---
title: "Cyber Security News Update, Week 13 of 2021 | DuoCircle"
description: "What looks like a legitimate app secretly works as a botnet; what seems like a harmless email from a service provider may be a phishing scam."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/"
---

Quick Answer

Week 13 of 2021 covered: the Spanish takedown of the Mobdro Android pirate-streaming app (over 100 million downloads), with operators arrested and more than €5 million in revenue tied to ad-injection, data sales, and use of devices in DDoS proxy botnets; simultaneous DNS hijacks at cryptocurrency portals Cream Finance and PancakeSwap (both using GoDaddy-managed records) redirecting users to fake homepages that harvested private keys and seed phrases; a phishing campaign impersonating India's income-tax e-filing site to target ICICI, SBI, Axis Bank, HDFC, and PNB customers via an Android Certificate.apk demanding administrator rights; a Lookout report finding only 0.08% of US-government Android devices ran the latest version, with about 25% on Android 8 (636+ known vulnerabilities); the US sentencing of 18-year-old Graham Clark to three years probation for the July 2020 Twitter hijacking that used social engineering against Twitter staff to post a Bitcoin scam raising $117,000 from accounts including Elon Musk, Bill Gates, and Barack Obama; and Finnish authorities attributing the 2020 parliament email-account compromise to the Chinese state group APT31 (Zirconium/Judgment Panda).

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2013%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2013%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2013%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F "Share via Email") 

![cyber security](https://media.mailhop.org/duocircle/images/2021/03/dkim-validation-5079.jpg) 

What looks like a legitimate app secretly works as a botnet; what seems like a harmless email from a service provider may be a phishing scam. Nothing on the internet is safe anymore, cybersecurity issues are a severe threat for individuals and organizations alike, which makes it essential to stay abreast of the latest cyber news to keep your information assets secure from falling into the hands of cyber adversaries.

## Beware Of Malicious Video Streaming App Mobdro

An android app called Mobdro works as a platform to broadcast pirated videos (sporting events) on the surface but _secretly sells users’ personal information and traps user devices into proxies and DDoS botnets_. The Spanish police have recently seized this malicious app’s servers with **over 100 million downloads**; its operators have been arrested as well.

Investigations on the app’s suspicious activities began in 2018 when the Spanish Football League, the English Premier League, and other associations had reported the app. It wasn’t until last month that the investigations yielded any result. Consequently, there were four arrests, twenty blocked servers and web domains, frozen bank accounts, and two server shutdowns. It becomes imperative to take [ransomware protection](/advanced-threat-defense) seriously because selling user information is a lucrative business, Mobdro operators made over [€5 million](https://therecord.media/police-shut-down-android-app-that-transformed-smartphones-into-proxies/?web%5Fview=true) via these seized documents. Revenue came from showing ads, selling users’ data, and using the devices as proxy bots in **DDoS attacks**.

However, this revelation doesn’t surprise experts because they knew its malicious code and activities as malware. The app isn’t circulated through Google Play Store, which again points at its gory nature.

## Simultaneous DNS Hijack At Cream Finance And Pancakeswap Cryptocurrency Services

[![Cryptocurrency Services](https://media.mailhop.org/duocircle/images/2021/03/SMTp-providers-5079.jpg)](https://media.mailhop.org/duocircle/images/2021/03/SMTp-providers-5079.jpg)

The cryptocurrency portals’ visitors portals, the Cream Finance and PancakeSwap, _are getting redirected to a fraudulent website homepage where adversaries try to collect their private keys and seed phrases_. Both outlets have notified visitors of this **DNS hijacking attack** through Twitter posts. It is suspected that the same attacker is behind both attacks since their [DNS records](https://therecord.media/two-cryptocurrency-portals-are-experiencing-a-dns-hijack-at-the-same-time/?web%5Fview=true) were changed simultaneously.

_The private keys and seed phrases let the attackers into the users’ cryptocurrency wallets and steal their funds_. It is advised for Cream Finance and PancakeSwap customers to use [email security as a service](/) and refrain from visiting the infected websites, at least until the two portals notify about resumed services on Twitter. In yet another revelation, it was found that both the cryptocurrency portals used the web hosting company GoDaddy to manage their DNS records. This narrows down the attack vector to two possibilities, either the adversaries compromised the individual web hosting accounts of Cream Finance and PancakeSwap, or a GoDaddy employee account was compromised (since such attacks have been frequent in the past).

## Income Tax E-Filing Web Page Linked Scam Targets Indians

_US and France-based hackers are impersonating the Indian income tax e-filing web page to target the ICICI, SBI, Axis Bank, HDFC, and PNB_. The circulated messages prompt users to apply to receive their income tax refund. However, the [attached link](https://ciso.economictimes.indiatimes.com/news/sbi-icici-hdfc-axis-bank-pnb-and-the-indian-it-department-targeted-in-phishing-scam/81522843) leads them to a _fake webpage looking precisely like the original income tax e-filing web page_.

_The third-party cloud hosting providers associated with the IP addresses use HTTP instead of the secure HTTPS protocol_. Further, it asks users to download an application (Certificate.apk) that doesn’t come from Play Store and instructs users to give administrator rights and other permissions. The information compromised inside the fake income tax e-filing website includes users’ name, address, Aadhar number, PAN, DOB, contact number, email, gender, account number, IFSC, card details (including pin), etc. With these many details exposed, financial losses are destined. The scam also asks for users’ online banking credentials, which seals the deal for them. Users are advised to use **email protection** and pay heed to cybersecurity guidelines.

## The Risk Of Using Outdated Android Versions For Work

_A recent Lookout report states that **only 0.08%** of the Android devices used by US government employees run on the latest version_. Almost a quarter of government employees run on [Android 8](https://www.techrepublic.com/article/99-2-of-us-government-android-users-are-running-outdated-os-versions/?&web%5Fview=true) (the 2017 version), which has at **least 636 known vulnerabilities**. Naturally, this exposes them to app threats, phishing scams, and other device and network threats. With the pandemic on, the risks from such attacks increased further as more and more people began working from home and on their mobiles.

_The report revealed that iOS users are comparatively less prone to attacks because of the increased adoption of the latest updates_. Federally managed devices (2.66%) generally show a **low vulnerability** to attacks than unmanaged devices (16.62%). The same is valid for local or state-managed devices (6.18%) and unmanaged devices (11.02%). The study also revealed that vulnerability to attacks was more for BYOD (Bring Your Own Devices) employees even if the number of unmanaged devices was less.

_Workers are advised to update their mobile systems regularly and get patches as soon as they are released_. The organizations must have an approved device list for BYOD devices to enhance the implementation of cybersecurity tools. Further, they must train employees to identify **phishing attacks** adequately!

## Mindmaster Behind The 2020 Twitter Attack Gets Sentenced

[![Twitter Attack](https://media.mailhop.org/duocircle/images/2021/03/windows-smtp-service-2407.jpg)](https://media.mailhop.org/duocircle/images/2021/03/windows-smtp-service-2407.jpg)

The US Department of Justice has finally sentenced the juvenile cybercriminal who took Twitter by storm in July last year with the hack of several verified Twitter accounts, including that of Elon Musk, Bill Gates, and former President Obama. Eighteen-year-old Graham Clark will [have three years of probation](https://thehill.com/policy/cybersecurity/543515-twitter-hacker-to-serve-three-years-in-prison?web%5Fview=true&rl=1) after serving time in a juvenile facility.

The Florida Department of Law Enforcement (FDLE) found him guilty of using several **social engineering** and hacking tactics to access the Twitter employee and user accounts and post the bitcoin scam, which raised funds **over $117,000** from ordinary citizens. The judgment serves as a lesson for cybercriminals to take cybersecurity seriously or be ready to face the consequences.

## Chinese Hacker Group APT31 Responsible For Attack On Finnish Parliament

_The Finnish Parliament’s principal attack that took place last year has been linked back to the Chinese state hacker group APT31_ (Zirconium or Judgment Panda). The attack had compromised some [parliament email accounts](https://www.bleepingcomputer.com/news/security/chinese-nation-state-hackers-linked-to-finnish-parliament-hack/?&web%5Fview=true) (belonging to MPs).

Investigations by the Parliament’s security team, the Finnish National Bureau of Investigation (NBI), the Security Police, and the Central Criminal Police **traced the attack** as an APT31 operation. The hacker group has been involved in similar espionage and cybersecurity incidents in the past. The authorities have withheld further information on the incident until the completion of investigations.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2013%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 13 of 2021","description":"What looks like a legitimate app secretly works as a botnet; what seems like a harmless email from a service provider may be a phishing scam.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/","datePublished":"2021-03-23T13:40:32.000Z","dateModified":"2025-05-28T13:41:57.000Z","dateCreated":"2021-03-23T13:40:32.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":1060,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/03/dkim-validation-5079.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 13 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 13 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 13 of 2021","description":"What looks like a legitimate app secretly works as a botnet; what seems like a harmless email from a service provider may be a phishing scam.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/","datePublished":"2021-03-23T13:40:32.000Z","dateModified":"2025-05-28T13:41:57.000Z","dateCreated":"2021-03-23T13:40:32.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":1060,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/03/dkim-validation-5079.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
