---
title: "Realistic Checkout Forms, Google Blocks Fraud, Ukrainian Sold Data, Cybersecurity News | DuoCircle"
description: "Here we are with this week’s top cybersecurity news sharing the latest arrests of cybercriminals, Google’s actions against threats actions."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/"
---

Quick Answer

Cybersecurity stories from the week of April 24, 2023: attackers shifted from in-browser skimmer scripts to deploying realistic full checkout-form overlays to harvest credit card data. Google banned 173,000 developer accounts in 2022 to disrupt malware and fraud rings on the Play Store. A Ukrainian individual was arrested for selling personal data on roughly 300 million people to Russian buyers. Google initiated takedowns of CryptBot infostealer infrastructure through legal action. Chinese state-aligned actors were observed deploying new Linux malware variants for espionage. And researchers warned that resold or returned enterprise routers often retain VPN credentials, RADIUS secrets, and authentication data, exposing prior owners' networks to anyone who buys the hardware.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Realistic%20Checkout%20Forms%2C%20Google%20Blocks%20Fraud%2C%20Ukrainian%20Sold%20Data%2C%20Cybersecurity%20News&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F&title=Realistic%20Checkout%20Forms%2C%20Google%20Blocks%20Fraud%2C%20Ukrainian%20Sold%20Data%2C%20Cybersecurity%20News "Share on Reddit") [ ](mailto:?subject=Realistic%20Checkout%20Forms%2C%20Google%20Blocks%20Fraud%2C%20Ukrainian%20Sold%20Data%2C%20Cybersecurity%20News&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/04/dkim-validation.jpg) 

Here we are with this week’s top [cybersecurity](/) news sharing the latest arrests of cybercriminals, Google’s actions against threats actions, and the latest campaigns. Let’s check these out. 

## Credit Card Theft Through Realistic Checkout Forms Replaces Hackers’ Stealth Tactics

_Hackers and threat actors hijack online marketplaces to steal **credit cards** from innocent individuals worldwide._

Threat actors add the code to display genuine-looking **fake payment forms** that display as a modal overlaid on the main webpage of these marketplaces and online stores. Researchers at Malwarebytes released a [report](https://www.malwarebytes.com/blog/threat-intelligence/2023/04/kritec-art) on this new campaign highlighting that these models are carefully crafted and visually captivating, adding to the sophistication of the campaign.

[![threat actors](https://media.mailhop.org/duocircle/images/2023/04/spf-record-5817.jpg)](https://media.mailhop.org/duocircle/images/2023/04/spf-record-5817.jpg)

Whenever an individual enters information into the modal, it shows a loading screen that **leads to an error**, redirecting the user to the original payment URL (Uniform Resource Locator). The details entered, such as the card number, expiration date, CVV, and the holder’s name, are sent to the [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/). 

_If you are a frequent shopper and come across a modal, it is better to **skip** these and look for the original payment link on the online store._ 

## Google Blocks Malware and Fraud Rings by Banning 173K Developer Accounts

Last year, Google banned 173,000 developer accounts to block [malware](/resources/malware-and-its-defense-mechanism) and fraud rings infecting the Google Play store and Android devices. 

Preventing nearly 1.5 million applications linked to **multiple policy violations**, Google [shared](https://security.googleblog.com/2023/04/how-we-fought-bad-apps-and-bad-actors.html) that its Google Play Commerce security team was able to block transactions of fraud and abuse, saving its customers over $2 billion in losses. Google has included additional requirements for developers who wish to join the Play Store ecosystem.

Now, the developers will have to undergo a **phone and email identity verification** and have also collaborated with [SDK (Software Development Kit)](https://www.techtarget.com/whatis/definition/software-developers-kit-SDK) providers to **minimize** sensitive data access and prevent sharing of data so applications on the app store offer better privacy to all users. 

## Ukrainian Individual Apprehended for Selling Data of 300 Million Individuals to Russians

The Ukrainian police apprehended a middle-aged man from Netishyn who **sold the personal data** and sensitive information of nearly 300 million individuals, including the data of Ukrainian and European citizens. 

The 36-year-old used **Telegram** to promote the stolen information and advertise it to buyers, asking for $500-$2000 depending on the volume of data. Ukrainian police released an [announcement](https://cyberpolice.gov.ua/news/kiberpolicziya-vykryla-zlovmysnyka-u-zbuti-baz-iz-personalnymy-danymy-gromadyan-ukrayiny-ta-yes-6598/) highlighting that the information included passport data, taxpayer numbers, driver’s licenses, financial information, and birth certificates.

The statement also shared that most **buyers** were [Russian](https://www.voanews.com/a/ukraine-warns-russian-cyber-onslaught-is-coming-/6738800.html) citizens who used prohibited currencies for the payments, leading the police right to the culprit. During the raid, the man attacked a police officer but was brought down.

The police **confiscated computers**, server equipment, and 36 hard drives with multiple databases. The man is facing criminal charges and now faces jail time of a minimum of 5-10 years. 

## Cryptbot Malware Infrastructure Takedown Initiated by Google

Google was granted a court order to take down the Cryptobot malware and [info stealer](https://thehackernews.com/2023/04/vipersoftx-infostealer-adopts.html) after filing a lawsuit against the individuals using the malware to infect its browser and **steal user data**. 

Nearly 18 defendants from Pakistan are charged with running malicious and fraudulent websites to trick users into downloading **malicious versions** of Google Chrome and **Google Earth Pro**. These malicious versions downloaded the Cryptbot malware on victim systems designed to steal their personal and financial information without their knowledge.

To combat the spread of **Cryptbot**, Google has been granted a [temporary restraining order](https://www.documentcloud.org/documents/23793321-google-cryptbot-disruption-order-to-show-cause-signed), allowing the organization to disrupt these malicious distributions. 

Google will now **take down domains** associated with the malware that has infected nearly 670,000 systems in the past year. 

## Chinese Hackers Adopt New Linux Malware Variants for Espionage Purposes

Threat actors deploy malware on Linux systems in a new **cyberespionage** campaign using the PingPull variant and Sword2023 [backdoors](https://cybersecuritynews.com/apt41s-powershell-backdoor/).

**Pingpull** is a RAT (Remote Access Trojan) used by the Chinese state-sponsored threat actor group Gallium that targets the government and financial organizations of Russia, Belgium, Vietnam, Australia, and the Philippines.

The Chinese threat actor is using new [malware variants](https://www.scmagazine.com/news/malware/new-icedid-malware-variants-banking-trojans-ransomware), targeting Nepal and South Africa, and using a previously **undocumented** backdoor, Sword2023\. Sword2023 can **upload files** onto breach systems, exfiltrate information, and files, and is associated with two different C2 (Command and Control) servers. 

Gallium is advancing its arsenal and **shifting focus** to Linux systems. Organizations should define a comprehensive security strategy to defend against this and similar threats. 

## Resold Corporate Routers Can Expose Networks to Hackers, Warns Security Experts

[![sensitive data](https://media.mailhop.org/duocircle/images/2023/04/spf-record-check-9358.jpg)](https://media.mailhop.org/duocircle/images/2023/04/spf-record-check-9358.jpg)

Enterprise-level **networking equipment** hides [sensitive data](https://informationsecuritybuzz.com/acers-sensitive-data-sale-hacker-forum/) that threat actors could use to breach these organizations and steal customer information. 

_Cybersecurity researchers at ESET [purchased](https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/) **18** **used** **core routers** and found that these routers still had the complete configuration data on the devices that worked adequately._ Core routers can **make or break** a large organization as they connect to all network devices and support data communication interfaces.

Using these configuration settings and the details about the organization, a threat actor could find out how the network was set, including the connections between systems, making it easier to breach the [corporate network](https://www.cpomagazine.com/cyber-security/hacker-earned-1-5-million-providing-backdoor-access-to-hundreds-of-corporate-networks/). The routers also contained **credentials** to connect to other networks as a trusted party. 

Organizations should **ensure** that all discarded or old equipment is reset to **factory defaults** to avoid threat actors using these against them.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Realistic%20Checkout%20Forms%2C%20Google%20Blocks%20Fraud%2C%20Ukrainian%20Sold%20Data%2C%20Cybersecurity%20News&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Realistic Checkout Forms, Google Blocks Fraud, Ukrainian Sold Data, Cybersecurity News","description":"Here we are with this week’s top cybersecurity news sharing the latest arrests of cybercriminals, Google’s actions against threats actions.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/","datePublished":"2023-04-24T17:09:30.000Z","dateModified":"2025-05-19T11:55:38.000Z","dateCreated":"2023-04-24T17:09:30.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":872,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/dkim-validation.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Realistic Checkout Forms, Google Blocks Fraud, Ukrainian Sold Data, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Realistic Checkout Forms, Google Blocks Fraud, Ukrainian Sold Data, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Realistic Checkout Forms, Google Blocks Fraud, Ukrainian Sold Data, Cybersecurity News","description":"Here we are with this week’s top cybersecurity news sharing the latest arrests of cybercriminals, Google’s actions against threats actions.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/","datePublished":"2023-04-24T17:09:30.000Z","dateModified":"2025-05-19T11:55:38.000Z","dateCreated":"2023-04-24T17:09:30.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":872,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/dkim-validation.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
