---
title: "Camaro Dragon Returns: USB Malware, THT Ransomware Menace, Crypto Malware Syndicate, Cybersecurity News [19 June 2023] | DuoCircle"
description: "Here is the latest cybersecurity news to be aware of to stay protected from the clutches of malicious cyber-attacks that may pop up any moment with phishing."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/"
---

Quick Answer

Four stories. Check Point reported that the Chinese APT Camaro Dragon is using self-propagating USB malware including WispRider and HopperTick to spread across air-gapped networks worldwide. The TimisoaraHackerTeam crew encrypted systems at a U.S. cancer hospital, forcing diversions in patient care; CISA published an advisory on the group's tactics. Ukrainian cyber police, working with Interpol, dismantled a phishing operation that stole more than $5 million from Canadian victims by impersonating banks. And researchers at Aqua found that millions of GitHub repositories are vulnerable to repo-jacking, where renamed or deleted accounts allow attackers to claim the namespace and serve malicious code to dependent projects.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Camaro%20Dragon%20Returns%3A%20USB%20Malware%2C%20THT%20Ransomware%20Menace%2C%20Crypto%20Malware%20Syndicate%2C%20Cybersecurity%20News%20%5B19%20June%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F&title=Camaro%20Dragon%20Returns%3A%20USB%20Malware%2C%20THT%20Ransomware%20Menace%2C%20Crypto%20Malware%20Syndicate%2C%20Cybersecurity%20News%20%5B19%20June%202023%5D "Share on Reddit") [ ](mailto:?subject=Camaro%20Dragon%20Returns%3A%20USB%20Malware%2C%20THT%20Ransomware%20Menace%2C%20Crypto%20Malware%20Syndicate%2C%20Cybersecurity%20News%20%5B19%20June%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F "Share via Email") 

![cybersecurity-news](https://media.mailhop.org/duocircle/images/2023/06/smtp-service.jpg) 

Here is the latest [cybersecurity](/) news to be aware of to stay protected from the clutches of malicious cyber-attacks that may pop up any moment with **phishing emails**, ransomware attacks, or any of the numerous other attack vectors.

## Chinese Threat Actor, Camaro Dragon, Is Back with Self-Propagating USB Malware

Malware that spreads through **infected USB drives** is in the news right now. Chinese threat actors are suspected as the activities are similar to Chinese groups Mustang Panda and LuminousMoth.

The espionage malware, [Camaro Dragon](https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/), started spreading when an unnamed European hospital employee connected his USB drive to an infected computer system while attending an Asian conference. The infected USB later spread the malware in the **European hospital’s information system**. Thus, the malware, which is prominent in Southeast Asian countries, has now made a global presence.

When a USB drive is inserted into a system infected with malware, the malware creates many **hidden folders** at the root of the drive and copies a Delphi loader. The malware makes use of the HopperTick launcher and WispRider backdoor infection component. The countries currently affected are Myanmar, the UK, South Korea, Russia, and India.

[![malware](https://media.mailhop.org/duocircle/images/2023/06/SMTP-email-1762.jpg)](https://media.mailhop.org/duocircle/images/2023/06/SMTP-email-1762.jpg)

Camaro Dragon is also seen to be updating the [malware](/resources/malware-and-its-defense-mechanism) to newer versions. Therefore, besides following precautions for email phishing protection, users must also be alert in following **cybersecurity best practices** associated with USB storage drives.

## TimiSoaraHackerTeam (THT) Ransomware Disrupts US Cancer Hospital and Risks Patient Lives

The Department of Health and Human Services (HHS) has **released an alert** regarding a [ransomware-as-a-service](https://www.cloudflare.com/learning/security/ransomware/ransomware-as-a-service/) group that has resurfaced this week and disrupted a US cancer treatment facility.

The financially motivated RaaS group known as **THT (TimiSoaraHackerTeam)** was also in the news earlier when it attacked a hospital in France.

At present, it has created a stir by encrypting critical information files in an unnamed cancer facility in the USA. The attack [disrupted cancer treatment](https://www.aha.org/news/headline/2023-06-20-hhs-alerts-health-sector-new-ransomware-threat) and **risked many patients’ lives** by blocking digital services and exposing confidential patient data.

Though THT is not a well-known threat group, it may have connections with China and Eastern Europe and links with other threat actors like APT 41 and DeepBlueMagic. A unique characteristic of the group is its **use of legitimate computing tools** like Jetico’s BestCrypt and Microsoft’s Bitlocker.

[![ransomware report](https://media.mailhop.org/duocircle/images/2023/06/what-is-dmarc.jpg)](https://media.mailhop.org/duocircle/images/2023/06/what-is-dmarc.jpg)

FBI and CISA (Cybersecurity & Infrastructure Security Agency) have urged users to **report** if any traces of THT activity is noticed immediately. Users must always be prepared with proper cybersecurity tools and safeguards for [ransomware protection](/resources/locky-ransomware) to stay safe from THT and similar groups.

## Ukrainian Cyber Police Busts Crypto Malware Group Targeting Canadians

Two Ukrainian residents targeting **foreigners’ crypto wallets** through a fake call center have been apprehended by the Ukraine Cyber Police force.

The fraudulent call center set up by two Ukrainian residents in the Khmelnytskyi region to steal money from foreign residents, especially those in Canada, [has ended](https://cyberpolice.gov.ua/news/pryvlasnyly-kryptovalyutni-aktyvy-inozemnyx-gromadyan-kiberpolicziya-vykryla-organizatoriv-shaxrajskogo-call-czentru-7229/) with the intervention of the law enforcement division of Ukraine.

The call center recruited staff through a highly professional interview process, and the candidates had to pass English proficiency and polygraph tests. Through the recruited staff, they reached out to foreign residents in countries like Canada through calls and text messages, **offering benefits** from stock trading.

They urged the customers to install software in their systems to receive the profits. The installed **malware** gets hold of customers’ [crypto wallets](https://www.infosecurity-magazine.com/news/crypto-wallets-attacked/), usernames, passwords, and account details.

Ukraine Cyber Police have confiscated money from the threat actors that they have made illegitimately, besides SIM cards, mobile phones, and computer systems. Those who handle cryptocurrency must remain **utterly alert** and use updated cybersecurity tools to stay safe from the clutches of such malicious crypto groups.

## Millions of Organizations and Customers Vulnerable to Repo Jacking on GitHub Repositories

Aqua Nautilus has discovered [vulnerabilities](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/) in **GitHub datasets** that can severely impact millions of organizations and their customers.

GitHub’s repositories with **retired names** of some existing organizations have information easily accessible to malicious actors. While the organizations’ data may be secure currently, anyone can easily access the **confidential information** associated with them from the repositories if they had an entry there previously with a different name which may be retired now.

Vulnerable organizations include big names like [Google, Lyft](https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking?&web%5Fview=true), and others who prefer to **remain anonymous**. Some such major brands who discovered the risk have mitigated them immediately.

Aqua Nautilus examined a sample of 1.25 million names in repositories and found 36,983 vulnerable. It means there could be millions of vulnerable names, considering the total repository names to be more than 300 million.

[Malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/) can quickly get old retired names of organizations existing with different names through **online sources** like the GHTorrent project. Subsequently, they can look for those abandoned names in GitHub and hijack the repositories (hence the name Repo Jacking) to access confidential information of the organizations and their customers.

Users must refrain from abandoning the ownership of their old names to avoid such repository hijacking and claiming of the old names by malicious actors. _They must also **be cautious** when involved in mergers and acquisitions resulting in a name change._

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Camaro%20Dragon%20Returns%3A%20USB%20Malware%2C%20THT%20Ransomware%20Menace%2C%20Crypto%20Malware%20Syndicate%2C%20Cybersecurity%20News%20%5B19%20June%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Camaro Dragon Returns: USB Malware, THT Ransomware Menace, Crypto Malware Syndicate, Cybersecurity News [19 June 2023]","description":"Here is the latest cybersecurity news to be aware of to stay protected from the clutches of malicious cyber-attacks that may pop up any moment with phishing.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/","datePublished":"2023-06-19T17:11:26.000Z","dateModified":"2025-05-09T17:15:16.000Z","dateCreated":"2023-06-19T17:11:26.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":840,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/smtp-service.jpg","caption":"cybersecurity-news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Camaro Dragon Returns: USB Malware, THT Ransomware Menace, Crypto Malware Syndicate, Cybersecurity News [19 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Camaro Dragon Returns: USB Malware, THT Ransomware Menace, Crypto Malware Syndicate, Cybersecurity News [19 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Camaro Dragon Returns: USB Malware, THT Ransomware Menace, Crypto Malware Syndicate, Cybersecurity News [19 June 2023]","description":"Here is the latest cybersecurity news to be aware of to stay protected from the clutches of malicious cyber-attacks that may pop up any moment with phishing.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/","datePublished":"2023-06-19T17:11:26.000Z","dateModified":"2025-05-09T17:15:16.000Z","dateCreated":"2023-06-19T17:11:26.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":840,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/smtp-service.jpg","caption":"cybersecurity-news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
