Cyber Attacks Rock Ukraine and Russia

From command & control to data wiping malware, Ukraine is struggling with quite a bit of cyber threats since the start of Russia’s operation. When it comes to DDoS attacks both Russia and Ukraine are both having to defend themself. Internet sites in both countries have been seen going completely un-reachable during this event.

ABC News – Cyberattacks accompany Russian military assault on Ukraine – ABC News: https://abcn.ws/3IjbNmX

ZDNet – Flight tracker Flightradar24 crash caused by ‘international interest’ in Ukraine, Russia conflict: https://www.zdnet.com/article/flight-tracker-flightradar24-crash-caused-by-international-interest-in-ukraine-russia-conflict/

ZDNet – Ukraine Ministry of Defense confirms DDoS attack; state banks lose connectivity: https://www.zdnet.com/article/ukraine-ministry-of-defense-confirms-ddos-attack-state-banks-loses-connectivity/

Infosecurity Magazine – US and UK Warn of VPNFilter Successor “Cyclops Blink”: https://www.infosecurity-magazine.com/

Reuters – Ukraine computers hit by data-wiping software as Russia launched invasion: https://www.reuters.com/world/europe/ukrainian-government-foreign-ministry-parliament-websites-down-2022-02-23/

CNBC – Cyberattack hits Ukrainian banks and government websites: https://www.cnbc.com/2022/02/23/cyberattack-hits-ukrainian-banks-and-government-websites.html

CNN – Russian government websites mysteriously go dark as invasion continues: https://www.cnn.com/europe/live-news/ukraine-russia-news-02-24-22-intl/h_e0d16b404e39c4f6bbbb337fe2e4f1a1

Threat Group Sandworm Creates New Worries with Cyclops Blink Malware

A new malware threat named Cyclops Blink, which appears to replace Sandworm’s VPNFilter malware that was used against Ukraine in 2018, is targeting Watchguard firewalls to compromise, implement command and control, update the malware instance with more mods to possibly use for larger attacks and even more.

https://www.cisa.gov/uscert/ncas/alerts/aa22-054a

Info Stealer Banking Trojan Xenomorph Supposedly on Google Play

Info Stealer Banking Trojan Xenomorph Supposedly on Google Play. Targeting 56 banks in Europe and having over 50,000 installations.

#banking #android #google #trojan #informationtheft #cybercrime #cybersecurity

burnoutblusbolsteredblog.blogspot.com/2022/02/info-stealer-banking-trojan-xenomorph.html


49ers Dealing With Blackbyte Ransomware Cyber Attack

The San Francisco 49ers are dealing with a cyber attack from the ransomware as a service operation Blackbyte.

For more detail: https://www.bleepingcomputer.com/news/security/nfls-san-francisco-49ers-hit-by-blackbyte-ransomware-attack/

Malware Utilizing WSL As Its Attack Vector

A new style of malware uniquely set to compromise Windows OS via the Windows Subsystem for Linux (WSL), has been reported by researchers at Lumen’s Black Lotus Labs.

More detail here: https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/

NYU Disinformation Research Challenged and Defended

“Mozilla, MacArthur and Ford foundations unite to oppose Facebook ban on NYU disinformation research” via Jonathan Greig | ZDNet

“Multiple high-profile foundations and philanthropic organizations came together to criticize Facebook for shutting down the accounts of New York University (NYU) researchers investigating advertising disinformation on the platform.

The open letter was from the NetGain Partnership, which includes the Mozilla Foundation, Ford Foundation, John D. and Catherine T. MacArthur Foundation, the Omidyar Network and more. The group of foundations focus their work on fostering research into”..

More detail here: https://www.zdnet.com/article/mozilla-macarthur-and-ford-foundations-unite-to-oppose-facebook-ban-on-disinformation-research/

Patch Tuesday is Here

Ready or not, it’s patch time again:

“Point and Print Default Behavior Change” via MSRC : https://msrc-blog.microsoft.com/2021/08/10/point-and-print-default-behavior-change/

Microsoft: Security Updates for August: https://msrc.microsoft.com/update-guide/

Adobe: Security updates for Adobe Connect and Magento : https://helpx.adobe.com/security/security-bulletin.html

“Firefox 91 Introduces Enhanced Cookie Clearing” via Mozilla Security Blog : https://blog.mozilla.org/security/2021/08/10/firefox-91-introduces-enhanced-cookie-clearing/

“Snort rule update for Aug. 10, 2021 — Microsoft Patch Tuesday” via Snort Blog : https://blog.snort.org/2021/08/snort-rule-update-for-aug-10-2021.html

More Network Routers Actively Being Attacked

“Actively exploited bug bypasses authentication on millions of routers” via Sergiu Gatlan | Bleeping Computer

“Threat actors actively exploit a critical authentication bypass vulnerability impacting home routers with Arcadyan firmware to take them over and deploy Mirai botnet malicious payloads.

The vulnerability tracked as CVE-2021-20090 is a critical path traversal vulnerability (rated 9.9/10) in the web interfaces of routers with Arcadyan firmware that could allow unauthenticated remote attackers to bypass”….

More detail here: https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/

MosaicLoader Malware Hiding in Search Ads

“This password-stealing Windows malware is distributed via ads in search results” via Danny Palmer | ZDNet

“MosaicLoader can be used to steal passwords, install cryptocurrency miners and deliver trojan malware warn researchers, who say those behind it want to sell access to Windows PCs on to other cyber criminals.”

More detail: https://www.zdnet.com/article/this-password-stealing-windows-malware-is-distributed-via-ads-in-search-results/