Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • French Hospitals Cut Internet Connection After Data Raid

    A French hospital has been forced to shut down its internet connectivity in two of its locations due to a cyberattack that launched an attempted extortion campaign. The hospital chain, GHT Coeur Grand Est revealed the news of the cyberattack yesterday, claiming that the cyber incident occurred last Tuesday. The announcement confirmed that the two…

  • Costa Rica Refuses to Pay Cyber Ransom

    Costa Rica has announced that it will not pay ransom demands requested by cybercriminals following a cyberattack that infected its government computer systems. The disruptions were first reported last week by Costa Rica’s Finance Ministry. The attack on the ministry disrupted several national processes such as tax collection, payment of public employees, and the importation…

  • The Emotet botnet is back, and it has some new tricks to spread malware

    The prolific Emotet botnet has reemerged with new techniques that aim to infect Windows PC devices with malware. Emotet has been around for years and has helped cybercriminals to perpetrate attacks and distribute malware and ransomware to victims around the world. The botnet was previously taken down by law enforcement on January 2021. Ten months…

  • The White House wants more powers to crack down on rogue drones

    The White House is looking to tighten restrictions on drone usage. Although unmanned aircraft systems (UAS) have become useful for many different endeavors, including research, recreation, and business, they also pose a risk to public safety and privacy. According to the White House, it laid out its plans to give more authorities the power to…

  • After hesitancy, Germany greenlights some heavy arms for Ukraine

    Defense leaders for over 40 countries met at the U.S. Ramstein Air Base in Germany on Tuesday to coordinate efforts of military aid for Ukraine. At this meeting, Germany contradicted previous statements made by its government.  Originally, Berlin said it couldn’t send its Marder infantry vehicles to Ukraine, then they would be sent to Slovenia…

  • Kim Jong Un vows full speed ahead for North Korea’s nuclear program, as he flaunts ICBM missiles

    On Monday, North Korean leader Kim Jong Un vowed to ramp up the development of nuclear arms. A military parade in Pyongyang featured an intercontinental ballistic missile that, according to experts, can put the entire mainland US in range.  The parade also included multiple giant rocket launchers and a submarine-launched ballistic missile. Kim Jong Un…

  • West warns of Russian cyber-attacks as concerns rise over Putin’s nuclear rhetoric

    The US and four of its closest allies have warned that “evolving intelligence” shows that Russia is contemplating cyber-attacks on countries backing Ukraine, as the Kremlin’s frustration grows at its failure to make military gains. Vladimir Putin used the launch on Wednesday of a powerful new Sarmat intercontinental ballistic missile (ICBM), capable of carrying ten or…

  • 4 questions every CISO should be asking about the metaverse

    The metaverse is coming — and it’ll be here sooner than you might think. Gartner forecasts that by 2026, a quarter of people will spend at least an hour a day in the metaverse. This is great news for businesses, as it will unlock new business models and ways of working that will add value…

  • North Korea Becoming Cryptocurrency-Hacking Central As Cyber Crimes Increase

    Hacking, which involves gaining unauthorized access to data in a computer system or individual unit, is used to exploit weaknesses in computer systems or networks, either to harm organizations or governments or to steal online assets. In 2021, a hack impacted the Colonial Pipeline system in Houston, Texas. The system carries gasoline and jet fuel…

  • Has Russia Already Lost the Cyberwar With Ukraine?

    Vladimir Putin’s war in Ukraine has not gone to plan. As sanctions sink their teeth deeper into the Russian economy, and battlefield losses continue to pile up, the Russian leader has found himself with yet another headache, one that just months ago would have seemed absurd. Since the invasion began on February 24, Russia has…

  • NY State Senator’s Bill Builds Legal Framework to Prosecute Crypto Crimes

    Kevin Thomas, a New York state senator, has introduced a new bill amendment that would establish some offenses related to rug pulls and other frauds with virtual tokens as official crimes, a report says. The bill, SB S8839, would call for defining, penalizing and criminalizing frauds targeted at developers and projects that would defraud crypto investors. The…

  • French election result: Macron defeats Le Pen and vows to unite divided France

    Emmanual Macron won five more years as France’s president over Rivval Marine Le Pen. The election results were 58.55% to 41.45%. Macron promised he would be a president for all. He is the first sitting president in 20 years to be reelected.  Le Pen felt that her vote share still marked victory and the ideas…

  • FBI Warning as BlackCat Ransomware Breaches at Least 60 Organizations

    The Federal Bureau of Investigation (FBI) released a FLASH warning this week pertaining to the ransomware-as-a-service group BlackCat. According to the warning, the hacking group has already compromised roughly 60 entities across the world. After successfully breaching an organization’s network, the group typically requests ransom payments of several million dollars. The group was recently established…

  • At least 168 killed in western Darfur violence, aid group says

    At least 98 people have been injured and 168 have been killed in the western Darfur town of Kreinik in tribal clashes. The clashes is the latest increase in violence in the region.  Western Darfur is the home to many people who were displaced in the early 2000s due to the conflict in the region…

  • Russia’s Sandworm hackers attempted a third blackout in Ukraine

    Several years after the Russian state sponsored hacking group Sandworm targeted an electrical transmission station north of Kyiv in 2016, the hackers are targeting Ukraine’s industrial grid again. In 2016, Russian hackers used a unique, automated piece of code to interact directly with circuit breakers and shut off lights to a small portion of its…

  • FBI Warns US Farmers of Ransomware Surge

    The FBI has warned that US food supply chains are at risk of ransomware attacks. The FBI released a Private Industry Notification this week that details how agricultural cooperatives may be seen as attractive targets to threat groups during the planting and harvesting seasons. Attacks could be financially motivated, or they could cause operational disruption…

  • This sneaky phishing attack tries to steal your Facebook password

    Researchers at Abnormal Security have released details pertaining to a phishing campaign targeting Facebook users. The phishing campaign aims to steal passwords to the popular social media platform. Researchers state that the phishing emails claim to be coming from Facebook employees and warn that the account might be disabled or removed due to content violations.…

  • Binance Recovers $5.8M Linked to Axie Infinity Hack

    Crypto exchange Binance has recovered a small fraction of the $622 million stolen from Sky Mavis’s Ethereum sidechain Ronin last month, according to a tweet by exchange CEO Changpeng “CZ” Zhao early this morning. Sky Mavis is the developer team behind the popular play-to-earn crypto game Axie Infinity. Zhao tweeted that the North Korean hacking…

  • Ukraine Postal Service Hit With Cyberattack After Selling Viral Anti-Russia Stamps

    Ukraine’s national post service said some of its systems went offline Friday because of a cyberattack following the much-publicized sale of stamps depicting a Ukrainian soldier giving the middle finger to the Russian warship Moskva, which sank last week. Director General Ihor Smilianskyi said that Ukrposhta, the postal service, had been hit by a distributed denial-of-service…

  • Hackers ‘DeFi’ threat risk expectations with new attack vectors in crypto

    Decentralized finance (DeFi) platforms have gained a lot of traction in recent years. Unfortunately, they have also gained a lot of attention from bad actors. Indeed, cryptocurrency transfers from illegal digital wallets to DeFi platforms skyrocketed nearly 2,000% between 2020 and 2021 alone, according to research from Chainalysis. Although malfeasance may be waning, the use of…

  • Treasury Secretary Janet Yellen calls for a reshaping of global supply chains that are ‘not secure.’

    Treasury Secretary Janet L. Yellen said on Thursday that global supply chains had proved to be unstable amid the pandemic and Russia’s war in Ukraine and called for a reshaping of trade relationships oriented around “trusted partners,” even if it meant higher costs for businesses and consumers. Ms. Yellen spoke at a news conference during the…

  • New York Man Arrested for Alleged $1.8M Crypto Mining Scam

    The Federal Bureau of Investigation arrested a 37-year-old man on Wednesday it says defrauded more than a dozen victims out of a total of $1.8 million in a long-running crypto mining scam. Between March 2019 and September 2021, officials say Chester “Chet” Stojanovich posed as a dealer of crypto mining equipment, convincing his would-be customers…

  • Cybersecurity Advisory warns of Russian-backed cyber threats to infrastructure

    Cybersecurity authorities from the US, Australia, Canada, New Zealand, and the UK released a joint Cybersecurity Advisory earlier this week detailing the cyber threat these countries face due to their support of Ukraine. According to the advisory, the support could expose the countries to increased rates of malicious cyber activity, especially to the infrastructure sector.…

  • Shanghai escalates Covid lockdown restrictions

    The enforcement of lockdown measures will be tightened by authorities in Shanghai as a Covid surge continues. Infected people will have door alarms to prevent them from leaving and will be evacuated to disinfect their homes. Hundreds of people were forcibly evacuated from their homes to disinfect the buildings they live in.  The lockdown is…

  • Ukraine war: Russia ‘plans to seize southern Ukraine’

    Russia hopes to seize southern Ukraine to open a route to the region of Transnistria in Moldova, one of the separatist regions of Ukraine. The Russian authorities also hope to take control of the eastern Donbas region in Ukraine. It is not clear if Major General Rustam Minnekayev’s comments about Russia’s plans were officially sanctioned.…

  • Bob’s Red Mill Reports Data Breach

    Bob’s Red Mill Natural Foods, the company behind popular American whole-grain foods, has notified its customers that their personal data may have been exposed in a cyberattack that occurred earlier this year. Bob’s Red Mills released a data breach notice on April 15 after detecting malicious activity that began two months ago. The company stated…

  • As the Iran nuclear deal nears, Saudi Arabia is rebuilding its stake in Lebanon

    In the first trip to Saudi Arabia by a Lebanese Prime Minister in almost four years, Najib Mikati will visit Saudi Arabia in the next two weeks.​ The last visit was in 2018 by Prime Minister Saad Hariri who stepped down in 2021.  Saudi Arabia is one of Lebanon’s biggest benefactors and their ties with…

  • FBI Seeks Info on BlackCat

    The Federal Bureau of Investigation (FBI) released a FLASH alert on Tuesday, seeking information pertaining to the threat actor BlackCat. BlackCat has been previously linked to other ransomware-as-a-service groups that have since gone inactive. Information the FBI is looking for includes IP addresses, Bitcoin or Monero addresses and transaction IDs, communications, decryptor files, and a…

  • LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave

    According to Microsoft’s security team, the operators of LemonDuck botnet are targeting systems in a mining campaign. Security researchers state that the malware exploits older vulnerabilities, most of which have already had patches released, to infiltrate cloud systems and servers. This includes EternalBlue, BlueKeep, and Microsoft Exchange ProxyLogon bugs. The threat actors behind the malware…

  • Crypto exchange Binance deactivating accounts in Russia

    Cryptocurrency exchange service Binance has announced that it will deactivate user accounts in Russia amid Moscow’s war with Ukraine. In a statement on Thursday, the company said Russian residents and Russian companies that hold crypto assets worth over 10,000 euros will be banned from making any deposits and trading within their accounts. “Accounts that classify under this…

  • Transaction Monitoring And Risk Mitigation Strategies For Global Supply Chains

    Between export bans and the numerous entities and individuals now restricted from transacting in the global economy, organizations worldwide must evaluate the legal, reputational, and cybersecurity impacts on their supply chain. How can companies navigate the current landscape and mitigate their supply chain and cyber risks? Sanctions against Russia continue to evolve rapidly, as governments…

  • West warns of Russian cyber-attacks as concerns rise over Putin’s nuclear rhetoric

    The US and four of its closest allies have warned that “evolving intelligence” shows that Russia is contemplating cyber-attacks on countries backing Ukraine, as the Kremlin’s frustration grows at its failure to make military gains. Vladimir Putin used the launch on Wednesday of a powerful new Sarmat intercontinental ballistic missile (ICBM), capable of carrying ten or…

  • A $600,000 Reminder to Not Save Your Passwords on Post-It Notes

    A security analyst in Pinellas Park, Florida (about a 15-minute drive from our office in downtown St. Petersburg) was arrested for stealing well over half a million dollars in cryptocurrency from a client. But unlike many other crypto theft cases, this incident isn’t the result of a complex cyber attack or even a phishing scam.…

  • Ireland Preparing to Ban Bitcoin Donations Over Russia Election Interference Fears

    Ireland’s Ministry for Housing, Local Government and Heritage is drafting rules that would ban political parties from accepting Bitcoin and other cryptocurrencies as donations. Local Government Minister Darragh O’Brien, who oversees elections and voting reform, put together a task force in January to recommend laws to maintain electoral integrity. Of specific concern was shielding the country…

  • UN Body Coordinator Calls For Greater Focus On North Korea’s Cyber Crimes

    The coordinator for the UN body monitoring enforcement of sanctions on North Korea said on Wednesday a stepped-up focus was needed on cybercrime, which had become fundamental to Pyongyang’s ability to finance its banned weapons programs. Eric Penton-Voak, of the UN Security Council’s Panel of Experts on North Korea, noted that despite the widest sanctions…

  • Russia tests nuclear-capable missile that Putin calls world’s best

    Russia has reportedly test-launched a nuclear capable intercontinental ballistic missile. On Wednesday, Russia’s leader President Vladimir Putin stated that the test should make enemies of Moscow stop and think about their interactions with the country. Putin was shown addressing the nation on TV after being told by the military that the Sarmat missile had been…

  • More than 20 dead and injured in four blasts in Afghanistan

    On Thursday, dozens of people were killed or injured in a series of explosions that tore through the city of Mazar-i-Sharif, Afghanistan. The first explosion occurred at a Shia mosque in the city and killed at least 11 people, according to officials. The Islamic State Group (IS) took responsibility for the attack, stating that it…

  • Taiwan investigates local TV network after it aired false reports of Chinese invasion

    The Taiwanese government is reportedly investigating a local TV news station over alarming false reports aired on the channel. The false reports concerned a Chinese invasion against the autonomous island, which is already on edge under the threat of Chinese interference. The government-affiliated Chinese Television System (CTS) aired the fake news during a Wednesday morning…

  • More on TraderTraitor and North Korean Threat Actors Targeting Cryptocurrency Organizations

    We previously reported on the TraderTraitor operation. The government investigation involved great work by the FBI, CISA and the US Treasury. As expected, many others in the press are also reporting on this. However, unlike OODA, the cybersecurity media is not in a position to evaluate the appropriate recommendations for mitigating the incident. For example,…

  • Google Reports Record Year for Zero Days in 2021

    Google reported that 2021 was a record year for zero-day exploits, the highest number since Google began tracking them. However, the company states that this could be a result of improved detection efforts and disclosure procedures rather than increased criminal activity. Project Zero, Google’s exploit team, tracked 58 zero-day exploits in 2021. This figure was…

  • Phishing emails targeting LinkedIn accounts are on the rise. Here’s what to watch out for

    Security researchers at Check Point released a report detailing phishing attempts against LinkedIn users. Check Point researchers stated that LinkedIn users should be wary of suspicious emails that seemingly come from LinkedIn. If the recipient clicks on the link, they are taken to a spoofed login page that harvests credentials and lands them in the…

  • Security Lessons From a Payment Fraud Attack

    On April 10, 2020, Atlanta-based fintech firm Brightwell was navigating more than the deadly COVID-19 pandemic. It all started with a series of customer phone calls. That morning sometime between 7 a.m. and 8 a.m., Brightwell received word from the customer service team that customers called to complain about missing funds, says Ernie Moran, at the…

  • NFTs: Functional Innovation or Cyber Weapons of Mass Destruction?

    While the culture and buzz surrounding Web3 can be overwrought, it’s more than hype: after all, the concept has won enthusiastic support from Silicon Valley giants and venture firms alike. Unfortunately, there is a darker side to the technology, that has been overlooked, especially when it comes to Web3’s novel file-exchange format: NFTs. Despite lofty…

  • Crypto-related phishing and how to avoid it

    In this video for Help Net Security, Michael Aminov, Chief Architect at Perception Point, talks about a recent Binance impersonation attack and, more broadly, the ongoing threat landscape impacting the cryptocurrency industry. Cryptocurrencies aren’t new, but they have become more mainstream: their use has increased significantly thanks to DeFi, gaming, NFTs, etc. In fact, according to…

  • Monero’s crypto of choice as ransomware ‘double extortion’ attacks increase 500%

    A new report by blockchain analytics firm CipherTrace highlights the growing role that privacy-focused cryptocurrencies such as Monero are playing in the rising tide of ransomware. “Current Trends in Ransomware” delves into trends observed during 2021 but was only released this week. The firm revealed there was almost a 500% increase in “double extortion” ransomware attacks…

  • Cyberattacks On Russian Targets Jumped 5X After Invasion Of Ukraine

    Russia is now the most-attacked country in the world and Russian citizens, who make up less than 2% of the global population, now constitute almost a fifth of all cyberattack victims. In fact, five times more Russian accounts were breached in March than in January as cyberattacks have ramped up significantly in 2022. Why? Anonymous declared…

  • Six killed as hundreds of Rohingya flee Malaysia detention

    Approximately 528 mostly Muslim Rohingya refugees fled a termporary immigration detention city in the north of Malaysia. The refugees escaped after a riot in the compound in the early morning on Wednesday. The escapees had broken through barriers and a door, the cause of the riot and break-out is under investigation.  At approximately 7am, six…

  • Ukraine war: Mariupol ultimatum passes as hundreds shelter in steel mill

    The deadline set for the Russian ultimatum demanding Ukrainian forces in Mariupol surrender has passed with no sign of compliance by Ukrainian troops. The final Ukrainian troops have taken shelter along with 1,000 civilians in the Azovstal steel plant. The local Ukrainian commander warned his troops they could hold out for only days or hours. …

  • This measure of German inflation just hit its highest level since 1949

    In March, the German annual producer price inflation topped 30%, reaching the highest level since the Federal Statistics Office began collecting data 73 years ago. Officials announced the milestone on Wednesday, stating that energy prices were likely to blame. Energy prices rose nearly 84% in 2022 from March of last year, due to increases in…

  • ‘CatalanGate’ Spyware Infections Tied to NSO Group

    Citizen Lab has uncovered a years-long campaign that is targeting the autonomous region of Spain, Catalonia, with an unknown zero-click exploit in Apple’s iMessage. The exploit was reportedly used by Israeli-based NSO Group to plant the Pegasus or Candiru spyware onto iPhones used by journalists, activists, politicians, and other public figures. Citizen Lab released a…

  • UK Government Staff Hit with Billions of Malicious Emails in 2021

    The UK government was reportedly targeted with billions of malicious emails in 2021, and employees may have clicked on tens of thousands of suspicious or fraudulent links. Comparitech recently conducted a report into these malicious emails, and received answers from 260 government organizations in the form of freedom of information requests. Comparitech calculated that 764,331…

  • Funky Pigeon Suspends Orders Following Cyber-Attack

    Gift card retailer Funky Pigeon has suffered from a cyberattack prompting it to temporarily suspend orders via its website. The company is owned by WHSmith and has informed law enforcement of the incident. The company has assured customers that no payment data was at risk and that it appears that no passwords were compromised. However,…

  • Okta says Lapsus$ breach hit just two customers

    Cloud software company Okta has confirmed that a cybersecurity incident that occurred in January had a much smaller impact than anticipated. The attackers were allegedly able to access the laptop of a third-party customer support engineer. The attack impacted just two other active customer tenants and lasted a total of 25 minutes, according to Okta’s…

  • IMF Warns of Crypto Mining as Possible Dodge on Russia Sanctions

    Countries such as Russia and Iran may eventually use cryptocurrency mining to evade sanctions, the International Monetary Fund warned in a report. There’s a risk that sanctioned nations will leverage their energy resources — which can’t be exported — to power mining, an energy-intensive process of validating coin transactions, the IMF said. By expanding their mining…

  • NATO Cyber Game Tests Defenses Amid War in Ukraine

    NATO’s large, multiday cyber defense exercise is set to bring together technical experts from alliance countries and Ukraine nearly two months after Russia’s invasion. The annual cyber wargames, known as the Locked Shields exercise, will start Tuesday in Tallinn, Estonia. The North Atlantic Treaty Organization’s Cooperative Cyber Defense Centre of Excellence organizes the event, which includes…

  • It’s the End of the Global Supply Chain as We Know It

    What a difference a year makes. The U.S. inflation rate was at 1.4 percent when Joe Biden was sworn in as President in January 2021. In just fifteen months, it has since risen rapidly to a 40-year high of 8.5 percent, the result of global supply chain issues. Many hoped that those issues would resolve themselves…

  • HowTo: Create a Cyber Maturity Strategy

    For modern enterprises, cybersecurity is key to success. Rapid digital innovation, fuelled by the pandemic, has led to countless new ways to connect with customers, employees and partners. However, it’s also seen the emergence of a multitude of new opportunities for cyber-criminals to gain access to data and take remote control of the critical business…

  • Top Security Concerns When Accepting Crypto Payment

    From Microsoft to AT&T to Home Depot, more companies are accepting cryptocurrency as a way to pay for products and services. This makes perfect sense as crypto coins are a viable revenue source. Perhaps the time is ripe for businesses to learn how to receive, process and convert crypto payments into fiat currency. Still, many questions…

  • TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

    The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). They…

  • Israel Airstrikes Hit Gaza After Rocket Fire

    Early Tuesday morning, Israel conducted airstrikes in Gaza, a move that officials state is response to a rocket fired from Palestinian territory. The fighting raises fears of a wider conflict amid tensions that have been growing over the past several months. Earlier this week, there were several instances of conflict at a sensitive holy site…