Crooks phish for guests; spies phish for drone operators. ZenRAT is used in an info-stealing campaign. More MOVEit-related incidents (some involving Cl0p). DeFi platforms hit. The UK hunts forward.
Sep 26, 2023
auto_awesome
An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.
Luxury hotels are being targeted in an ongoing phishing campaign, with advanced information stealer malware delivered through phishing emails.
A new malware called ZenRAT is infecting Windows devices through fake Bitwarden password manager installers, exhibiting information stealing capabilities.
Deep dives
Phishing Campaign Targets Hospitality Industry with Information Stealing Malware
Co-fence has discovered an ongoing phishing campaign targeting the hospitality industry. The campaign primarily targets luxury hotel chains and resorts. The phishing emails use lures related to the sector, such as booking requests and reservation changes. Once opened, these emails deliver advanced information stealer malware, exhibiting information stealing capabilities. Windows users are advised to exercise caution.
New Malware Strain ZenRAP Disguised as Bitwarden Installer
Proofpoint has reported a new malware strain called ZenRAP being distributed through fake installation packages posing as the Bitwarden password manager. If users on Windows devices fall for the fake installer, they become infected with the remote access Trojan that exhibits information stealing capabilities. ZenRAP only targets Windows devices, redirecting users of other operating systems to benign sites instead.
Data Breaches Exploit Vulnerabilities in Moved Software
Several organizations have reported data breaches related to vulnerabilities in the widely used Moved software. Sovos Compliance LLC, a service provider, has discovered data exposure that potentially affects six of its clients, including UBS Financial Services and Atlantic Shareholder Services. Additionally, the National Student Clearinghouse, used by nearly 900 colleges and universities, experienced a ransomware attack resulting in the exposure of varying personal data of students.
An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.
For links to all of today's stories check out our CyberWire daily news briefing: