Cyware Weekly Threat Intelligence - March 27–31

Weekly Threat Briefing • March 31, 2023
Weekly Threat Briefing • March 31, 2023
To beat a hacker, you have to think like one! This is why the NCA, along with several international law enforcement agencies, have come up with an idea to crack down on wannabe cybercriminals. The agency has set up multiple fake cybercrime markets as part of the Operation PowerOFF project to gather information on cybercriminals. Yet another new FDA cybersecurity guideline has been issued for organizations in the healthcare sector and it is about enhancing the security of internet-connected devices.
The cyber community also witnessed pernicious threats, all of which led to the exposure of sensitive data. While Toyota Italy had inadvertently left access to its marketing tools exposed for more than a year due to a flaw in its website, NCB Management Services revealed that the personal information of over 500,000 users was stolen after threat actors gained unauthorized access to its systems. In the latest update on the infamous GoAnywhere hacking incident, Procter & Gamble and the U.K. Pension Protection Fund admitted to falling victim to the attack pulled off by the Cl0p ransomware gang.
Moving on to new threats, researchers warned of a new swiss-army-knife toolset for cybercriminals that can be used to harvest private information from 18 cloud services. Named AlienFox, the toolset is being sold on a private Telegram channel. New variants of the IcedID trojan have also been spotted in multiple phishing campaigns since February. It is touted that one of them, tracked as Lite, is being used alongside Emotet. DBatLoader also made a comeback, targeting various businesses in European countries with Remcos and Formbook trojans.