News – November 2021


  • Interpol: More than 1,000 arrests and USD 27 million intercepted in massive financial crime crackdown

    November 26, 2021

    LYON, France – An operation coordinated by INTERPOL codenamed HAECHI-II saw police arrest more than 1,000 individuals and intercept a total of nearly USD 27 million of illicit funds, underlining the global threat of cyber-enabled financial crime. Taking place over four months from June to September 2021, Operation HAECHI-II brought together specialized police units from 20 ...

  • IKEA email systems hit by ongoing cyberattack

    November 26, 2021

    IKEA is battling an ongoing cyberattack where threat actors are targeting employees in internal phishing attacks using stolen reply-chain emails. A reply-chain email attack is when threat actors steal legitimate corporate email and then reply to them with links to malicious documents that install malware on recipients’ devices. As the reply-chain emails are legitimate emails from a ...

  • RATDispenser downloader delivers a ‘silent threat’ that wants to steal your passwords

    November 26, 2021

    Cyber criminals are using a new JavaScript downloader to distribute eight different kinds of remote access Trojan (RAT) malware and information-stealing malware in order to gain backdoor control of infected Windows systems, as well as steal usernames, passwords and other sensitive data. The downloader has been detailed by cybersecurity researchers at HP Wolf Security, who’ve called ...

  • IT threat evolution Q3 2021

    November 26, 2021

    Last March, Kaspersky researchers reported a WildPressure campaign targeting industrial-related entities in the Middle East. While tracking this threat actor in spring 2021, they discovered a newer version. It contains the C++ Milum Trojan, a corresponding VBScript variant and a set of modules that include an orchestrator and three plugins. This confirms Kaspersky previous assumption ...

  • BazarLoader Adds Compromised Installers, ISO to Arrival and Delivery Vectors

    November 25, 2021

    We continue monitoring the campaigns using information stealer BazarLoader (detected by Trend Micro as TrojanSpy.Win64.BAZARLOADER, TrojanSpy.Win64.BAZARLOADER, and Backdoor.Win64.BAZARLOADER). While InfoSec forums have noted the spike in detections during the third quarter, we noticed two new arrival mechanisms included in the existing roster of delivery techniques that malicious actors abused for data theft and ransomware. One of ...

  • UK government transport website caught showing porn

    November 25, 2021

    A UK Department for Transport (DfT) website was caught serving porn earlier today. The particular DfT subdomain behind the mishap, on most days, provides vital DfT statistics for the public and the department’s business plan. Racy traffic ahead The UK DfT’s charts.dft.gov.uk website was seen serving porn today, as confirmed by BleepingComputer. Read more… Source: Bleeping Computer  

  • CronRAT, Linux remote access trojan hides behind the invalid date, February 31.

    November 25, 2021

    Security researchers have discovered a new remote access trojan (RAT) for Linux that keeps an almost invisible profile by hiding in tasks scheduled for execution on a non-existent day, February 31st. Dubbed CronRAT, the malware is currently targeting web stores and enables attackers to steal credit card data by deploying online payment skimmers on Linux servers. Characterized ...

  • ICCECIP 2021 international scientific conference

    November 25, 2021

    The ICCECIP 2021 – 3rd International Conference on Central European Critical Infrastructure Protection was held this year on 15th November. This year conference was the third after the 2019 and 2020 ones. This event as part of the Hungarian Science Festival was organized by the Bánki Donát Faculty of Mechanical and Safety Engineering of the ...

  • Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure

    November 25, 2021

    Security researchers are warning biomanufacturing facilities around the world that they are being targeted by a sophisticated new strain of malware, known as Tardigrade. The warning comes from the non-profit Bioeconomy Information Sharing and Analysis Center (BIO-ISAC) which revealed that at least two large facilities working on manufacturing bio-drugs and vaccines have been hit by the ...

  • Attackers Actively Target Windows Installer Zero-Day

    November 24, 2021

    Attackers are actively exploiting a Windows Installer zero-day vulnerability that was discovered when a patch Microsoft issued for another security hole inadequately fixed the original and unrelated problem. Over the weekend, security researcher Abdelhamid Naceri discovered a Windows Installer elevation-of-privilege vulnerability tracked as CVE-2021-41379 that Microsoft patched a couple of weeks ago as part of its ...

  • Apple sues Israeli spyware firm NSO Group

    November 24, 2021

    Apple is suing Israeli spyware firm NSO Group and its parent company for allegedly targeting iPhone users with a hacking tool. NSO’s Pegasus software can infect both iPhones and Android devices, allowing operators to extract messages, photos and emails, record calls and secretly activate microphones and cameras. NSO Group said its tools were made to target terrorists ...

  • The dangers of “connected” healthcare: predictions for 2022

    November 23, 2021

    For a second consecutive year, the time for Kaspersky to make its predictions for the healthcare sector comes amid the global COVID-19 pandemic. Unfortunately, the virus still dominates most aspects of our lives, and, of course, the pandemic remained the biggest and most-discussed topic in medicine. Part of our predictions last year were based on the ...

  • TSA makes changes to new cyber requirements after industry feedback

    November 23, 2021

    The Transportation Security Administration is softening the deadlines on new cybersecurity requirements for major passenger and freight rail operators, as the agency’s leader said it learned from efforts earlier this year to begin regulating the cybersecurity of the pipeline sector. TSA is expected to issue the new security directives for major railroad and rail transit entities ...

  • Cyberthreats to financial organizations in 2022

    November 23, 2021

    A look back on the year 2021 and what to expect in 2022 First of all, we are going to analyze the forecasts we made at the end of 2020 and see how accurate they were. Then we will go through the key events of 2021 relating to attacks on financial organizations. Finally, we will make ...

  • Over nine million Android devices infected by info-stealing trojan

    November 23, 2021

    A large-scale malware campaign on Huawei’s AppGallery has led to approximately 9,300,000 installs of Android trojans masquerading as over 190 different apps. The trojan is detected by Dr.Web as ‘Android.Cynos.7.origin’ and is a modified version of the Cynos malware designed to collect sensitive user data. The discovery and report come from researchers at Dr. Web AV, who ...