HomeCybersecurity NewsNews roundup February 5, 2024
February 5, 2024

News roundup February 5, 2024

SAN MATEO, CA, February 5, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Brought to you by NetworkTigers.

  1. VajraSpy malware discovered hiding in Google Play apps
  2. Updated FritzFrog botnet exploits internal devices via Log4j
  3. US government shuts down botnet operated by Volt Typhoon Chinese threat actors
  4. CISA orders federal agencies to disconnect Ivanti VPNs
  5. Telegram cybercrime marketplaces make dangerous dark web tools publicly accessible
  6. DarkGate malware spreading through Microsoft Teams group chats
  7. Joe Biden deepfake robocalls signal new era of AI election interference
  8. Ransomware payments drop as victims no longer pay up
  9. US National Security Agency purchasing American web browsing info without a warrant
  10. Microsoft discloses how Russian hackers breached Exchange Online accounts
  11. More cybersecurity news

VajraSpy malware discovered hiding in Google Play apps

12 Android apps, six of which were available for download via the Google Play store, have been found to harbor VajraSpy, a remote access trojan. Most malicious apps are disguised as messaging software, while others pose as news apps. The apps available on Google Play have been downloaded around 1,400 times, while the number of downloads through third-party marketplaces is unknown. VajraSpy mainly focuses on data theft and can gather and exfiltrate call logs and texts and even extract messages from encrypted apps such as WhatsApp and Signal. It can record phone calls, exfiltrate images, audio, and documents, and activate a device’s camera. Read more.

Updated FritzFrog botnet exploits internal devices via Log4j

Two years after the vulnerability in Log4j was discovered, threat actors are still capitalizing on unpatched instances to find their way into targeted networks. FritzFrog is a botnet that hopes to capitalize on admins not updating internal systems because they aren’t connected to the internet. FritzFrog begins its attack by brute-forcing its way into a network through servers with weak password protections. Once network access has been gained, it scans the system for targets vulnerable to a Log4Shell attack. FritzFrog is highly sophisticated and has also been upgraded with a module that kills unrelated malware within a system and new features that take advantage of victims running Linux. Read more.

US government shuts down botnet operated by Volt Typhoon Chinese threat actors

A botnet made of hundreds of compromised small office and home office routers has been shut down by the US government to lessen the impact of the Chinese state-sponsored threat actor group Volt Typhoon. The KV-botnet is part of an ongoing threat that, according to CISA, sees Chinese hackers “burrowing deep into our critical infrastructure to be ready to launch destructive cyber attacks” on behalf of the country’s government. In a statement, the Department of Justice said, “the vast majority of routers that comprised the KV-botnet were Cisco and NetGear routers that were vulnerable because they had reached ‘end of life’ status.” Volt Typhoon is notorious for using legitimate tools and living-off-the-land techniques to remain undetected over long periods. Read more.

CISA orders federal agencies to disconnect Ivanti VPNs

CISA has given federal agencies until Saturday, February 3rd, to disconnect Ivanti Connect Secure and Policy Secure VPN appliances. The devices are currently under active attack, with hackers chaining an authentication bypass and a command injection security flaw to breach targeted systems. Ivanti also recently warned of an additional zero-day flaw under attack that allows threat actors to bypass authentication on a number of their products. Agencies are ordered to “disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure solution products,” maintain vigilance as they hunt for signs of intrusion, completely refresh their configurations, and follow several other steps while reporting to CISA at each stage. Read more.

Telegram cybercrime marketplaces make dangerous dark web tools publicly accessible

Telegram has become an epicenter for cybercriminals looking to grab inexpensive kits or exchange information with hackers that they can use to launch cyberattacks. The cross-platform messaging app prioritizes privacy and is lightly moderated, making it an attractive tool for illegal activity and sharing content previously only accessible via invite-only dark web forums. According to a researcher at Guardio Labs, the app has “transformed into a bustling hub where seasoned cybercriminals and newcomers alike exchange illicit tools and insights, creating a dark and well-oiled supply chain of tools and victims’ data.” The resources needed to create phishing campaigns can be purchased cheaply from other Telegram users, and in some cases, they’re even offered for free. Read more.

DarkGate malware spreading through Microsoft Teams group chats

Microsoft Teams group chats are being leveraged against users in a phishing campaign installing DarkGate malware payloads onto their systems. AT&T Cybersecurity researchers have determined that the attackers appear to be using compromised user accounts to send out malicious invites. Once a request is accepted, the victim is tricked into downloading a file containing malware that connects to a command-and-control server at hgfdytrywq[.]com, part of DarkGate’s infrastructure. AT&T Cybersecurity recommends that users disable External Access in Microsoft Teams unless “absolutely necessary for daily business use.” DarkGate malware has seen a rise in usage over the last few months, which is believed to be directly related to authorities’ disruption of the Qakbot botnet. Read more.

Joe Biden deepfake robocalls signal new era of AI election interference

New Hampshire voters have been receiving phone calls that sound like Joe Biden instructing them not to show up to the primary polls as it “enables the Republicans in their quest to elect Donald Trump.” The phone calls show up as originating from a number belonging to the former New Hampshire Democratic state party chair in what looks to be the first AI-generated audio campaign to target American voters. Politicians, given the extraordinary amount of accessible audio of their speech and their ability to influence, are in the deepfake crosshairs. The origin of the phone calls and the exact motive behind them remains unclear, although the consensus is that this will be far from the last such spoof US citizens see as the 2024 election looms large. Read more.

Ransomware payments drop as victims no longer pay up

Research from Coveware indicates that the number of ransomware victims choosing to give in to attacker demands has dropped to a record low of 29%. Coveware cites “better preparedness by organizations, a lack of trust towards cybercriminals promising not to publish stolen data, and legal pressure in some regions where paying a ransom is illegal” as driving forces behind the decline. The dollar amount of ransom payments has also been dropping. In the fourth quarter of 2023, the average payout dropped by 33% compared to the third. The data may imply that ransomware is becoming less effective, although threat actors are sure to continue to be agile and perhaps even more insidious in the face of opposition. Read more.

US National Security Agency purchasing American web browsing info without a warrant

According to the US National Security Agency’s director, the agency purchases massive amounts of Americans’ web browsing information from data brokers, sidestepping the need for a warrant and resulting in a refreshed debate regarding the agency’s proclivity for spying on US citizens. US government agencies need to secure a warrant to collect private data from a telecom, but some have been taking advantage of a loophole in which they are free to purchase said data from companies that offer it for sale. The disclosure comes as the FTC cracks down on data brokers that sell information without user consent, possibly exposing a legal gray area that may find its way into the courts. Read more.

Microsoft discloses how Russian hackers breached Exchange Online accounts

Microsoft has revealed that the recent breach of the company’s executive email accounts by Russian threat actor group Midnight Blizzard was carried out via password spraying. According to a statement from Microsoft, “the actor tailored their password spray attacks to a limited number of accounts, using a low number of attempts to evade detection and avoid account blocks based on the volume of failures.” One account was reportedly a “legacy, non-production test tenant account” that did not have MFA enabled but did have privileged access to Microsoft’s “corporate environment.” The company goes on to say that they have identified the same hackers using similar tactics against other organizations, with security researchers believing the recently breached Hewlett Packard Enterprises to be one such target. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

What do you think?

Popular Articles