DEV Community

Mark0
Mark0

Posted on

The Good, the Bad and the Ugly in Cybersecurity – Week 29

International authorities from the EU, UK, and United States have launched a coordinated crackdown on Russian cybercriminal infrastructure, sanctioning military intelligence officers and dismantling "bulletproof" hosting services like 1VPNS and Media Land. These entities provided critical support to ransomware syndicates such as Lockbit and Play by shielding their identities and ignoring abuse complaints, resulting in billions of dollars in global financial damages.

Technically, threat actors are evolving their delivery methods through trojanized remote work platforms and malicious GitHub repositories. The UAT-11795 group is currently deploying the Starland RAT via spoofed installers for apps like Zoom and WebEx, while another campaign uses nearly 300 fake GitHub repos to distribute BoryptGrab malware. These attacks leverage DLL side-loading and sophisticated social engineering to bypass modern defenses like Chrome’s App-Bound Encryption to exfiltrate sensitive credentials and cryptocurrency data.


Read Full Article

Top comments (0)