• Skip to primary navigation
  • Skip to main content
GreyKeep Security logo

GreyKeep Security

Expert security for an evolving digital age

  • Services
  • Our Approach
  • Blog
  • About
  • Contact Us
  • Show Search
Hide Search

Weekly Malware Roundup – August 29, 2023

greykeep · August 29, 2023 ·

GreyKeep Security Malware Roundup

This is the GreyKeep Security Malware Roundup for August 29, 2023. Here’s a summary of what’s in this week’s edition:

Targets

MacOS
Adobe ColdFusion
MOVEit Transfer
WinRAR
Openfire XMPP
Ivanti Sentry
Roblox
Juniper SRX
Cisco Nexus 3000/9000 (NX-OS)
Citrix NetScaler
Barracuda ESG
EsafeNet Cobra DocGuard
IoT devices

Organizations

U.S. government
Rust developers
Roblox developers
Taiwan
Hong Kong
Metropolitan Police Service

Threat Actors

CL0P (Russia)
Carderbee (China)
Evilnum (Russia)
TradeTraitor (N. Korea)
Lazarus (N. Korea)
FIN8
Lapus$
Evilnum
Flax Typhoon (China)

Malware / Ransomware

Korplug/PlugX
Lazarus APT
Whiffy Recon
QuiteRAT
Luna Grabber
LockBit 3.0
Kmsdx
DarkGate

Malware in the News

MacOS

  • New Variant of XLoader macOS Malware Disguised as ‘OfficeNote’ Productivity App

Adobe

  • Adobe Patches Critical Deserialization Vulnerability, butExploits Persist

Cisco

  • Cisco NX-OS Software Flaw Let Attacker Trigger a DoS Attack
  • Cisco Nexus 3000 and 9000 Series Switches Flaw Let Attackers Trigger DoS Attack

Juniper

  • Hackers exploit critical Juniper RCE bug chain after PoC release

ManageEngine

  • North Korea’s Lazarus Group hits organizations with two new RATs

Openfire

  • Thousands of Unpatched Openfire XMPP Servers Still Exposed to High-Severity Flaw

WinRAR

  • Threat Actor Exploits Zero-Day in WinRAR to Target Crypto Accounts

Citrix

  • FIN8-linked actor targets Citrix NetScaler systems

Developers

  • Over a Dozen Malicious npm Packages Target Roblox Game Developers
  • Signs of Malware Attack Targeting Rust Developers Found on Crates.io

Government

  • US govt email servers hacked in Barracuda zero-day attacks

Other Malware News

  • Clop ransomware dominates ransomware space after MOVEit exploit campaign
  • Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack
  • Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates
  • Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software
  • China Unleashes Flax Typhoon APT to Live Off the Land, Microsoft Warns
  • New “Whiffy Recon” Malware Triangulates Infected Device Location via Wi-Fi Every Minute
  • Leaked LockBit 3.0 ransomware builder used by multiple threat actors
  • Updated Kmsdx botnet targets IoT devices

Malware, News, Vulnerabilities

How can we help you become more secure? Contact Us

GreyKeep Security

© 2025 GreyKeep Security LLC · All Rights Reserved

  • Services
  • Our Approach
  • GreyKeep Security Blog
  • About Us
  • Contact Us