This is the GreyKeep Security Malware Roundup for August 29, 2023. Here’s a summary of what’s in this week’s edition:
Targets
MacOS Adobe ColdFusion MOVEit Transfer WinRAR Openfire XMPP Ivanti Sentry Roblox | Juniper SRX Cisco Nexus 3000/9000 (NX-OS) Citrix NetScaler Barracuda ESG EsafeNet Cobra DocGuard IoT devices |
Organizations
U.S. government Rust developers Roblox developers | Taiwan Hong Kong Metropolitan Police Service |
Threat Actors
CL0P (Russia) Carderbee (China) Evilnum (Russia) TradeTraitor (N. Korea) Lazarus (N. Korea) | FIN8 Lapus$ Evilnum Flax Typhoon (China) |
Malware / Ransomware
Korplug/PlugX Lazarus APT Whiffy Recon QuiteRAT | Luna Grabber LockBit 3.0 Kmsdx DarkGate |
Malware in the News
MacOS
Adobe
Cisco
- Cisco NX-OS Software Flaw Let Attacker Trigger a DoS Attack
- Cisco Nexus 3000 and 9000 Series Switches Flaw Let Attackers Trigger DoS Attack
Juniper
ManageEngine
Openfire
WinRAR
Citrix
Developers
- Over a Dozen Malicious npm Packages Target Roblox Game Developers
- Signs of Malware Attack Targeting Rust Developers Found on Crates.io
Government
Other Malware News
- Clop ransomware dominates ransomware space after MOVEit exploit campaign
- Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack
- Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates
- Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software
- China Unleashes Flax Typhoon APT to Live Off the Land, Microsoft Warns
- New “Whiffy Recon” Malware Triangulates Infected Device Location via Wi-Fi Every Minute
- Leaked LockBit 3.0 ransomware builder used by multiple threat actors
- Updated Kmsdx botnet targets IoT devices