Skip to main content

CyberWire Daily: Self-Replicating Malware, Phishing-as-a-Service, and DDR5 Vulnerabilities

N2K NetworksSeptember 17, 202535 min410 views
23 connections·40 entities in this video→

Self-Replicating Malware in NPM

  • 🦠 A new self-replicating malware named Shy Halude has infected over 180 npm packages, stealing developer credentials and publishing them publicly.
  • πŸ› οΈ The worm spreads by hijacking npm tokens and injecting itself into popular packages, using tools like Truffle Hog for propagation.
  • πŸ”’ Experts emphasize the need for stronger two-factor authentication for publishing packages to prevent similar outbreaks.

Disruption of Phishing Operations

  • 🎣 Microsoft and Cloudflare have disrupted Raccoon 0365, a phishing-as-a-service platform targeting Microsoft 365 credentials.
  • πŸ’» The platform used adversary-in-the-middle tactics to bypass MFA and captured session cookies, generating at least $100,000.
  • πŸ‡³πŸ‡¬ Nigerian programmer Joshua Ouipe has been identified as the ringleader and is facing international law enforcement action.
  • 🎯 Octa uncovered Void Proxy, another phishing-as-a-service platform targeting Microsoft 365 and Google accounts using similar MITM techniques.

Advanced Persistent Threats and Backdoors

  • πŸ‡ΊπŸ‡¦ Researchers discovered a new APT28 Fancy Bear campaign, Operation Phantom Net Voxil, using malicious Office documents to deliver backdoors to Ukrainian military officials.
  • ☁️ Attackers leverage cloud services like Kufer and Ice Drive for command and control, highlighting a growing reliance on blended open-source and legitimate cloud services for stealth.

Memory Vulnerabilities and Budget Concerns

  • ⚑ A new Rowhammer attack variant, dubbed Phoenix, targets DDR5 memory, exploiting electrical charge leakage to corrupt data.
  • πŸ“‰ Democrats warned that proposed budget cuts could slash the FBI's cyber division staff by half, potentially undermining defenses against foreign threats and ransomware.
  • πŸ›οΈ FBI Director Patel countered that arrests have increased, but concerns remain about resource allocation and AI-driven election interference.

Securing Google Workspace

  • πŸ”‘ Abhishek Agrawal from Material Security discussed the challenges of securing Google Workspace, emphasizing its role as a critical identity and data repository.
  • βš™οΈ While Google Workspace offers secure infrastructure, organizations often need additional controls and customization for security operations and investigations.
  • πŸ”’ Identity-based attacks are prevalent, and attackers can move laterally within Workspace by compromising accounts, establishing persistence through mail rules or MFA changes.
  • πŸ“Š Data sprawl in services like Google Drive poses significant risks, with vast amounts of data often shared broadly and forgotten, creating large exposure surfaces.
  • πŸ“ˆ Material Security leverages Google Workspace's powerful APIs to build custom detection and response capabilities, offering automated remediation to free up security team resources.

Legal Consequences for Cybercriminals

  • βš–οΈ Connor Brian Fitzpatrick, founder of Breach Forums, was sentenced to 3 years in prison for facilitating the sale of billions of stolen records.
Knowledge graph40 entities Β· 23 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters12 moments

Key Moments

Transcript125 segments

Full Transcript

Topics18 themes

What’s Discussed

Shy HaludenpmMalwareCredential TheftTwo-Factor AuthenticationRaccoon 0365Phishing-as-a-ServiceMicrosoft 365Google WorkspaceAdversary-in-the-MiddleAPT28Fancy BearRowhammer AttackDDR5 MemoryFBI Cyber DivisionMaterial SecurityBreach ForumsPompompurin
Smart Objects40 Β· 23 links
MediaΒ· 1
ConceptsΒ· 10
PeopleΒ· 5
CompaniesΒ· 12
ProductsΒ· 10
EventsΒ· 2