logo
episode-header-image
Jan 2023
25m 15s

Criminal evolutions, disgruntled insider...

N2K Networks
About this episode

Gootloader's evolution. Yandex source code leaked (and Yandex blames a rogue insider). New GRU wiper malware is active against Ukraine. Latvia reports cyberattacks by Gamaredon. Russia and the US trade accusations of malign cyber activity. A hacktivist auxiliary's social support system. Deepen Desai from Zscaler describes the Lilithbot malware. Rick Howard looks at chaotic simians. And wannabes can be a nuisance, too: LockBit impersonators are seen operating in northern Europe.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/19


Selected reading.

Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations (Mandiant) 

Yandex denies hack, blames source code leak on former employee (BleepingComputer) 

Hackers use new SwiftSlicer wiper to destroy Windows domains (BleepingComputer) 

Sandworm APT targets Ukraine with new SwiftSlicer wiper (Security Affairs) 

Ukraine: Sandworm hackers hit news agency with 5 data wipers (BleepingComputer)

Ukraine Links Media Center Attack to Russian Intelligence (BankInfoSecurity) 

Latvia confirms phishing attack on Ministry of Defense, linking it to Russian hacking group (The Record from Recorded Future News) 

Russia knows US recruits hackers, trains Ukrainian IT-army — Deputy Foreign Minister (TASS)

Taking down the Hive ransomware gang. (CyberWire)

US puts a $10m bounty on Hive while Russia shuts down access (Register) 

Exploring Killnet’s Social Circles (Radware)

Copycat Criminals mimicking Lockbit gang in northern Europe (Security Affairs)

Learn more about your ad choices. Visit megaphone.fm/adchoices

Up next
Yesterday
Plug-ins gone rogue.
Patch Tuesday. An Iranian ransomware group puts a premium on U.S. and Israeli targets. Batavia spyware targets Russia’s industrial sector. HHS fines a Texas Behavioral Health firm for failed risk analysis. The Anatsa banking trojan targets financial institutions in the U.S. and C ... Show More
29m 52s
Jul 8
Memory leaks and login sneaks.
Researchers release proof-of-concept exploits for CitrixBleed2. Grafana patches four high-severity vulnerabilities. A hacker claims to have breached Spanish telecom giant Telefónica. Italian police arrest a Chinese man wanted by U.S. authorities for alleged industrial espionage. ... Show More
30m 50s
Jul 7
SafePay, unsafe day.
Ingram Micro suffers a ransomware attack by the SafePay gang. Spanish police dismantle a large-scale investment fraud ring. The SatanLock ransomware group says it is shutting down. Brazilian police arrest a man accused of stealing over $100 million from the country’s banking syst ... Show More
37m 27s
Recommended Episodes
Mar 2022
Russie : un malware inédit contre l’Ukraine ?
Si le conflit entre l’Ukraine et la Russie est un drame absolu pour les citoyens, force est de constater que le monde de la tech y joue un rôle de premier plan. Ces derniers jours, nous vous avons présenté différentes actions mises en place par les occidentaux pour tenter d’affai ... Show More
2m 31s
Jan 2023
A hacking group called Hive has been hacked by the US authorities
The hackers have been hacked - a prolific international ransomware operation has been shut down by US, German and Dutch officials. The criminal network, Hive, is said to have targeted over 1,500 victims worldwide in the past 18 months and extorted over $100 million. FBI director ... Show More
27m 45s
Dec 2022
Babbage: The surprising ineffectiveness of Russia’s cyber-war
When Russia invaded Ukraine, for the first time ever, two mature cyber-powers began to fight over computer networks in wartime. But while Russia’s cyber-war may have been intense, its impact has been modest. Has the country’s cyber prowess been overrated? The Economist’s Benjamin ... Show More
36m 46s