Risky Bulletin: Secret ransomware campaign targeted DrayTek routers for a year
Dec 16, 2024
auto_awesome
A covert ransomware campaign targeting DrayTek routers has gone undetected for a year, raising alarming cybersecurity concerns. Recent layoffs at Yahoo and Amazon's security worries about Microsoft Office 365 highlight industry turbulence. The podcast also covers rising threats against media organizations and a surge in password spraying attacks. Furthermore, there's a notable decline in online scams in the Philippines and an exploration of regulatory actions affecting crypto exchanges and secure messaging services.
A secret ransomware campaign exploiting a zero-day vulnerability in DrayTek routers demonstrates the significant risks posed by advanced persistent threats.
Recent layoffs in Yahoo's security team and the dismantling of the Ridox cybercrime marketplace reflect the evolving challenges in the cybersecurity landscape.
Deep dives
Ransomware Targeting Draytech Routers
A secret ransomware campaign has exploited a suspected zero-day vulnerability in Draytech routers for over a year, specifically employed by a group called Monstrous Mantis. This group has been able to extract router passwords, which they then shared with affiliates, including members connected to the notorious Revil Group. Notably, the Greater Manchester Police Department in the UK confirmed that they were among the victims of this cyberattack. This highlights the ongoing threats posed by advanced persistent threats (APTs) targeting essential infrastructure through unpatched vulnerabilities.
Widespread Cybersecurity Developments
Recent significant layoffs within Yahoo's security team, referred to as the Paranoids, involved the loss of over 40 employees, with the company outsourcing its offensive penetration testing efforts. Concurrently, U.S. authorities successfully dismantled the Ridox cybercrime marketplace, which had been operational since 2016 and generated over a quarter of a million dollars in profits from selling hacking tools and personal data. Additionally, Amazon's planned migration to Microsoft 365 has been temporarily paused due to escalating security concerns following a breach of Microsoft's internal systems. These events underscore the volatile landscape of cybersecurity and the growing importance of robust security measures within organizations.