Cyware Weekly Threat Intelligence - June 10–14

Weekly Threat Briefing • June 14, 2024
Weekly Threat Briefing • June 14, 2024
The FCC, in a decisive move, has greenlit a notice of proposed rulemaking that zeroes in on Border Gateway Protocol (BGP) security. The crux of the matter? Mandating the nine biggest U.S. broadband behemoths to concoct and uphold top-secret BGP security risk management blueprints. Meanwhile, in a dramatic turn of events, U.S. federal agents have swooped in and seized 70 domains tied to a cunning cryptocurrency investment scam. This elaborate ruse specifically targeted the Russian diaspora in New York, culminating in a staggering $5 million in victim losses nationwide.
ESET researchers have unearthed five campaigns zeroing in on Android users with trojanized apps, likely the handiwork of the Arid Viper APT group. These operations revolve around the deployment of a three-stage Android spyware dubbed AridSpy, targeting Egypt and Palestine. On another front, a newly surfaced North Korean threat actor, Moonstone Sleet, has turned its sights on the software supply chain. It is spreading malevolent npm packages through public open-source repositories. Meanwhile, the Kimsuky threat ensemble is exploiting a vulnerability in Microsoft Office's Equation Editor. This attack unfolds when an unwitting user opens a compromised Office document, setting off the equation editor to run a malicious script.
The Pakistan-linked threat group Cosmic Leopard has been running a long-term malware campaign known as Operation Celestial Force, targeting Windows, Android, and macOS devices. This campaign, active since at least 2018, utilizes several malware tools: GravityRAT, HeavyLift, and GravityAdmin. Separately, a significant XSS vulnerability has been identified in the SummerNote 0.8.18 WYSIWYG editor. This vulnerability allows attackers to embed harmful scripts into trusted applications or websites. Additionally, a new Agent Tesla RAT variant is targeting Spanish-speaking individuals via phishing emails posing as SWIFT transfer notifications from financial institutions.