Cyware Weekly Threat Intelligence - March 13–17

Weekly Threat Briefing • March 17, 2023
Weekly Threat Briefing • March 17, 2023
This week, the CISA launched a pilot program to help critical infrastructure organizations deal with ransomware threats. Created under the purview of recent incident reporting legislation, and in collaboration with the FBI, the program will be used to warn organizations about the vulnerabilities lurking in their systems and software, along with the remedies to reduce the impacts of ransomware attacks. Meanwhile, the NSA and the SEC also released two different cybersecurity guidelines in an effort to improve the security posture of organizations in several critical sectors.
Remember the GoAnywhere MFT zero-day vulnerability that the Cl0p ransomware group had exploited to compromise over 130 organizations? This week, a data security firm confirmed that it was among those affected companies. Meanwhile, the LockBit group has set a ransom payment deadline for a SpaceX supplier following which it plans to auction the stolen 3,000 proprietary schematics of SpaceX. Besides these, researchers spotted a wave of phishing attacks that capitalized on the recent crisis at SVB to target its customers.
Coming to new threats, researchers reported the first-ever Dero cryptojacking operation that was orchestrated against exposed Kubernetes clusters. In separate news, Microsoft warned of high-volume AiTM attacks facilitated by a phishing kit from DEV-1101. In addition to these, several new malware, GoatRAT, HinataBot, and dotRunpeX to name a few, were uncovered this week in different cyberespionage campaigns across the globe.