Weekly Threat Digest: December 30, 2024 – January 05, 2025
For a detailed threat digest, download the PDF file here
Summary
HiveForce Labs has identified a surge in cybersecurity threats, highlighting the increasing complexity and frequency of cyber incidents. Over the past week, seven major attacks were detected, seven critical vulnerabilities were actively exploited, and one threat actor group was closely monitored, reflecting a relentless rise in malicious activities.
Recent botnet activity highlights the increasing threat to cybersecurity, with FICORA (a Mirai variant) and CAPSAICIN (a Kaiten variant) exploiting vulnerabilities in D-Link routers via the Home Network Administration Protocol (HNAP). Concurrently, the Paper Werewolf cyberespionage group, active since 2022, has been targeting Russian organizations using phishing emails embedded with malicious macros to deploy PowerRAT for unauthorized access and data exfiltration.
Adding to the concern, a malicious npm package named ‘ethereumvulncontracthandler’ poses as a tool for identifying Ethereum smart contract vulnerabilities but instead delivers the Quasar Remote Access Trojan (RAT). These developments highlight the advanced techniques employed by threat actors and reinforce the critical need for robust, proactive cybersecurity strategies to address the rapidly evolving global threat landscape.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.