---
title: "Malware Steals Credentials, Gang Claims Ransomware Attack, Cisco Adapters Vulnerable, Cybersecurity News | DuoCircle"
description: "Here is the weekly cybersecurity bulletin, bringing you the top cybersecurity news covering the latest malware discoveries, ransomware attacks."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/"
---

Quick Answer

Cybersecurity stories from the week of May 1, 2023: the Fluhorse Android malware family targeted users in East Asia, posing as legitimate apps to steal credentials and intercept two-factor authentication codes. The Alpha gang claimed responsibility for a ransomware attack on Constellation Software, exfiltrating sensitive corporate data. A remote-code-execution flaw in Cisco SPA112 phone adapters had no available patch because the product was end-of-life. Facebook disrupted the NodeStealer information stealer infrastructure. Brightline disclosed a data breach affecting 783,000 pediatric mental-health patients tied to the GoAnywhere MFT zero-day. And the FBI seized nine cryptocurrency exchanges used to launder ransomware payouts.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Malware%20Steals%20Credentials%2C%20Gang%20Claims%20Ransomware%20Attack%2C%20Cisco%20Adapters%20Vulnerable%2C%20Cybersecurity%20News&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F&title=Malware%20Steals%20Credentials%2C%20Gang%20Claims%20Ransomware%20Attack%2C%20Cisco%20Adapters%20Vulnerable%2C%20Cybersecurity%20News "Share on Reddit") [ ](mailto:?subject=Malware%20Steals%20Credentials%2C%20Gang%20Claims%20Ransomware%20Attack%2C%20Cisco%20Adapters%20Vulnerable%2C%20Cybersecurity%20News&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/05/cross-tenant-migration-office-365.jpg) 

Here is the weekly cybersecurity bulletin, bringing you the top [cybersecurity](/) news covering the latest malware discoveries, ransomware attacks, vulnerable Cisco adapters, healthcare data breaches, and the FBI taking down nine crypto exchange websites. Let us take a look.

## Fluhorse Malware Targets Android Devices, Stealing Passwords and 2FA Codes

Fluhorse, a new Android malware, has targeted **East Asian users** with malicious versions of genuine applications.

Check Point’s researchers [discovered](https://research.checkpoint.com/2023/eastern-asian-android-assault-fluhorse/) the [malware](/resources/malware-and-its-defense-mechanism) sample, targeting multiple sectors since May 2022\. FluHorse is **distributed via emails** and is known for stealing account credentials and credit card information from high-profile targets.

The malware also snatches [2FA (Two Factor Authentication)](https://economictimes.indiatimes.com/tech/technology/twitter-to-no-longer-support-two-factor-authentication-for-free-users/articleshow/98828178.cms) codes and approaches high-profile targets with a payment issue, urging them to act promptly, leading them to a phishing website with a **fake APK (Android Package File)** that contains the malware.

FluHorse mimics ETC, VPBank Neo, and multiple genuine applications on the Google Play store. Individuals are advised not to pay attention to such [phishing emails](/content/email-phishing-protection/what-do-phishing-emails-do) and refrain from downloading files or software from websites.

## Alpha Gang Claims Responsibility for Ransomware Attack on Constellation Software

A Canadian software enterprise, Constellation Software, [confirmed](https://www.globenewswire.com/news-release/2023/05/04/2662158/0/en/Press-Release-of-Constellation-Software-Inc.html) that its systems were breached where the hackers made away with critical business data and personal information.

The threat actors were able to access a handful of systems in Constellation’s **internal financial reporting**, but other independent systems were not impacted in any way. Constellation has highlighted that all of its systems have been restored and that business partners and customers whose information was stolen during the [data breach](/email-security/how-to-respond-to-an-email-security-or-data-breach/) will be contacted and provided with all the details.

[![Ransomware](https://media.mailhop.org/duocircle/images/2023/05/what-is-dkim-selector-1.jpg)](https://media.mailhop.org/duocircle/images/2023/05/what-is-dkim-selector-1.jpg)

Constellation did not give any details of the attack. However, the [ALPHV (aka BlackCat)](https://www.computerweekly.com/news/252525240/ALPHV-BlackCat-ransomware-family-becoming-more-dangerous) added a new entry to its leaked website, claiming to breach Constellation’s website and steal over 1 TB of data. ALPHV has made a ransom demand and will not negotiate.

ALPHV threatened to release the data and shared a few documents with critical business information online.

## Cisco Phone Adapters Vulnerable to RCE Attacks; No Available Fix at the Moment

Cisco [disclosed](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW) a new critical vulnerability where its web-based interface for **Cisco SPA112 2-Port Phone Adapters** is at risk of [RCE (Remote Code Execution)](https://www.techtarget.com/searchwindowsserver/definition/remote-code-execution-RCE) attacks.

Being tracked as the CVE-2023-20126, Cisco shared details of the vulnerability caused by a missing authentication process contained within the firmware upgrade that allows threat actors to upgrade the device to a **crafted firmware** and [execute arbitrary code](https://www.bleepingcomputer.com/news/security/git-patches-two-critical-remote-code-execution-security-flaws/) on these devices with full privileges. One crucial thing is that these adapters are not exposed to the Internet, and the flaw can only be exploited from the local network.

Since the SPA112 has reached the end of its life, Cisco will not provide a security update. Individuals relying on the same should go for the **Cisco ATA 190 Series Analog Telephone Adapter**.

## Facebook Disrupts NodeStealer Information-Stealing Malware

Facebook came across NodeStealer, a new **info-stealer distributed on Meta**.

NodeStealer allows threat actors to steal browser cookies and hijack Meta, Gmail, and Outlook accounts. In a [blog post](https://engineering.fb.com/2023/05/03/security/malware-nodestealer-ducktail/), Facebook’s security team shared malware details highlighting that NodeStealer is still in the early distribution phase.

The organization disrupted the operation only 2 weeks after its deployment. [NodeStealer](https://www.bleepingcomputer.com/news/security/facebook-disrupts-new-nodestealer-information-stealing-malware/) was observed in late January this year by Vietnamese threat actors with the primary goal of stealing cookies and account credentials from Chromium-based browsers such as _Microsoft Edge, Google Chrome, Brave, Opera, and more._

Facebook reported the threat actor’s server, which was taken down on 25 January.

## Brightline Data Breach Affects 783K Pediatric Mental Health Patients

Brightline, a pediatric mental health provider, suffered a data breach that impacted 783,606 individuals.

A ransomware gang was able to steal data by exploiting a critical [zero-day](https://www.hindustantimes.com/technology/google-fixes-8th-zero-day-vulnerability-of-2022-details-here-101669440547022.html) in the Fortra GoAnywhere MFT file-sharing platform. Brightline confirmed the details of the breach and highlighted that the data stolen contained **protected health information**.

[![Clop ransomware gang](https://media.mailhop.org/duocircle/images/2023/05/hosted-email-server-6924.jpg)](https://media.mailhop.org/duocircle/images/2023/05/hosted-email-server-6924.jpg)

[Clop ransomware gang](https://www.bleepingcomputer.com/news/security/clop-ransomware-gang-begins-extorting-goanywhere-zero-day-victims/), the ransomware gang behind the attack, utilized the CVE-2023-0669 to steal data from nearly 130 organizations, including Brightline. The internal investigation revealed that the threat actors made away with _full names, residential addresses, dates of birth, member identification numbers, date of health plan coverage, and employer names._

Brightline has offered all impacted individuals identity theft and credit monitoring services for 2 years via Cyberscout.

## FBI Seizes 9 Crypto Exchanges Involved in Laundering Ransomware Payments

The FBI (Federal Bureau of Investigation) and the Ukrainian police **seized 9 crypto exchanges** that facilitated money laundering for threat actors.

The FBI [outlined](https://www.justice.gov/usao-edmi/pr/fbi-disrupts-virtual-currency-exchanges-used-facilitate-criminal-activity) that the crypto exchange websites allowed threat actors to anonymously convert crypto into another coin, which is harder to trace, allowing threat actors to launder their stolen assets without being traced by **law enforcement agencies**. Here is a list of all the websites that the FBI took down:

- 24xbtc.com
- 100btc.pro
- pridechange.com
- 101crypta.com
- uxbtc.com
- trust-exchange.org
- bitcoin24.exchange
- paybtc.pro
- owl.gold

All the above websites show the “**This Website Has Been Seized**” message in English and Russian. By taking these websites down, the FBI has dismantled malicious services and hindered the financial operations of multiple ransomware groups, sending out a strong message that the law will prevail against [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Malware%20Steals%20Credentials%2C%20Gang%20Claims%20Ransomware%20Attack%2C%20Cisco%20Adapters%20Vulnerable%2C%20Cybersecurity%20News&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-18-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malware Steals Credentials, Gang Claims Ransomware Attack, Cisco Adapters Vulnerable, Cybersecurity News","description":"Here is the weekly cybersecurity bulletin, bringing you the top cybersecurity news covering the latest malware discoveries, ransomware attacks.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/","datePublished":"2023-05-01T10:51:46.000Z","dateModified":"2025-05-16T12:10:25.000Z","dateCreated":"2023-05-01T10:51:46.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":839,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/cross-tenant-migration-office-365.jpg","caption":"cybersecurity","width":900,"height":563},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Malware Steals Credentials, Gang Claims Ransomware Attack, Cisco Adapters Vulnerable, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Malware Steals Credentials, Gang Claims Ransomware Attack, Cisco Adapters Vulnerable, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malware Steals Credentials, Gang Claims Ransomware Attack, Cisco Adapters Vulnerable, Cybersecurity News","description":"Here is the weekly cybersecurity bulletin, bringing you the top cybersecurity news covering the latest malware discoveries, ransomware attacks.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/","datePublished":"2023-05-01T10:51:46.000Z","dateModified":"2025-05-16T12:10:25.000Z","dateCreated":"2023-05-01T10:51:46.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-18-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":839,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/cross-tenant-migration-office-365.jpg","caption":"cybersecurity","width":900,"height":563},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
