Cyware Weekly Threat Intelligence - January 30–03

Weekly Threat Briefing • February 3, 2023
Weekly Threat Briefing • February 3, 2023
The U.S. government is leaving no stone unturned to protect critical infrastructures from the risk of cyber attacks. In the latest development, the CISA is establishing a new office to tackle supply chain security issues. The task force will be composed of the federal government and industry representatives from the Information and Communications Technology (ICT) sector. Meanwhile, Singapore and European Union have signed an agreement to drive collaboration across different digital platforms, including improving their cybersecurity standards.
Beware! Emails and SMS messages that convincingly look like communications from well-known brands are being sent to users in a widespread BEC campaign that is active since April 2021. Attributed to a newly found threat actor called Firebrick Ostrich, the campaign is primarily focused on organizations in the U.S. That’s not all. Another BEC campaign is underway that redirects users to a fraudulent Microsoft phishing page. In other news, a car retailer and a school in Guildford County in the U.K. were targets of separate ransomware attacks that impacted the sensitive information of individuals.
A series of new data-wiping malware such as SwiftSlicer and Nikowiper came to light this week as researchers unveiled the recent activities of the Russia-based Sandworm APT group. Variants of several known malware threats also emerged, with one of them coming from the LockBit ransomware operators. Called LockBit Green, the ransomware is designed to target cloud-based services. Three new variants of the Prilex PoS malware were also found using sophisticated methods to steal credit card information.