Cyware Weekly Threat Intelligence, March 31–April 04, 2025

Weekly Threat Briefing • April 4, 2025
Weekly Threat Briefing • April 4, 2025
The EU is putting serious weight behind its digital ambitions. A €1.3 billion investment will fund cybersecurity and AI initiatives across the bloc from 2025 to 2027. Projects include the rollout of the EU Digital Identity Wallet, AI development hubs, and efforts to harden critical infrastructure. Canada’s privacy watchdog is giving organizations a way to think before they panic. A new online tool helps assess the risk of significant harm after a data breach, guiding users through questions about the sensitivity of exposed data and its potential misuse.
A fake research invite is the front for something far more invasive. Operation HollowQuill is targeting Russian academic and defense networks with booby-trapped PDFs that deploy Cobalt Strike. The Bybit breach didn’t end with the heist - it opened the floodgates. In the weeks following the crypto theft, nearly 600 phishing domains emerged, many impersonating the exchange or posing as refund services. Phishing lures dressed as tax documents are making the rounds again but this time with sharper teeth. Microsoft warns that campaigns tied to the RaccoonO365 platform are using QR codes, URL shorteners, and cloud services to deliver malware.
Cloudflare branding, Telegram tracking, and malware in disguise - this phishing campaign checks all the boxes. Hosted on legitimate Cloudflare platforms, fake DMCA takedown pages lure victims into downloading PDFs rigged to launch malware. Credit card skimming has moved beyond compromised websites. RolandSkimmer is targeting Windows users in Bulgaria through malicious browser extensions on Chrome, Edge, and Firefox. Microsoft Teams is being turned against the workplace. In a new campaign, attackers are sending phishing messages through Teams chats to deliver PowerShell-based malware.