WEEKLY TOP TEN | SEPTEMBER 2, 2022 16:22 GMT
Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk:
- LockBit Ransomware Group Begins DDoS As Part of Triple Extortion Tactics
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-gets-aggressive-with-triple-extortion-tactic/ - Cybereason Performs Deep Dive on Ragnar Locker Ransomware Group Trends and TTPs
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector - LassPass Discloses the Compromise of Its Source Code After a Breach
https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/ - Video Game Anti-Cheating Driver Used by Ransomware, Rootkits to Disable Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html - Nitrokod “Freeware” Campaign Deploying Cryptominers Via Malware-packed Applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/ - Iran-affiliated Mercury APT Continuing to Leverage Log4Shell Vulnerability as Initial Access Vector
https://securityaffairs.co/wordpress/134876/apt/mercury-exploit-log4shell-flaw.html - Researchers Discover Infostealer MiniStealer Distributing for Free on Cybercrime Forums
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer/ - Cross-platform BianLian Ransomware Reaches 15 Victims Since July Inception
https://thehackernews.com/2022/09/researchers-detail-emerging-cross.html - Georgia Institute of Technology Develops Tool to Discover Malicious Plugins Infecting Thousands of WordPress Sites
https://securityaffairs.co/wordpress/135032/reports/wordpress-malicious-plugins.html - Google Confirms Several Chrome Extensions Perform Cookie-Stuffing to Support Threat Actor Activity
https://www.popsci.com/technology/chrome-extension-installation-malware-netflix-party/