Cyware Weekly Threat Intelligence, May 12–16, 2025

Weekly Threat Briefing • May 16, 2025
Weekly Threat Briefing • May 16, 2025
Smart heat pumps are getting a cybersecurity upgrade. Under the U.K.'s new Smart Secure Electricity Systems Programme, devices up to 45 kW must now comply with ETSI EN 303 645 standards. The move aims to protect both consumers and the national grid from potential cyber threats. Blockchain just got a rulebook refresh. The BSSC has rolled out four new standards. Together, they offer a structured approach to tackling security across blockchain infrastructures.
APT37 is back with another Dropbox-powered espionage play. In Operation: ToyBox Story, the North Korean group used fake national security event invites to deliver RoKRAT malware via ZIP archives. Two ransomware gangs, BianLian and RansomExx, are now exploiting the same SAP NetWeaver vulnerability as Chinese APTs. Using CVE-2025-31324, the attackers deliver PipeMagic alongside privilege escalation flaws like CVE-2025-29824. Swan Vector is the latest addition to a string of APT campaigns zeroing in on East Asia’s research and engineering sectors.
OtterCookie is getting smarter with every version. The North Korea-linked group WaterPlum is actively using the malware to breach financial institutions and crypto platforms worldwide. A PowerShell script posing as a helpful utility is the entry point for Chihuahua Stealer. This .NET-based info-stealer uses scheduled tasks for persistence and grabs browser credentials and crypto wallet data. Not every AI tool on Facebook is what it claims to be. Threat actors are luring users with fake content-generation apps, pushing Noodlophile malware to tens of thousands of victims.