Cyware Monthly Threat Intelligence

Monthly Threat Briefing • March 2, 2023
Monthly Threat Briefing • March 2, 2023
Counterterrorism and confronting new challenges in cyberspace is the only way forward. In the wake of the newest offensive cyber operations and national security threats against the U.S. and its allies, the DoJ has introduced the Disruptive Technology Strike Force. With increasing attempts to compromise IoT devices, NIST has picked Ascon as the new cryptography standard for small IoT devices. Get ready to witness post-quantum cryptography guidance in the first, much anticipated National Cybersecurity Strategy from the White House Office of the National Cyber Director.
With organizations striving to detect, track, and take down phishing and malware attack attempts, the DDoS landscape also continues to evolve. Last month, security analysts took the wraps off of a DDoSaaS activity dubbed Passion, which may have an inimitable connection with Russian hacking groups. Meanwhile, Vice Society, which also happens to have a Russian connection, claimed two victims in the education sector in the U.S. and the U.K. Besides, there were several data breach incidents this month.
Given all the hype around ChatGPT, cybercriminals are not far from exploiting it for disruptive attacks. A case in point is cybercriminals abusing the platform through fake Windows desktop clients and bogus payment portals. Additionally, three ransomware groups, namely ESXiArgs, Royal Ransomware, and BlackBasta, were found crippling ESXi servers. Moving on, we have two BEC scammer groups baiting users in at least 13 languages, such as Norwegian, Polish, Portuguese, and Spanish.