---
title: "Cyber Security News Update, Week 12 of 2021 | DuoCircle"
description: "Cybersecurity cannot be ensured if threat actors remain adamant about finding new ways of getting through ransomware protection and other such cybersecurity."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/"
---

Quick Answer

Week 12 of 2021 covered: nine Google Play apps (Pacific VPN, Cake VPN, eVPN, Qrecorder, BeatPlayer, tooltip nation library, Music Player, QR/Barcode Scanner MAX) using the Clast82 dropper to deliver MRAT and AlienBot Banker via GitHub and Firebase resources, removed February 9 after detection on January 28; researchers at TU Darmstadt finding flaws (CVE-2020-9986) in Apple's Offline Finding network that let a malicious macOS app retrieve seven days of finder/owner location history through cached rolling advertisement keys; WhatsApp testing password protection for cloud chat backups on iCloud and Google Drive ahead of its May 15 privacy-policy update; a GitHub authentication-handling bug that misrouted authenticated session cookies between users (under 0.001% of sessions affected, patched March 5 and 8); a phishing campaign targeting 25,000+ Coinbase users globally with fake unusual-activity emails harvesting credentials and wallet seeds; and rising supply-chain attacks where threat actors buy software and source code to push malicious updates through existing distribution channels.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2012%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2012%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2012%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2021/03/what-is-dkim-selector-5072.jpg) 

Cybersecurity cannot be ensured if _threat actors remain adamant about finding new ways of getting through ransomware protection and other such cybersecurity tools_. There isn’t any stopping to these **perennial cyber threats**, and that’s why we bring you the latest news from the cyber realm. For, what is better than reading about cyberattacks and rectifying similar errors within our organizations? Here are the top headlines from this past week.

## Play Store Removes 9 Android Apps Spreading Alienbot Banker And MRAT

_Three cybersecurity researchers at Check Point have recently discovered a new malware dropper in 9 Google Play Store Android apps_. These apps use a second stage malware which slowly makes its way into the victims’ financial accounts. The adversaries spreading this **dropper called Clast82** use malicious techniques to evade Google Play Protect detection and even complete the evaluation period. The transition happens from a non-malicious payload to the MRAT and AlienBot Banker.

The nine android apps include Pacific VPN, Cake VPN, eVPN, Qrecorder, BeatPlayer, tooltip nation library, Music Player, and QR/Barcode Scanner MAX. The [malicious apps](https://thehackernews.com/2021/03/9-android-apps-on-google-play-caught.html?&web%5Fview=true) were detected on 28th January and removed from Google Play Store on 9th February.

The adversaries created a new developer user for each of the nine apps and a repository on their own GitHub account. Resultantly, _different payloads were delivered to devices with different apps_.

All the attackers did to bypass Google Play’s protections is manipulate the readily available 3rd party resources such as a FireBase or a GitHub account. With the kind of trust users have on Play Store’s **cybersecurity tools**, _nobody would have guessed that they are downloading trojans that get into their financial accounts in the name of a utility app_.

## Is Offline Finding Exposing Apple Users’ Identity?

Apple’s crowd-sourced location tracking system is arguably the largest but is using Apple’s offline finding (OF) network safe for users? _Academic researchers from the Technical University of Darmstadt, Germany, have identified vulnerabilities with the [OF network](https://www.securityweek.com/flaws-apple-location-tracking-system-could-lead-user-identification?&web%5Fview=true)_, which lets adversaries access the last seven days’ location history of both finder and owner devices, leading to location correlation attacks.

The bug known as CVE-2020-9986 has been fixed, but its existence questions the claims of anonymity Apple makes. _A malicious macOS application can decrypt and retrieve the users’ location history using the cached rolling advertisement keys retained on the file system_. The vulnerability can only be exploited if the victims request their device location using the Find My application. In simple words, finder and owner identities get revealed every time a location report is uploaded or downloaded.

The cybersecurity researchers found another flaw in the OF network, which _enables threat actors to access all owner devices’ location, which is without their awareness or consent_.

## Whatsapp To Introduce Password Protection For Cloud

[![Password Protection For Cloud](https://media.mailhop.org/duocircle/images/2021/03/DMARC-generator-1036.jpg)](https://media.mailhop.org/duocircle/images/2021/03/DMARC-generator-1036.jpg)

After much debate about its new privacy policy, _Facebook-owned WhatsApp is now working on its new password protection feature, which encrypts chat backups in the cloud_. The new privacy feature will make users’ chat backups on the cloud inaccessible to everybody else.

Although WhatsApp chats are **end-to-end encrypted**, this protection isn’t extended to online backups on iCloud and GDrive. Even WABetaInfo has confirmed the WhatsApp initiative to provide **cloud backups encryption**.

The password won’t be allowed by WhatApp and is a user’s **private security key**, likely to be available in a future build for Android and iOS. The password needs to be remembered to restore files from the backup. Though with a reversible algorithm, the chat database (excluding media) is encrypted now. The new [password protection](https://ciso.economictimes.indiatimes.com/news/whatsapp-to-password-protect-your-chat-backups-on-cloud/81404199) shall be compatible with local Android backups and be part of the new privacy policy that WhatsApp will launch from 15th May. _This cybersecurity update is yet to be made official by WhatsApp_.

## Serious Anomaly Detected In Authenticated GitHub Sessions

These days, most cybersecurity incidents are triggered by adversaries; however, this latest incident at GitHub stands out for its rarity. _GitHub discovered a severe bug in some of its authenticated sessions recently_, which routes one user’s session to [another user’s browser](https://www.securityweek.com/github-informs-users-potentially-serious-authentication-bug?&web%5Fview=true) and provides the second user an **authenticated session cookie** to the first user’s account. _This is caused by improper handling of authenticated sessions and cannot be triggered by a malicious user_.

After discovering the issue on 2nd March, GitHub quickly released a patch on 5th March, followed by a second patch on 8th March. Github has invalidated all authenticated sessions created before 12:03 UTC on 8th March to ensure further [ransomware protection](/advanced-threat-defense). _The silver lining in all this fiasco is that less than 0.001% of authenticated GitHub sessions were affected by this anomaly_.

## New Phishing Scam Targets Coinbase Users

[![phishing scam](https://media.mailhop.org/duocircle/images/2021/03/what-is-DKIM-6045.jpg)](https://media.mailhop.org/duocircle/images/2021/03/what-is-DKIM-6045.jpg)

_The adversaries are using the cryptocurrency Coinbase to steal sensitive user information of over 25k users_. The majority of the attacks originated in India, followed by Brazil, the US, and Japan. The affected users belong to South Korea, Sweden, Ireland, Japan, the US, Britain, and Canada. Bitdefender Antispam Lab first reported the cybersecurity incident, who said that the _attackers are trying to steal user credentials and loot their cryptocurrency wallets_.

The adversaries follow the same old strategy of asking users to verify their account credentials by filling a form immediately, lest their accounts get suspended because of ‘unusual activity.’ Such [phishing emails](https://web.archive.org/web/20210321033739/https://hotforsecurity.bitdefender.com/blog/malicious-actors-target-crypto-wallets-of-coinbase-users-in-new-phishing-campaign-25445.html?web%5Fview=true) from seemingly genuine addresses have time and again conned people into giving away their usernames, passwords, and other personally identifiable information.

In case a similar email popped in your mailbox, and you responded to it, then consider changing your password for all accounts with the same password. Victims are advised to go to the official Coinbase page and use the options they have provided for security incidents like this, MFA, password change, disabling account temporarily, etc. Further, it’s advised to use [email security as a service](/) to make sure your digital assets remain secure for a breach like this in the future.

## Will Supply Chain Attacks Increase?

After the barcode scanner app went all grey and malicious last month, it is difficult for users to believe every update notification on their phone to be genuine. _This is a relatively new attack scheme where adversaries buy software and its [source code](https://web.archive.org/web/20220627150107/https://cyware.com/news/supply-chain-attack-trends-involving-apps-and-extensions-8c399936) and then spread its malicious version based on the existing goodwill_. Chances are, there will be more utilization of this attack scheme among cybercriminals.

Such supply chain attacks are a great way to evade the stringent scrutiny process and, hence, benefit the attackers. What’s more concerning for us end-users is that such scams are on the rise. Several malicious apps manage to fool people with their fake ratings and reviews.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2012%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 12 of 2021","description":"Cybersecurity cannot be ensured if threat actors remain adamant about finding new ways of getting through ransomware protection and other such cybersecurity.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/","datePublished":"2021-03-15T17:49:11.000Z","dateModified":"2025-06-02T15:41:02.000Z","dateCreated":"2021-03-15T17:49:11.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":1084,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/03/what-is-dkim-selector-5072.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 12 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 12 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 12 of 2021","description":"Cybersecurity cannot be ensured if threat actors remain adamant about finding new ways of getting through ransomware protection and other such cybersecurity.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/","datePublished":"2021-03-15T17:49:11.000Z","dateModified":"2025-06-02T15:41:02.000Z","dateCreated":"2021-03-15T17:49:11.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":1084,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/03/what-is-dkim-selector-5072.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
