Resources
Research
Resource Library
February 7, 2024
United Arab Emirates Cybersecurity: Supply Chain Threat Report
This research presents an analysis of the cybersecurity landscape of the top 30 companies in the United Arab Emirates (UAE) by revenue. Companies were ranked based on various factors, such as: network security, potential malware infections, and patching cadence.
Supply Chain Cyber Risk
January 23, 2024
Ransomware Attack on Vendor Managing U.S. Government Records
Executive Summary On January 3, CyberScoop reported a cyberattack resulting from an earlier service interruption affecting a vendor that manages records for U.S. county governments. As of January 10, some counties’ records remain inaccessible due to the incident. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and… Read More
Public Sector
January 23, 2024
BlackCat Ransomware Group Claims Attack on Healthcare Service Provider
Executive Summary On January 17, the BlackCat ransomware group added an entry for an electronic health record (EHR) vendor to its extortion site., Bbut, as of January 21, the vendor’s entry no longer appeared there. Following the claim, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team investigated the incident. Read More
Cyber Threat Intelligence
January 23, 2024
Avoslocker Ransomware Group Targets U.S University
Executive Summary On May 1, the Avoslocker ransomware group claimed responsibility for an attack against a small U.S. university. Shortly after news of the incident surfaced, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external sources to collect and analyze intelligence about the attack. These sources yielded… Read More
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence
January 23, 2024
Investigation of North Korea-Linked Indicators of Compromise (IOCs)
Executive Summary On February 9, CISA published a #StopRansomware alert regarding ransomware attacks against healthcare and public health organizations they attribute to threat actors acting on behalf of the North Korean state. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external data sources to enrich the indicators… Read More
Cyber Threat Intelligence
January 23, 2024
Newly-identified Vulnerability Affecting All Versions of Outlook for Windows
Executive Summary On March 14, Microsoft released a security update for a newly-identified vulnerability affecting all versions of Outlook for Windows. Current reports indicate that the vulnerability is under active exploitation by a threat actor group the cybersecurity community believes is acting on behalf of the GRU, Russia’s military intelligence… Read More
Cyber Threat Intelligence
January 23, 2024
New Intrusion Campaign Targeting Users of Popular Business Communication Software
Executive Summary On March 29, cybersecurity vendors announced that a new intrusion campaign had targeted users of business communication software company 3CX’s desktop client through a supply-chain attack. Initial reports have attributed the activity to the threat actor group tracked as Labyrinth Chollima, which is believed to conduct espionage on behalf… Read More
Cyber Threat Intelligence
January 23, 2024
Investigations of Lazarus Group Indicators of Compromise Reveals Suspicious Traffic Involving State Government IP Addresses
Executive Summary In early February, analysts attributed a new intrusion affecting a healthcare research organization to the Lazarus Group, a well-established threat actor believed to act on behalf of the government of the Democratic People’s Republic of Korea (DPRK). In an effort to enrich the Indicators of Compromise (IoCs) provided in… Read More
Cyber Threat Intelligence
January 23, 2024
Attackers Exploit Windows Vulnerability to Deliver Nokoyawa Ransomware
On April 11, security researchers announced the discovery of CVE-2023-28252, a zero-day vulnerability under active exploitation by a sophisticated cybercriminal group. The vulnerability affects all versions of Windows and could therefore be quite widespread; however, a patch is available.\r\n
Cyber Threat Intelligence
January 23, 2024
New APT29 – Attributed Phishing Activity Targets Diplomatic Services
On April 13, Poland’s Computer Emergency Response Team (CERT.PL) and Military Counterintelligence Service released a group of joint advisories regarding newly-observed espionage activity attributed to a Russia-linked threat actor group.
Cyber Threat Intelligence
January 23, 2024
Cyber Risk Intelligence: Cold Storage and Logistics Disruption
On April 26, reports of a service disruption affecting a major cold storage and logistics firm surfaced.
Cyber Threat Intelligence
January 23, 2024
LockBit Group Claims Ransomware Attack Against Southeast Asian Bank
On May 8, the LockBit ransomware group claimed an attack against a major state-owned bank in Southeast Asia.
Cyber Threat Intelligence
January 23, 2024
Ransomware Affiliates Exploit Recently-Discovered PaperCut Vulnerability
On April 26, security researchers announced the discovery of CVE-2023-27350 and CVE-2023-27351, vulnerabilities in the PaperCut print management software solution.
Cyber Threat Intelligence
January 22, 2024
Investigation into Breached Australian Organizations
In mid-March, two Australian financial and professional services firms reported data breaches. These were followed by a series of cyber incidents affecting large Australian firms throughout 2022 and early 2023. As a result, some reporting on the incidents presented them as indications of systematic shortcomings in the country’s cyber defenses.\r\n\r\n
Cyber Threat Intelligence
January 22, 2024
Investigation into Last Month’s Royal Ransomware Attack Against a City Government
On May 1, local media reported that a city government had suffered a disruption resulting from an attack claimed by the Royal ransomware group.\r\n
Cyber Threat Intelligence
Public Sector
January 22, 2024
LockBit Ransomware Group Claims Attack Against Prominent Taiwanese Semiconductor Firm
On June 29, the LockBit ransomware group added an entry for a major semiconductor manufacturer to its data leak site.
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence
January 22, 2024
SecurityScorecard Identifies Possible Flax Typhoon Infrastructure
On August 24, Microsoft published its analysis of espionage activity it attributes to a new threat actor group tracked as Flax Typhoon, which it assesses to act on behalf of the People’s Republic of China.
Cyber Threat Intelligence
January 22, 2024
Cyber Risk Intelligence Update: STRIKE Team Investigation Identifies Possible Flax Typhoon Links to Higher Education
Following Microsoft’s identification of Flax Typhoon, a new threat actor group believed to conduct espionage on behalf of the People’s Republic of China (PRC), the STRIKE Team used SecurityScorecard’s data to investigate the IoCs Microsoft supplied in its report. This investigation yielded a collection of new IP addresses featuring the same TLS certificates that Microsoft linked to Flax Typhoon.\r\n\r\n
Cyber Threat Intelligence
Public Sector
January 22, 2024
Daixin Team Ransomware Group Claimed Airline Ransomware Attack
Executive Summary An information security researcher reported on November 20 that the Daixin Team ransomware group had claimed that a recent attack against an airline had resulted in a breach exposing the personal data of all airline employees and five million passengers. Following this report, the SecurityScorecard Threat Research,… Read More
Cyber Threat Intelligence
Public Sector
January 22, 2024
Cyber Risk Intelligence: County Government Cyber Incident May Have Involved Social Engineering and Targeting of Vulnerable SSH Services
Executive Summary A U.S. county government announced on September 11 that a recent cyber incident strongly resembling a ransomware attack had disrupted its online services. SecurityScorecard researchers identified evidence suggesting two possible (and not mutually exclusive) paths by which the threat actors may have accessed county systems: Two… Read More
Cyber Threat Intelligence
Public Sector
January 22, 2024
Microsoft ProxyNotShell Zero Days
Prepared by: Rob Ames, Staff Threat Researcher, Jared M. Smith, Ph.D., Senior Director of Threat Research, Ryan Sherstobitoff, SVP of Threat Intelligence