---
title: "Surge in Malware Attacks, AmericanBar Data Breach, Trigona Ransomware Spread, Cybersecurity News | DuoCircle"
description: "Here is this week’s cybersecurity bulletin that covers details around how malware attacks are on the rise and how threat actors are leaving no stone unturned."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/"
---

Quick Answer

Cybersecurity stories from the week of April 17, 2023: Fortinet researchers tracked a sharp rise in EvilExtractor, a $59-per-month data-theft tool from Kodex with seven attack modules that bypasses Windows Defender. Campaigns aimed at Europe and the US start with phishing emails carrying gzip-compressed attachments. Opening the attachment runs a Python program that loads a .NET stage and executes the EvilExtractor binary, which performs date and time checks, anti-sandbox checks, and anti-VM checks before stealing data. Coverage also included the AmericanBar data breach exposure and the spread of Trigona ransomware through compromised systems. The takeaway is that commodity phishing kits and inexpensive malware-as-a-service tooling are lowering the bar for credible breach attempts.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Surge%20in%20Malware%20Attacks%2C%20AmericanBar%20Data%20Breach%2C%20Trigona%20Ransomware%20Spread%2C%20Cybersecurity%20News&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F&title=Surge%20in%20Malware%20Attacks%2C%20AmericanBar%20Data%20Breach%2C%20Trigona%20Ransomware%20Spread%2C%20Cybersecurity%20News "Share on Reddit") [ ](mailto:?subject=Surge%20in%20Malware%20Attacks%2C%20AmericanBar%20Data%20Breach%2C%20Trigona%20Ransomware%20Spread%2C%20Cybersecurity%20News&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/04/spf-permerror-1.jpg) 

Here is this week’s [cybersecurity](/) bulletin that covers details around how malware attacks are on the rise and how threat actors are leaving no stone unturned to make their breach attempts **successful**.

## Europe and the U.S. Witness a Surge in EvilExtractor Malware Attacks

There has been a surge in EvilExtractor’s usage to target Europe and the U.S.

A **data theft tool** sold by Kodex for $59 per month, EvilExtractor has seven attack modules and can **bypass** [Windows Defender](https://www.techradar.com/news/windows-defender-hacked-to-deploy-this-dangerous-ransomware). Fortinet’s researchers have been monitoring EvilExtractor and its development and shared a report highlighting that the tool’s deployment increased significantly in March 2023.

The attacks start with [phishing emails](/content/phishing-prevention/phishing-email) that appear to be account confirmation requests. The emails contain **gzip compressed** attachments that execute a Python program that launches a **.NET loader** to launch EvilExtractor executables. The tool is updated and has the following capabilities:

- _Date time checking_
- _Anti-Sandbox_
- _Anti-VM_
- _Anti-Scanner_
- _FTP server setting_
- _Steal data_
- _Upload Stolen data_
- _Clear log_
- _Ransomware_

Fortinet also [shared](https://www.fortinet.com/blog/threat-research/evil-extractor-all-in-one-stealer) that the tool is constantly updated, and individuals **must stay vigilant** against phishing emails to steer clear of EvilExtractor.

## Data Breach at American Bar Association Affects 1.4 Million Members

_The ABA (American Bar Association) suffered a data breach where the threat actors gained access to the credentials of 1,466,000 old ABA members._

The ABA observed suspicious activity on the network on 17 March 2023 and activated its **incident response plan**. The investigation revealed that unauthorized individuals could steal usernames, hashed, and salted passwords of ABA users that they used **before 2018**.

The ABA has outlined that it is not a ransomware or corporate attack. Even if the stolen passwords are hashed and salted, [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) may be able to de-hash them in the long run and use some of the **default passwords** to gain access to the accounts.

ABA has recommended that ABA users **change their passwords** on the site and any other websites that employ the same passwords. They should watch for [spear-phishing](/content/spear-phishing-protection/spear-phishing-examples) emails of threat actors imitating the ABA.

## Trigona Ransomware Spread Through Hacked Microsoft SQL Servers

Threat actors are hacking into the Internet-exposed MS-SQL (Microsoft SQL) servers and deploying Trigona **ransomware payloads**.

[![Ransomware Lifecycle](https://media.mailhop.org/duocircle/images/2023/04/spf-permerror-2.jpg)](https://media.mailhop.org/duocircle/images/2023/04/spf-permerror-2.jpg)

The threat actors are deploying the malware to encrypt all files. The servers are breached using **brute-force** or [dictionary attacks](https://www.geeksforgeeks.org/what-is-a-dictionary-attack/), and they deploy the malware dubbed **CLR shell** after establishing a server connection. The Trigona malware is sophisticated, as it can be used to harvest system information, alter account configurations, and escalate privileges to the LocalSystem.

Once the threat actors have [established](https://asec.ahnlab.com/en/51343/) a presence, they install and launch another **dropper malware** that, in turn, launches Trigona and configures the binary to automatically launch on each system restart utilizing a Windows autorun key.

_The ransomware gang has been a constant threat since the start of the year._

## U.K. Cybersecurity Agency Cautions About a New Breed of Russian Hackers

The U.K.’s NCSC (National Cyber Security Centre) has warned about **increased risk** from state-aligned [Russian hacktivists](https://www.theregister.com/2023/02/28/anonymous%5Fsudan%5Fddos%5Fhospitals/) and urged nationwide organizations to take security measures.

Over the last year and a half, these state-aligned groups have emerged, and these are sympathetic to **Russia’s invasion** and are not financially motivated.

These hacktivists launch DDoS (Distributed Denial of Service) attacks and cause **service disruptions** in critical areas such as the parliament, transport departments, and [government websites](https://www.infosecurity-magazine.com/news/japan-govt-websites-killnet/). NCSC has outlined that the threat actors also intend to cause as much harm as possible, and organizations should implement all of NCSC’s recommended actions.

This is the [dedicated guide](http://www.ncsc.gov.uk/guidance/actions-to-take-when-the-cyber-threat-is-heightened) businesses and organizations should follow during the elevated risk of **cyber threats**.

## Australians’ Scam Losses Reach an All-Time High of $3.1 Billion in the Previous Year

The ACCC (Australian Competition & Consumer Commission) shared that the country’s individuals lost $3.1 billion to scams last year, a staggering **80% increase** from 2021.

A significant loss was due to [investment scams](https://www.commbank.com.au/support/security/investment-scams.html) that accounted for $1.5 billion, followed by $229 million lost to remote access scams and $224 million to payment redirections. ACCC attributed the increase in the losses to the increased effectiveness of fraud due to threat actors employing various themes to make said scams appear genuine.

_The Deputy Chair of the ACCC, Catriona Lowe, [added](https://www.scamwatch.gov.au/news-alerts/accc-calls-for-united-front-as-scammers-steal-over-3bn-from-australians) that these scams included the **impersonation** of official phone numbers, emails, and websites._

You should always know the latest scams and **verify investment** opportunities by searching for legitimate websites.

## New Chameleon Android Malware Imitating Bank, Government, and Cryptocurrency Applications

## [![malware](https://media.mailhop.org/duocircle/images/2023/04/sender-policy-framework-2584.jpg)](https://media.mailhop.org/duocircle/images/2023/04/sender-policy-framework-2584.jpg)

A new Android [malware](/resources/malware-and-its-defense-mechanism) named “Chameleon” has emerged, **targeting** Australian and Polish citizens since the start of the year.

The malware mimics the CoinSpot crypto exchange, Australian government agencies, and IKO bank. The malware performs multiple checks upon execution to **evade detection** and [requests](https://blog.cyble.com/2023/04/13/chameleon-a-new-android-malware-spotted-in-the-wild/) the victim to use the Accessibility Service, getting additional permissions and disables Google Play.

Chameleon is a **highly sophisticated** tool that sends the device’s details and has other capabilities to steal cookies, key logs, inject phishing pages, and steal lock patterns and SMS.

Android users **should be cautious** when installing applications and only download software from the Google Play store. You should also enable [Google Play Protect](https://www.lifewire.com/what-is-google-play-protect-4773171).

## Topics

NewsSecurity 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Surge%20in%20Malware%20Attacks%2C%20AmericanBar%20Data%20Breach%2C%20Trigona%20Ransomware%20Spread%2C%20Cybersecurity%20News&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-16-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Surge in Malware Attacks, AmericanBar Data Breach, Trigona Ransomware Spread, Cybersecurity News","description":"Here is this week’s cybersecurity bulletin that covers details around how malware attacks are on the rise and how threat actors are leaving no stone unturned.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/","datePublished":"2023-04-17T13:08:50.000Z","dateModified":"2025-05-19T12:13:08.000Z","dateCreated":"2023-04-17T13:08:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/"},"articleSection":"announcements","keywords":"News, Security","wordCount":842,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/spf-permerror-1.jpg","caption":"cybersecurity","width":900,"height":540},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Surge in Malware Attacks, AmericanBar Data Breach, Trigona Ransomware Spread, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Surge in Malware Attacks, AmericanBar Data Breach, Trigona Ransomware Spread, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Surge in Malware Attacks, AmericanBar Data Breach, Trigona Ransomware Spread, Cybersecurity News","description":"Here is this week’s cybersecurity bulletin that covers details around how malware attacks are on the rise and how threat actors are leaving no stone unturned.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/","datePublished":"2023-04-17T13:08:50.000Z","dateModified":"2025-05-19T12:13:08.000Z","dateCreated":"2023-04-17T13:08:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-16-of-2023/"},"articleSection":"announcements","keywords":"News, Security","wordCount":842,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/spf-permerror-1.jpg","caption":"cybersecurity","width":900,"height":540},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
