the emergence of new threats. To begin with, let’s first glance through all the positive developments that have emerged over the past week. Google has announced its expansion of Android’s security key technology to iOS devices. Researchers have developed a framework to measure the agility of cyber attackers and defenders. Meanwhile, Microsoft’s Windows 10 v1903, allows users to sign-in to their Microsoft account without a password.

  • Google has announced that it is expanding Android’s security key technology to iOS devices. This implies that iPhone and iPad users could use Android smartphones as a security key while logging into their Google accounts on an iOS device. For this to work, users should have Bluetooth enabled on both their iOS and Android devices.

  • A research team from the University of Texas at San Antonio (UTSA) has developed the first framework to score and quantify the agility of cyber attackers and defenders. This cyber agility project is funded by the Army Research Office. This framework will help government and industry organizations to test out numerous and varied responses to an attack.

  • Microsoft has released Windows 10, version 1903, which allows users to add a passwordless phone number Microsoft account to Windows and to sign-in with the Microsoft Authenticator app. This Microsoft Authenticator app allows users to create a Microsoft account with just their phone number in mobile Office apps and unlock their Microsoft account without a password.

The Bad

Several data breaches and security incidents were witnessed in the past week. The US Customs and Border Protection agency disclosed that the photos of travelers and license plates have been compromised in a cyber attack at one of its contractors. Telegram suffered a powerful DDoS attack originating from China during the Hong Kong protests. Last but not least, ASCO, one of the world’s largest airplane parts manufacturer, suffered a ransomware attack paralyzing the production in factories across various countries.

  • ASCO, one of the largest airplane parts manufacturer, suffered a ransomware attack crippling production in factories across four countries including Belgium, Germany, Canada, and the United States. ASCO factory in Zaventem, Belgium was hit by a ransomware infection causing major downtime as most of the plant’s IT systems were infected. As a result of which, almost 1,000 of its 1,400 workers were sent home.

  • The City of Edcouch suffered a data breach after a hacker gained access to the city’s network and stole all the city’s information. The hacker then threatened to erase all the information if a ransom of $40,000 in BTC was not paid. The compromised information includes the personal data of over 3000 residents. The hacker also stole information from the water department and city finances.

  • A Distributed Denial of Service (DDoS) attack on Telegram messenger caused service outages and connection problems for users primarily in South and North America and other parts of the world. A botnet formed of compromised computers sent huge traffic to Telegram servers which resulted in unstable connections as the messenger could not handle all the requests. The attack originated from China during the Hong Kong protests.

  • Hackers stole several archived mini discs from the Radiohead’s lead singer Thom Yorke and demanded a ransom payment of $150,000 to stop them from being released to the public. The mini discs contained 18 tracks of OK Computer sessions. Instead of meeting the hacker’s demand, Radiohead themselves released all the stolen tracks on Bandcamp for £18, with all the proceeds going to Extinction Rebellion.

  • The e-invitations platform Evite has admitted that it suffered a data breach in February. The stolen user data was actually put up for sale in the Dream Market marketplace by the infamous hacker ‘Gnosticplayers’. Evite also provided additional details about the breach. The social planning website revealed that an unauthorized third party gained access to an inactive data storage file that contained Evite user accounts prior to 2013.

  • Three major private banks in Russia, OTP Bank, Alfa Bank, and HCF Bank had its customer data leaked online. A publicly available database listed as OTP Bank contained personal data of almost 800,000 clients. Another unsecured database that contained data of HCF bank held almost 24,400 customers’ personal information. DeviceLock uncovered two databases that contained customer data of Alfa Bank. The first database included personal data of over 55,000 customers and the second database contained just 504 entries.

  • The retro gaming site ‘Emuparadise’ suffered a data breach in April 2018, which led to the exposure of account details of almost 1.1 million Emuparadise forum members. The exposed account information included members’ email addresses, IP addresses, usernames, and passwords stored as salted MD5 hashes.

  • The US Customs and Border Protection agency disclosed that the photos of travelers and license plates have been compromised in a cyber attack at one of its contractors. The CBP said that one of its contractors transferred copies of license plate images and traveler photos collected by CBP to the company’s network, which was later compromised by an attacker. The agency did not reveal the name of the contractor, however, CBP’s public statement sent to the Washington Post included the name “Perceptics” in the title: “CBP Perceptics Public Statement”, indicating that the contractor is Perceptics.

  • A misconfiguration in the Kingman Regional Medical Center website allowed unauthorized individuals to view and access the information entered into the website by KRMC customers. The information that was accessible by unauthorized persons included customer’s names, dates of birth, and limited medical information.

  • An unprotected Elasticsearch database belonging to Shanghai Jiao Tong University which is sized 8.4TB has exposed almost 9.5 billion rows of email metadata. Based on the metadata, the researchers were able to find out that all emails were being sent or received by a specific person. The data included the IP address and user agent of the person checking their email.

  • The City Hall in Lake City, Florida has been hit with the ‘Triple Threat’ ransomware, crippling the City Hall’s email and telephone services. However, all emergency services including Police and Fire are not affected by the attack. Public Safety networks have also been isolated and protected by encryption.

New Threats

The past week also witnessed the occurrence of several new malware strains and vulnerabilities. A new variant of Mirai botnet that uses 18 exploits to target IoT devices has been spotted. FIN8 threat group has resurfaced with a new variant of ShellTea/PunchBuggy backdoor targeting the hospitality industry. Meanwhile, Researchers have uncovered an ongoing crypto jacking campaign, wherein attackers are using NSA hacking tools to compromise vulnerable computers of businesses across the globe.

  • Researchers have uncovered a new variant of Mirai botnet that uses 18 exploits to target IoT devices. This variant includes 8 new exploits apart from the 10 existing exploits. It is capable of targeting devices ranging from wireless presentation systems to set-top-boxes, SD-WANs, and even smart home controllers. It also includes exploits targeting the Oracle WebLogic Server RCE vulnerability.
  • Microsoft has issued a warning on an ongoing malspam campaign that drops a backdoor trojan by abusing an old MS Office vulnerability. This campaign targets European users with emails written in various European languages. The spam emails include malicious RTF documents which when opened, download a backdoor trojan without any user interaction. However, the good news is that the backdoor trojan’s C&C server has been taken down since Microsoft issued a security alert.
  • Microsoft has released its June 2019 Updates which fixes 88 security flaws affecting a range of its products. Out of the 88 flaws, 21 were rated ‘critical’ by Microsoft. The security updates also fix 9 remote code execution vulnerabilities found in the tech giant’s Office products such as Word 2010, Word 2013, Word 2016, Office 2010, Office Online Server, SharePoint Foundation 2013, Project Server 2010, SharePoint Server 2010, and SharePoint Server 2010 Office Web Apps.
  • Security researchers have uncovered a new cryptocurrency mining malware that targets Oracle WebLogic servers. The malware exploits a known vulnerability to hijack insecure Oracle servers and install a Monero cryptocurrency mining bot on the servers. Researchers noted that the malware used in the attack remained hidden inside certificate files and later dropped Monero miners in the system.
  • A new malspam campaign targeting UK users has been spotted in the wild. Researchers observed a number of spam emails related to this campaign with the scammers attempting to abuse DNS records in their methods. The IP addresses associated with the campaign are likely linked with Necurs botnet. The spam emails include HTML attachments, which upon clicking redirect users to a fraudulent trading site.
  • Security researchers uncovered several vulnerabilities in the HSM of a major vendor that could allow attackers to retrieve sensitive data stored inside Hardware Security Modules. Attackers could also exploit a cryptography bug in the firmware signature verification to upload a modified firmware to the HSM that includes a persistent backdoor.
  • An analysis by Google Security has revealed that hackers in 2017 had cleverly loaded adware into Android devices by tampering with the pre-installed software. The malware, a variant of the Triada adware family, was inserted through apps and programs built by third-party vendors. The adware was installed during the manufacturing process of Android phones. The affected smartphone models are Leagoo M5 Plus, Leagoo M8, Nomu S10, and Nomu S20.
  • FIN8 threat group is back with a new variant of ShellTea/PunchBuggy backdoor targeting the hospitality industry. The ShellTea malware is capable of creating and executing files, writing the data or shellcode it received from the C&C server, and executing the shellcode. The malware leverages a hashing algorithm to evade detection from antivirus tools.
  • Researchers have uncovered a new variant of the Hide ‘N Seek botnet that includes exploits of two new vulnerabilities in the ThinkPHP installations and the Sonatype Nexus Repository Manager software installations. The vulnerabilities are tracked as CVE-2018-20062 and CVE-2019-7238 respectively. This new variant targets Android devices via ADB.
  • Twitter URLs could be abused by bad actors for various nefarious activities including distributing malware, spread fake news, and redirecting users to a phishing page. Bad actors could abuse a tweet URL by simply changing the username but using a status ID that points to a tweet from an account controlled by them. In this way, attackers could spread fake news or malicious content as users click on the tweet thinking it is from a trusted source.
  • Researchers have uncovered an ongoing crypto jacking campaign, wherein attackers are using NSA hacking tools to compromise vulnerable computers of businesses across the globe. The NSA hacking tools used in this campaign include EternalBlue and EternalChampion. Using these tools, attackers target unpatched Windows computers to install XMRig Monero miners.

Related Threat Briefings

Feb 7, 2025

Cyware Weekly Threat Intelligence, February 03–07, 2025

PyPI is taking a "dead but not gone" approach to abandoned software with Project Archival, a new system that flags inactive projects while keeping them accessible. Developers will see warnings about outdated dependencies, helping them make smarter security choices and avoid relying on unmaintained code. The U.K is bringing earthquake-style metrics to cybersecurity with its new Cyber Monitoring Centre, designed to track digital disasters as precisely as natural ones. Inspired by the Richter scale, the CMC will quantify cyber incidents based on financial impact and affected users, offering clearer insights for national security planning. Kimsuky is back with another phishing trick, this time using fake Office and PDF files to sneak forceCopy malware onto victims' systems. Its latest campaign delivers PEBBLEDASH and RDP Wrapper by disguising malware as harmless shortcuts, ultimately hijacking browser credentials and sensitive data. Hackers have found a new way to skim credit card data - by hiding malware inside Google Tag Manager scripts. CISA is flagging major security holes in Microsoft Outlook and Sophos XG Firewall, urging agencies to patch them before February 27. One flaw allows remote code execution in Outlook, while another exposes firewall users to serious risks. Bitcoin scammers are switching tactics, swapping static images for video attachments in MMS to make their schemes more convincing. A recent case involved a tiny .3gp video luring victims into WhatsApp groups where scammers apply pressure to extract money or personal data. XE Group has shifted from credit card skimming to zero-day exploitation, now targeting manufacturing and distribution companies. A new version of ValleyRAT is making the rounds, using stealthy techniques to infiltrate systems. Morphisec found the malware being spread through fake Chrome downloads from a fraudulent Chinese telecom site.

Jan 10, 2025

Cyware Weekly Threat Intelligence, January 06–10, 2025

The U.K is fortifying its digital defenses with the launch of Cyber Local, a £1.9 million initiative to bridge cyber skills gaps and secure the digital economy. Spanning 30 projects across England and Northern Ireland, the scheme emphasizes local business resilience, neurodiverse talent, and cybersecurity careers for youth. Across the Atlantic, the White House introduced the U.S. Cyber Trust Mark, a consumer-friendly cybersecurity labeling program for smart devices. Overseen by the FCC, the initiative tests products like baby monitors and security systems for compliance with rigorous cybersecurity standards, ensuring Americans can make safer choices for their connected homes. China-linked threat actor RedDelta has ramped up its cyber-espionage activities across Asia, targeting nations such as Mongolia, Taiwan, Myanmar, and Vietnam with a modified PlugX backdoor. Cybercriminals have weaponized trust by deploying a fake PoC exploit tied to a patched Microsoft Windows LDAP vulnerability. CrowdStrike reported a phishing operation impersonating the company, using fake job offers to lure victims into downloading a fraudulent CRM application. Once installed, the malware deploys a Monero cryptocurrency miner. A new Mirai-based botnet, dubbed Gayfemboy, has emerged as a formidable threat, leveraging zero-day exploits in industrial routers and smart home devices. With 15,000 active bot nodes daily across China, the U.S., and Russia, the botnet executes high-intensity DDoS attacks exceeding 100 Gbps. In the Middle East, fraudsters are posing as government officials in a social engineering scheme targeting disgruntled customers. Cybercriminals have weaponized WordPress with a malicious plugin named PhishWP to create realistic fake payment pages mimicking services like Stripe. The plugin not only captures payment details in real time but also sends fake confirmation emails to delay detection.

Dec 20, 2024

Cyware Weekly Threat Intelligence, December 16–20, 2024

In a digital age where borders are blurred, governments are sharpening their strategies to outpace cyber adversaries. The draft update to the National Cyber Incident Response Plan (NCIRP) introduces a comprehensive framework for managing nationwide cyberattacks that impact critical infrastructure and the economy. Meanwhile, the fiscal year 2025 defense policy bill, recently approved by the Senate, emphasizes strengthening cybersecurity measures both at home and abroad. A deceptive health app on the Amazon Appstore turned out to be a Trojan horse for spyware. Masquerading as BMI CalculationVsn, the app recorded device screens, intercepted SMS messages, and scanned for installed apps to steal sensitive data. Malicious extensions targeting developers and cryptocurrency projects have infiltrated the VSCode marketplace and NPM. Disguised as productivity tools, these extensions employed downloader functionality to deliver obfuscated PowerShell payloads. The BADBOX botnet has resurfaced, compromising over 192,000 Android devices, including high-end smartphones and smart TVs, directly from the supply chain. Industrial control systems are facing heightened risks as malware like Ramnit and Chaya_003 targets engineering workstations from Mitsubishi and Siemens. Both malware families exploit legitimate services, complicating detection and mitigation efforts in ICS environments. The Chinese hacking group Winnti has been leveraging a PHP backdoor called Glutton, targeting organizations in China and the U.S. This modular ELF-based malware facilitates tailored attacks across industries and even embeds itself into software packages to compromise other cybercriminals. A tax-themed phishing campaign, dubbed FLUX#CONSOLE, is deploying backdoor payloads to compromise systems in Pakistan. Threat actors employ phishing emails with double-extension files masquerading as PDFs.

Dec 13, 2024

Cyware Weekly Threat Intelligence, December 09–13, 2024

Cybercrime’s web of deception unraveled in South Korea as authorities dismantled a fraud network responsible for extorting $6.3 million through fake online trading platforms. Dubbed Operation Midas, the effort led to the arrest of 32 individuals and the seizure of 20 servers. In a significant move to combat surveillance abuses, the U.S. defense policy bill for 2025 introduced measures to shield military and diplomatic personnel from commercial spyware threats. The legislation calls for stringent cybersecurity standards, a review of spyware incidents, and regular reporting to Congress. The subtle art of deception found a new stage with a Microsoft Teams call, as attackers used social engineering to manipulate victims into granting remote access. By convincing users to install AnyDesk, they gained control of systems, executing commands to download the DarkGate malware. Russian APT Secret Blizzard has resurfaced and used the Amadey bot to infiltrate Ukrainian military devices and deploy their Tavdig backdoor. In a phishing spree dubbed "Aggressive Inventory Zombies (AIZ)," scammers impersonated brands like Etsy, Amazon, and Binance to target retail and crypto audiences. Surveillance has reached unsettling new depths with the discovery of BoneSpy and PlainGnome, two spyware families linked to the Russian group Gamaredon. Designed for extensive espionage, these Android malware tools track GPS, capture audio, and harvest data. A new Android banking trojan has already caused havoc among Indian users, masquerading as utility and banking apps to steal sensitive financial information. With 419 devices compromised, the malware intercepts SMS messages, exfiltrates personal data via Supabase, and even tricks victims into entering details under the pretense of bill payment. Iranian threat actors have set their sights on critical infrastructure, deploying IOCONTROL malware to infiltrate IoT and OT/SCADA systems in Israel and the U.S.

Dec 6, 2024

Cyware Weekly Threat Intelligence, December 02–06, 2024

NIST sharpened the tools for organizations to measure their cybersecurity readiness, addressing both technical and leadership challenges. The two-volume guidance blends data-driven assessments with managerial insights, emphasizing the critical role of leadership in applying findings. The Manson Market, a notorious hub for phishing networks, fell in a sweeping Europol-led takedown. With over 50 servers seized and 200TB of stolen data recovered, the operation spanned multiple countries, including Germany and Austria. Russian APT group BlueAlpha leveraged Cloudflare Tunnels to cloak its GammaDrop malware campaign from prying eyes. The group deployed HTML smuggling and DNS fast-fluxing to bypass detection, targeting Ukrainian organizations with precision. Earth Minotaur intensified its surveillance operations against Tibetan and Uyghur communities through the MOONSHINE exploit kit. The kit, now updated with newer exploits, enables the installation of the DarkNimbus backdoor on Android and Windows devices. Cloudflare Pages became an unwitting ally in the sharp rise of phishing campaigns, with a staggering 198% increase in abuse cases. Cybercriminals exploited the platform's infrastructure to host malicious pages, fueling a surge from 460 incidents in 2023 to over 1,370 by October 2024. DroidBot has quietly infiltrated over 77 cryptocurrency exchanges and banking apps, building a web of theft across Europe. Active since June 2024, this Android malware operates as a MaaS platform, enabling affiliates to tailor attacks. Rockstar 2FA, a phishing platform targeting Microsoft 365 users, has set the stage for large-scale credential theft. With over 5,000 phishing domains launched, the platform is marketed on Telegram. The Gafgyt malware is shifting gears, targeting exposed Docker Remote API servers through legitimate Docker images, creating botnets capable of launching DDoS attacks.