---
title: "Malicious Malware Disguised, CISA Reports Alarming Samsung, Android Malware Rampage, Cybersecurity News | DuoCircle"
description: "Here is our latest weekly cybersecurity bulletin with the latest cybersecurity news covering new threats and security updates."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/"
---

Quick Answer

Cybersecurity stories from the week of May 8, 2023: Cyble researchers reported malware disguised as the popular CapCut video-editing tool, stealing browser data, credentials, and crypto wallets. CISA flagged active exploitation of a Samsung ASLR-bypass flaw, CVE-2023-21492, on Galaxy devices. McAfee identified a cybercrime syndicate that had pre-installed malware on millions of low-cost Android devices, monetizing them through ad fraud and proxy services. LayerZero launched a $15 million crypto bug-bounty program. WhatsApp introduced Chat Lock to protect specific conversations with biometrics or a password. And researchers documented macOS attacks using Geacon, an open-source Cobalt Strike port written in Go.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Malicious%20Malware%20Disguised%2C%20CISA%20Reports%20Alarming%20Samsung%2C%20Android%20Malware%20Rampage%2C%20Cybersecurity%20News&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2023%2F&title=Malicious%20Malware%20Disguised%2C%20CISA%20Reports%20Alarming%20Samsung%2C%20Android%20Malware%20Rampage%2C%20Cybersecurity%20News "Share on Reddit") [ ](mailto:?subject=Malicious%20Malware%20Disguised%2C%20CISA%20Reports%20Alarming%20Samsung%2C%20Android%20Malware%20Rampage%2C%20Cybersecurity%20News&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/05/dmarc-report-1.jpg) 

Here is our latest weekly cybersecurity bulletin with the latest [cybersecurity](/) news covering new threats and security **updates**.

## Malicious Malware Disguised as CapCut Websites Promote Information Theft

A novel **malware campaign** is underway where threat actors impersonate the CapCut tool to push malware strains. 

**CapCut**, the official video editor by ByteDance, is a popular editor for music mixing, filtering, animation, and more. With over 500 million Google Play downloads, many individuals use the app for **TikTok videos**. However, threat actors saw this as an opportunity, and two campaigns are distributing different [malware](/resources/malware-and-its-defense-mechanism) impersonating CapCut.

Researchers at Cyble [discovered](https://blog.cyble.com/2023/05/19/capcut-users-under-fire/) these two and highlighted the attack method wherein the threat actors use **black hat SEO**, advertisements, and social media to promote a CapCut impersonating website that delivers the Offx stealer or a PowerShell script that downloads the [redline stealer](https://www.triskelelabs.com/blog/redline-stealer) to their devices. 

_Avoid such promotions and use the official Google Play and App Store applications._

## Exploit Targeting Samsung ASLR Bypass Flaw Raises Alarm, CISA Reports

CISA (Cybersecurity and Infrastructure Security Agency) warned individuals of a new **security vulnerability** in Samsung devices that threat actors are using to [bypass the ASLR.](https://nvd.nist.gov/vuln/detail/CVE-2023-21492) 

[The security feature ASLR (Address Space Layout Randomization)](https://nvd.nist.gov/vuln/detail/CVE-2023-21492) **randomizes memory** where application and OS components are loaded, making it challenging for threat actors to launch buffer overflow or memory-based attacks.

The vulnerability, [CVE-2023-21492](https://nvd.nist.gov/vuln/detail/CVE-2023-21492), is present on Samsung devices running Android versions 11, 12, and 13, and threat actors can use the sensitive information to conduct **ASLR bypasses**, allowing them to exploit memory management. 

Samsung has not released any details about the exploit, but the FCEB (U.S. Federal Civilian Executive Branch) agencies were served with a **3-week deadline**, ending on June 9, to address the flaw. You can read about CISA’s alert [here](https://www.cisa.gov/news-events/alerts/2023/05/19/cisa-adds-three-known-exploited-vulnerabilities-catalog).

## Massive Android Device Infection: Cybercrime Syndicate Deploys Malware on Millions

A malicious enterprise, the Lemon group, has pre-installed the “Guerilla” malware on [nearly 9 million](https://www.trendmicro.com/en%5Fus/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html) **Android smartphones** and smart devices. 

[![Android Malware](https://media.mailhop.org/duocircle/images/2023/05/check-dmarc-record-2.jpg)](https://media.mailhop.org/duocircle/images/2023/05/check-dmarc-record-2.jpg)

_The threat actors can load additional payload intercept OTPs (One Time Passwords), **set up reverse proxies**, hijack WhatsApp sessions, and more._ Trend Micro released a [report](https://www.trendmicro.com/en%5Fus/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html) when its analysts discovered Lemon Group and highlighted how the attack infrastructure of the group overlaps with the Triada malware operation of 2016.

Trend Micro exposed the group in February 2022, which led it to **rebrand** itself as “Durian Cloud SMS.” The complete details were not shared, but Trend Micro did share that the infection turns the infected devices into [mobile proxies](https://infatica.io/blog/all-you-need-to-know-about-mobile-proxies/) and that the threat actors can steal and sell the information transmitted on these devices and social media applications. 

These infected devices are not limited by geography and include devices from **around the world**. 

## Revolutionary $15M Crypto Bug Bounty Program Introduced by LayerZero

LayerZero Labs launched a new [bug bounty program](https://www.prnewswire.com/news-releases/layerzero-labs-launches-15m-bug-bounty-largest-in-the-world-301827316.html) offering a max reward of up to $15 million for **critical vulnerabilities**. 

The significant figure is a record in the blockchain and crypto worlds. Bug bounty initiatives encourage software developers to reward researchers that **identify bugs** in their platforms so they can be fixed before any [threat actor](/email-security/threat-actors-are-using-google-ads-to-launch-sophisticated-phishing-campaigns/) exploits them.

The creator of the LayerZero blockchain messaging protocol enables secure communication across **multiple blockchains** and has already facilitated the exchange of 10 million texts. With the $15 million **bounty launch**, LayerZero showcases its commitment to security and how it wants to promote trust. 

Within the program, **individuals will be rewarded** based on the severity level of the [vulnerabilities](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/) they discover, and the payouts start from $1,000, going up to $15 million.

## Enhance Privacy: WhatsApp Introduces Chat Lock Feature with Password or Fingerprint

Meta, the organization behind WhatsApp, has [released](https://www.youtube.com/watch?v=RVFsS-PeJm8) a new **“Chat Lock” feature** that users can utilize to block others from accessing personal conversations.

This feature will create a new folder that **users can lock** with a password or biometrics to ensure the privacy of conversations.

> [WhatsApp](https://www.thequint.com/tech-and-auto/tech-news/whatsapp-for-ios-android-will-now-have-a-chat-lock-feature-mark-zuckerberg) released the feature, stating, “Locking a chat takes that thread **out of your inbox** and puts it behind its folder that can only be accessed with your device’s password or biometric, like a fingerprint.”

The feature will **automatically hide** details of locked chat in notifications, preventing others from looking over your shoulders while using your devices. _Users can quickly view the locked chats by swiping down on the inbox and authenticating the lock._ 

The new feature will also expand and include locks designed for [companion devices](https://www.newelectronics.co.uk/content/news/cryptographic-companion-device-brings-security-to-the-automotive-market) and allow using different passwords for chats.

[![malware](https://media.mailhop.org/duocircle/images/2023/05/spf-record-7527.jpg)](https://media.mailhop.org/duocircle/images/2023/05/spf-record-7527.jpg)

## macOS Attacks Employ Open-source Cobalt Strike Port ”Geacon”

A **Go-based** implementation of Geacon is being utilized to target macOS devices. 

**Geacon and Cobalt Strike** simulate attacks against enterprise networks to improve defenses, but malicious actors use these to conduct attacks. Threat actors have been using [Cobalt Strike](https://inspiredelearning.com/blog/what-is-cobalt-strike-malware/) to compromise **Windows systems** for quite some time, but the researchers at Sentinel One recently discovered Geacon activity in the wild.

_The researchers found two cases of various Geacon deployments, requesting access to the device camera, contacts, photos, microphone, reminders, and even **administrator privileges** once launched_.

You can check out the IoCs (Indicators of Compromise) and details of the **Geacon attacks** [here](https://www.sentinelone.com/blog/geacon-brings-cobalt-strike-capabilities-to-macos-threat-actors/).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malicious Malware Disguised, CISA Reports Alarming Samsung, Android Malware Rampage, Cybersecurity News","description":"Here is our latest weekly cybersecurity bulletin with the latest cybersecurity news covering new threats and security updates.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/","datePublished":"2023-05-08T12:00:28.000Z","dateModified":"2025-05-22T11:57:48.000Z","dateCreated":"2023-05-08T12:00:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":839,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/dmarc-report-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Malicious Malware Disguised, CISA Reports Alarming Samsung, Android Malware Rampage, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Malicious Malware Disguised, CISA Reports Alarming Samsung, Android Malware Rampage, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malicious Malware Disguised, CISA Reports Alarming Samsung, Android Malware Rampage, Cybersecurity News","description":"Here is our latest weekly cybersecurity bulletin with the latest cybersecurity news covering new threats and security updates.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/","datePublished":"2023-05-08T12:00:28.000Z","dateModified":"2025-05-22T11:57:48.000Z","dateCreated":"2023-05-08T12:00:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":839,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/dmarc-report-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
