Cyware Weekly Threat Intelligence - November 08–12

Weekly Threat Briefing • November 12, 2021
Weekly Threat Briefing • November 12, 2021
The Good
The biggest news of the week comes in the form of law enforcement busting REvil. Five individuals were arrested on different charges related to REvil and millions of dollars of ransom payments were seized. In another such bold move, the U.S. Treasury announced sanctions on the Chatex cryptocurrency exchange for aiding and abetting ransom payments.
The Bad
No matter how much joy these developments have brought us this week, it is time to face the music. In a new wave of assaults, Cl0p ransomware has started making headlines by abusing an RCE flaw in a software made by SolarWinds. Ransomware gangs have become extremely sophisticated and relentless. After attacking thousands of systems of MediaMarkt, the Hive ransomware gang has demanded a whopping $240 million in ransom. This week, another DeFi platform fell victim to a crypto theft incident. The firm lost around $55 million worth of assets.
New Threats
Is SquirrelWaffle going to be the new Emotet? Researchers say so, as akin to Emotet, SquirrelWaffle is being used to launch huge malspam campaigns. One of those campaigns was found deploying Qakbot. With courage running in their evil veins, hackers spoofed Proofpoint to lure targets into giving up their Office 365 and Gmail credentials. In other news, BazarBackdoor was revealed targeting Windows 10 in a new phishing campaign.