Cyware Weekly Threat Intelligence - October 18–22

Weekly Threat Briefing • October 22, 2021
Weekly Threat Briefing • October 22, 2021
The Good
While the enemy of my enemy cannot always be a friend, it’s always fun to watch hackers pitting against each other. In one such case, REvil has been forced to close up shop once more! We always love bringing indictment news to you. In today’s episode of arrests, the Dutch Police incarcerated nine bank support fraudsters and the South African Police arrested eight suspects for siphoning off funds from romance scam victims.
The Bad
Cookie monsters have been crushed! Some 4,000 YouTube creators were targeted with cookie-stealing malware in a phishing campaign that spanned for two years, discovered Google TAG team. The week has been gloomy, but especially so for the Argentinian government, as a hacker gained access to the National Registry of Persons and stole ID cards of the entire population. While we hope that no medical facilities fall prey to malicious purposes, this time an insider breach by a former employee of the University Hospital Newark impacted the sensitive info of thousands of individuals.
New Threats
The week presented us with two new distinct espionage campaigns. While one was conducted by TA551, the other perpetrator is yet unknown and has targeted Southeast Asia. Academic researchers from the U.S. discovered a new fingerprint capturing attack called Gummy Browsers. They have warned that the attack is really easy to perform and can have severe implications. The financially motivated TA505 gang has been propagating a new FlawedGrace RAT strain.