The Five Stories That Shaped Cybersecurity in 2022
2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem As we looked back at the security incidents, events and stories that demanded attention over the past year, it became crystal clear that high-profile data breaches and zero-day attacks would continue to dominate the headlines. It seemed that hardly a week went by without some sort of cybersecurity incident making headlines, stretching spending budgets to the limits as CISOs and defenders navigated a worsening economy and staff cuts that hurt security programs. In this review of the top stories of 2022, SecurityWeek editors take a closer look at the five big stories that shaped 2022 and what they might mean for the future of securing data at scale.
https://www.securityweek.com/five-stories-shaped-cybersecurity-2022
The Most Prolific Ransomware Gangs of 2022
As we look forward to 2023, we can find many ransomware lessons in looking back at 2022. The year brought us numerous attacks by many of the same gangs we’ve watched for years, as well as some newcomers. Many ransomware gangs operate like businesses, with their own marketing departments and user documentation. With the advent of Ransomware-as-a-Service (RaaS), gangs now sell their software to other criminals and get a portion of the profits — revenue without having to lift even a virtual finger. But just like legitimate companies, some gangs are more successful than others. By understanding recent and common tactics, companies can create an effective plan to thwart ransomware attacks in the new year.
Fraudsters’ working patterns have changed in recent years
Less sophisticated fraud — in which doctored identity documents are readily spotted — has jumped 37% in 2022, according to Onfido. Fraudsters can scale these attacks on an organization’s systems around the clock. It is estimated that the current global financial cost of fraud is $5.38 trillion (£4.37 trillion), which is 6.4% of the world’s GDP. With most fraud now happening online (80% of reported fraud is cyber-enabled), Onfido’s Identity Fraud Report uncovers patterns of fraudster behavior, attack techniques, and emerging tactics.
3 Industries, 3 Security Programs
Security leaders from a media corporation, a commercial real estate company, and an automotive technology company share how they address cyber-risk. Every organization is at risk of a cyberattack, but each organizations addresses risk differently. No one expects SMBs to take the same approach to cybersecurity as a large enterprise, or a legacy organization to have the same appetite for risk as a startup. Similarly, how an organization defends itself from attack depend on various factors, including its size, type of industry, supply chain resources, approach to outsourcing and remote work, and global presence. Security leaders from three very different industries sat down with Dark Reading to discuss their respective cybersecurity programs.
https://www.darkreading.com/edge-articles/3-industries-3-security-programs
Extracting Encrypted Credentials From Common Tools
Attackers are harvesting credentials from compromised systems. Here’s how some commonly used tools can enable this. The majority of cyberattacks rely on stolen credentials — obtained by either tricking employees and end-users into sharing them, or by harvesting domain credentials cached on workstations and other systems on the network. These stolen credentials give attackers the ability to move laterally within the environment as they pivot from machine to machine — both on-premises and cloud — until they reach business-critical assets.
https://www.darkreading.com/dr-tech/extracting-encrypted-credentials-from-common-tools
Reported phishing attacks have quintupled
The third quarter of 2022, APWG observed 1,270,883 total phishing attacks — is the worst quarter for phishing that APWG has ever observed. The total for August 2022 was 430,141 phishing sites, the highest monthly total ever reported to APWG. Over recent years, reported phishing attacks submitted to APWG have more than quintupled since the first quarter of 2020, when APWG observed 230,554 attacks.
INCIDENTS:
BitKeep Confirms Cyber Attack, Loses Over $9 Million in Digital Currencies
Decentralized multi-chain crypto wallet BitKeep on Wednesday confirmed a cyberattack that allowed threat actors to distribute fraudulent versions of its Android app with the goal of stealing users’ digital currencies. “With maliciously implanted code, the altered APK led to the leak of user’s private keys and enabled the hacker to move funds,” BitKeep CEO Kevin Como said, describing it as a “large-scale hacking incident.”
https://thehackernews.com/2022/12/bitkeep-confirms-cyber-attack-loses.html
Hackers Steal $3 Million from BTC.com
Blockchain portal BTC.com has suffered a cyberattack that cost it $3 million in digital assets, announced cryptocurrency miner BIT Mining, the portal’s parent company. BIT Mining offers mining pool, data center operation and miner manufacturing services, among others. Its subsidiary, BTC.com, is touted as the world’s top blockchain browser, providing mining services in multiple currencies, including BTC, ETH and LTC. BIT Mining this week announced that a cyberattack hit BTC.com at the start of December.
https://www.bitdefender.com/blog/hotforsecurity/hackers-make-off-with-3-million-from-btc-com/
MALWARE:
GuLoader Malware Utilizing New Techniques to Evade Security Software
Cybersecurity researchers have exposed a wide variety of techniques adopted by an advanced malware downloader called GuLoader to evade security software. “New shellcode anti-analysis technique attempts to thwart researchers and hostile environments by scanning entire process memory for any virtual machine (VM)-related strings,” CrowdStrike researchers Sarang Sonawane and Donato Onofri said in a technical write-up published last week. GuLoader, also called CloudEyE, is a Visual Basic Script (VBS) downloader that’s used to distribute remote access trojans such as Remcos on infected machines. It was first detected in the wild in 2019.
https://thehackernews.com/2022/12/guloader-malware-utilizing-new.html
Raspberry Robin malware used in attacks against Telecom and Governments
The Raspberry Robin worm attacks aimed at telecommunications and government office systems across Latin America, Australia, and Europe. The campaign has been active since at least September 2022, most of the infections have been observed in Argentina (34,8%), followed by Australia (23,2%). “We found samples of the Raspberry Robin malware spreading in telecommunications and government office systems beginning September.” reads the report published by Trend Micro. “The main payload itself is packed with more than 10 layers for obfuscation and is capable of delivering a fake payload once it detects sandboxing and security analytics tools.” Raspberry Robin is a Windows worm discovered by cybersecurity researchers from Red Canary, the malware propagates through removable USB devices.
VULNERABILITIES:
Google Home speakers allowed hackers to snoop on conversations
A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed. A researcher discovered the issue and received $107,500 for responsibly reporting it to Google last year. Earlier this week, the researcher published technical details about the finding and an attack scenario to show how the flaw could be leveraged. Compromise process While experimenting with his own Google Home mini speaker, the researcher discovered that new accounts added using the Google Home app could send commands to it remotely via the cloud API.
Netgear warns users to patch recently fixed WiFi router bug
Netgear has fixed a high-severity vulnerability affecting multiple WiFi router models and advised customers to update their devices to the latest available firmware as soon as possible. The flaw impacts multiple Wireless AC Nighthawk, Wireless AX Nighthawk (WiFi 6), and Wireless AC router models. Although Netgear did not disclose any information about the component affected by this bug or its impact, it did say that it is a pre-authentication buffer overflow vulnerability.
Microsoft Patches Azure Cross-Tenant Data Access Flaw
Microsoft has silently fixed an important-severity security flaw in its Azure Container Service (ACS) after an external researcher warned that a buggy feature allowed cross-tenant network bypass attacks. The vulnerability, documented by researchers at Mnemonic, effectively removed the entire network and identity perimeter around internet-isolated Azure Cognitive Search instances and allowed cross-tenant access to the data plane of ACS instances from any location, including instances without any explicit network exposure.
https://www.securityweek.com/microsoft-patches-azure-cross-tenant-data-access-flaw
Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




