Cyware Weekly Threat Intelligence, February 24–28, 2025

Weekly Threat Briefing • Feb 28, 2025
This website uses cookies and similar technologies to provide essential functionality and improve your experience. Some features, such as demo scheduling and chat support, require marketing cookies to function. By clicking "Accept All", you consent to all cookies. Alternatively, you can customize your preferences, but note that declining marketing cookies will limit certain website features.
Weekly Threat Briefing • Feb 28, 2025
Amid the relentless tide of cyber threats, some positive strides are being made to fortify the digital ecosystem. OpenSSF has introduced the Open Source Project Security (OSPS) Baseline, a structured set of best practices designed to help developers mitigate risks and align with regulations like the EU’s Cyber Resilience Act and frameworks like NIST’s Secure Software Development Framework. Meanwhile, vlt has upped supply chain security in the JavaScript ecosystem with reproduce, a new tool that verifies whether npm packages can be faithfully rebuilt from their source code. This initiative marks crucial progress in securing the foundations of open-source development.
Cyber threats are escalating, with the Vo1d botnet infecting 1.6 million Android TV devices across 226 nations, enabling ad fraud and illegal proxy services. Meanwhile, GitVenom is deceiving gamers and crypto investors with hundreds of fake GitHub repositories, distributing stealers, RATs, and clipboard hijackers, netting attackers 5 BTC. On the espionage front, Lotus Blossom is targeting government and telecom sectors in the Philippines, Vietnam, Hong Kong, and Taiwan, using the Sagerunex backdoor and leveraging Dropbox, Twitter, and Zimbra webmail for covert operations.
This week, new threats were also found propagating through GitHub, and vulnerabilities in Windows and WordPress. Over 1,100 rogue GitHub repositories spread Redox Stealer, stealing crypto wallets, browser cookies, and gaming credentials while promising game mods and cracked software. Meanwhile, LCRYX ransomware has resurfaced, encrypting Windows files, disabling security tools, and damaging the Master Boot Record (MBR) to pressure victims into paying a $500 Bitcoin ransom. Lastly, a critical WordPress flaw in the Essential Addons for Elementor plugin exposed over two million sites to XSS attacks, phishing, and malware distribution via malicious URL parameters.