Cyware Weekly Threat Intelligence - March 07–11

Weekly Threat Briefing • March 11, 2022
Weekly Threat Briefing • March 11, 2022
The Good
Data centers are lucrative targets for cybercriminals. Hence, the risk of breaches and other attacks is quite tall. The NCSC issued new guidance for owners and users of data centers to stay safe from such threats. A REvil affiliate was extradited to the U.S. to stand trial for charges related to the Kaseya attack. Let this be a lesson to threat actors that there are dire consequences for their actions.
The Bad
The Lapsus$ ransomware gang is claiming victims left, right, and center. After NVIDIA, it reportedly attacked and pilfered data from Samsung, MercadoLibre, and Vodafone, in disparate attacks. Ransomware gangs have heightened efforts as law enforcement agencies released advisories warning about the attack techniques and tools used by Ragnar Locker and Conti ransomware groups. Emotet is operating at full throttle as it has infected hundreds of thousands of devices since November 2021.
New Threats
As geopolitical tensions rise, cybercriminals are launching different kinds of attacks to exploit ongoing conflicts. In one such instance, they were found launching three unique DDoS attacks against Ukraine. One of them used the new Zhadnost botnet. Emotet is disseminating in a fresh campaign that uses over 500 Excel files. Researchers spotted a set of seven vulnerabilities, dubbed Access:7, in PTC’s Axeda agent.