Cyware Weekly Threat Intelligence - September 09–13

Weekly Threat Briefing • September 13, 2024
Weekly Threat Briefing • September 13, 2024
The U.K government has elevated data centers to a new level of importance, officially designating them as critical national infrastructure - ensuring these digital fortresses get the protection and support they need during crises. Choosing secure tech just got easier: the FCC is introducing a cybersecurity labeling program, helping consumers spot products that meet strict security standards, just like ENERGY STAR does for energy efficiency.
An innocent-looking Excel file hides a malicious secret: exploiting an old Microsoft vulnerability to deploy the stealthy Remcos RAT, giving attackers remote access and dodging traditional security defenses across sectors worldwide. Iran's OilRig is making waves again, targeting Iraqi government networks with two new malware strains, Veaty and Spearal, designed to harvest files and execute PowerShell commands. Crimson Palace, a trio of Chinese hacker clusters, has quietly infiltrated Southeast Asian governments, using their latest weapon, Tattletale malware, to steal sensitive data and authentication keys.
More than 1.3 million Android TV streaming boxes have fallen victim to the Vo1d backdoor, giving attackers full control and spreading infections across 200 countries. Banking customers in Central Asia are caught in the crosshairs of Ajina.Banker, a sneaky Android malware that’s spreading through Telegram channels disguised as trusted apps, siphoning off sensitive data for financial gain. Hadooken malware is taking Linux systems by storm, targeting WebLogic servers to drop cryptominers and Tsunami malware, exploiting weak passwords and erasing traces to ensure its silent persistence across compromised networks.