SAN MATEO, CA, December 4, 2023 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Brought to you by NetworkTigers.
- Apple issues emergency updates for iOS, macOS, and Safari
- FjordPhantom Android malware uses virtualization to fly under the radar
- North Korea’s Lazarus Group has made off with $3 billion in crypto
- New DJVU ransomware variant posing as freeware
- Okta breach led to exposure of customer support data
- Key individuals behind ransomware groups arrested in Ukraine
- BlackCat ransomware gang attacks healthcare company Henry Schein
- US and global partners release new guidelines for secure AI system development
- MacOS users targeted with fake browser updates
Apple issues emergency updates for iOS, macOS, and Safari
Apple has sent an emergency security update to iOS, macOS, and Safari users that addresses flaws under active exploitation. CVE-2023-42916 is an “out-of-bounds read issue that could be exploited to leak sensitive information when processing web content.” CVE-2023-42917 is a “memory corruption bug that could result in arbitrary code execution when processing web content.” Apple has not provided further details on the nature of the exploitation, “but previously disclosed zero-days in iOS have been used to deliver mercenary spyware targeting high-risk individuals, such as activists, dissidents, journalists, and politicians.” Read more.
FjordPhantom Android malware uses virtualization to fly under the radar
FjordPhantom, a new Android malware discovered by researchers at Promon, has been observed using virtualization to “run malicious code in a container and evade detection.” Spread through emails, texts, and messaging apps, the malware’s malicious code is hidden in what are purported to be legitimate banking apps. However, the fraudulent software is designed to steal banking credentials and perform “on-device fraud.” To stay hidden, FjordPhantom “incorporates a virtualization solution from open-source projects to create a virtual container on the device without the user knowing.” On an Android device, multiple apps can run within isolated environments called containers. FjordPhantom creates a container to inject its malicious code into a victim’s banking app while appearing as part of Android’s “trusted process.” Read more.
North Korea’s Lazarus Group has made off with $3 billion in crypto
Over the last six years, North Korea’s Lazarus Group has stolen an estimated $3 billion in cryptocurrency, with most of the funds going directly to supporting the country’s military and missile programs. Sanctions placed on the country have generated a highly sophisticated state-sponsored cybercrime organization, with high-ranking government officials and hackers having privileged access to resources and information that is withheld from the rest of North Korea’s population. A new report from Recorded Future highlights the nation’s lucrative cybercrime arm. It came out as the US Treasury Department placed sanctions on a virtual currency mixer called Sinbad, a highly favored tool used by Lazarus Group to launder stolen funds. Read more.
New DJVU ransomware variant posing as freeware
A ransomware variant called DJVU has a new strain codenamed Xaro. The variant is distributed under the guise of legitimate freeware. However, opening the file “leads to the execution of a supposed installer binary for a PDF writing software called CutePDF that, in reality, is a pay-per-install malware downloader service known as PrivateLoader.” PrivateLoader can fetch several stealer and loader malware types, and the goal of this campaign seems to be to exfiltrate sensitive information for double extortion schemes while using different payloads to get through victims’ security blockers. Read more.
Okta breach led to exposure of customer support data
A breach of Okta’s Help Center environment has resulted in data theft associated with its customer support systems. Okta has stated that the threat actor also “downloaded a report that contained the names and email addresses of all Okta customer support system users.” While Okta says that 99.6% of the users affected only had their name and email address exposed, data stolen from some individuals may also include their “username, company name, user type, address, last password change/reset, role, phone number, mobile number, time zone, and SAML Federation ID.” Read more.
Key individuals behind ransomware groups arrested in Ukraine
Individuals associated with LockerGoga, MegaCortex, and Dharma ransomware families have been arrested in Ukraine following a coordinated law enforcement operation involving France, Germany, the Netherlands, Norway, Switzerland, Ukraine, and the US. “According to a statement from Europol, “on November 21, 30 properties were searched in the regions of Kyiv, Cherkasy, Rivne, and Vinnytsia, resulting in the arrest of the 32-year-old ringleader. Four of the ringleader’s most active accomplices were also detained.” The individuals are believed to have affected more than 1,800 victims across 17 countries since 2019. Read more.
BlackCat ransomware gang attacks healthcare company Henry Schein
Henry Schein, a prominent American healthcare company, has been hit this month by the BlackCat ransomware gang, making it the second attack on the organization in two months. BlackCat added Henry Schien to its leak site, claiming to have stolen 35 terabytes of data. The gang also claims that they “re-encrypted the company’s devices after negotiations faltered towards the end of October while Henry Schein was on the verge of restoring its systems,” bringing the total number of times the group encrypted the company’s data to three. BlackCat is releasing “a portion of their internal payroll data and shareholder folders,” supposedly in response to Henry Schein’s unwillingness to negotiate. Read more.
US and global partners release new guidelines for secure AI system development
The US, the UK, and 16 other countries have published new guidelines for developing secure AI systems to increase the cybersecurity levels of AI and ensure that the technology is developed safely. CISA describes the new guidelines as an approach that “prioritizes ownership of security outcomes for customers, embraces radical transparency and accountability, and establishes organizational structures where secure design is a top priority.” The idea is to make cybersecurity an “essential precondition of AI system safety” and install guardrails to address potential societal harms. Read more.
MacOS users targeted with fake browser updates
A fake browser update campaign, ClearFake, has widened its net and is now targeting Apple computers with Atomic Stealer malware. Previously only affecting Windows users, the ClearFake campaign employed malicious Chrome update prompts launched from compromised websites. Researchers at Malwarebytes discovered that the update is now doing the same to Safari users. Atomic Stealer is malware offered as a service to criminals for $1,000 a month. It can steal “passwords, cookies, and credit cards stored in browsers, local files, data from over 50 cryptocurrency extensions, and keychain passwords.” Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles brought to you by NetworkTigers
