BleepingComputer reports that more than $5.9 million worth of cryptocurrency has been pilfered by the Inferno Drainer cryptocurrency phishing and scam service from 4,888 victims.
New business email compromise attacks launched by threat actors in Asia and a country in Eastern Europe have been using residential IP addresses matching victims' locations in an effort to conceal malicious activity, according to SecurityWeek.
BleepingComputer reports that nearly 9 million Android smartphones, TVs, TV boxes, and watches across 180 countries have been pre-infected by the Lemon Group cybercrime operation with the Guerilla malware, which could facilitate additional payload delivery, reverse proxy creation, and WhatsApp session takeovers.
Suspected Indian state-sponsored threat operation SideWinder has been discovered to have an attack infrastructure with 55 phishing domains and IP addresses impersonating organizations in the government, news media, financial, and telecommunications sectors, according to The Hacker News.
SiliconAngle reports that organizations with one unpatched security vulnerability were 33% more likely to have cyber insurance claims, while those that continued leveraging old unsupported software had a threefold increased likelihood of claims.
Chinese state-sponsored advanced persistent threat group Mustang Panda, also known as Earth Preta, Bronze President, Camaro Dragon, HoneyMyte, RedDelta, BASIN, and Red Lich, has launched new attacks exploiting TP-Link routers to compromise European foreign affairs organizations since January, according to The Hacker News.
Financially motivated threat operation Water Orthus, which was behind the CopperStealer malware, has reemerged with new attacks deploying the novel CopperStealth and CopperPhish payloads, reports The Hacker News.
Even though nearly three-quarters of business email compromise attacks during the past year have emerged from Nigeria, Israel has been gaining traction as a base for sophisticated BEC campaigns, as evidenced by the nearly 350 BEC attacks by an Israel-based threat operation since 2021, TechRepublic reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.