---
title: "LetMeSpy Privacy Breach, Anatsa Trojan Targets, Malvertising Threatens Cybersecurity, Cybersecurity News [26 June 2023] | DuoCircle"
description: "Here is the latest edition of the weekly cybersecurity bulletin to update you about the most recent news associated with the digital security landscape."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/"
---

Quick Answer

Four stories. Polish stalkerware vendor LetMeSpy was breached, with attackers wiping its servers and exfiltrating credentials and tracking data on tens of thousands of users. ThreatFabric warned that the Anatsa Android banking trojan, distributed through Google Play droppers posing as PDF readers, is now targeting customers of more than 600 banks across the U.S., U.K., Germany, Austria, and Switzerland. Malvertising on Google search results is delivering infostealers like Bumblebee, NetSupport, and IcedID through fake software download sites for tools like Cisco AnyConnect, GIMP, and Citrix. And the AEI Threat Report noted that ransomware actors increasingly target high-revenue organizations with double extortion to maximize payouts.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=LetMeSpy%20Privacy%20Breach%2C%20Anatsa%20Trojan%20Targets%2C%20Malvertising%20Threatens%20Cybersecurity%2C%20Cybersecurity%20News%20%5B26%20June%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F&title=LetMeSpy%20Privacy%20Breach%2C%20Anatsa%20Trojan%20Targets%2C%20Malvertising%20Threatens%20Cybersecurity%2C%20Cybersecurity%20News%20%5B26%20June%202023%5D "Share on Reddit") [ ](mailto:?subject=LetMeSpy%20Privacy%20Breach%2C%20Anatsa%20Trojan%20Targets%2C%20Malvertising%20Threatens%20Cybersecurity%2C%20Cybersecurity%20News%20%5B26%20June%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/07/dkim-selector.jpg) 

Here is the latest edition of the weekly [cybersecurity](/) bulletin to update you about the most **recent news** associated with the digital security landscape.

## Phone Tracking App LetMeSpy Claims Thousands of Users’ Privacy Breached After Being Compromised

LetMeSpy, a widespread **phone monitoring app** used for surveillance, has fallen victim to a recent attack. The app, known as stalkerware or spouseware, discreetly operates on Android phones, making it difficult to detect and remove. _The application uploads text messages, call logs, and precise location data to its servers without the user’s knowledge. It made it easy for the [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) to **track the victims** in real time._

The leaked data, analyzed by [TechCrunch](https://techcrunch.com/2023/06/27/letmespy-hacked-spyware-thousands/#:~:text=A%20data%20breach%20reveals%20the%20spyware%20is%20built%20by%20a%20Polish%20developer&text=A%20hacker%20has%20stolen%20the,company%20that%20makes%20the%20spyware.), contains call logs and text messages covering years since 2013\. The compromised database includes records of at least 13,000 devices, although some have minimal or no associated data.

The [LetMeSpy](https://web.archive.org/web/20230129013309/https:/www.letmespy.com/en/) website’s functionality appeared broken for a while, and its activity counters showed zero usage. The malicious actor responsible for the breach **remains unidentified**, but they claimed to have deleted LetMeSpy’s databases stored on the server.

A copy of the compromised database has surfaced online and was shared with TechCrunch by the transparency collective [DDoSecrets](https://securityboulevard.com/2021/03/unknown-hacker-grabs-gabs-data-ddosecrets-doesnt-leak-it/), with **limited distribution** to journalists and researchers due to personal information concerns.

This breach adds to a growing list of compromised [spyware](https://www.infosecurity-magazine.com/news/pegasus-spyware-found-high-risk/) and phone monitoring apps, **emphasizing the risks** associated with such tools. Xnspy, KidsGuard, TheTruthSpy, and Support King have also experienced similar breaches, highlighting the need for increased awareness and security measures surrounding such applications.

## Anatsa Android Trojan Expands Its Reach, Targeting Banking Information in the US, the UK, and Other Countries

Mobile [malware](/resources/malware-and-its-defense-mechanism) has [targeted](https://www.bleepingcomputer.com/news/security/anatsa-android-trojan-now-steals-banking-info-from-users-in-us-uk/) banking customers in the US, the U.K., Germany, Austria, and Switzerland since March of this year. Security researchers from [ThreatFabric](https://www.threatfabric.com/blogs/anatsa-hits-uk-and-dach-with-new-campaign) have discovered that the campaign distributes the Android banking trojan ‘Anatsa’ through the official **Android app store**, Google Play. 

In November 2021, ThreatFabric identified a previous Anatsa campaign on Google Play, where the **trojan** was disguised as various apps, leading to [300,000](https://www.bleepingcomputer.com/news/security/android-banking-malware-infects-300-000-google-play-users/) installations. After a six-month hiatus, the threat actors resumed their malicious activity by launching a new campaign, enticing victims to download Anatsa **dropper apps** from Google Play.

The dropper apps **mimic** legitimate office and productivity apps like PDF viewers and editor apps. When the malicious apps were reported and removed from the store, the attackers swiftly uploaded new dropper apps with different disguises.

Once installed, the [dropper apps](https://thehackernews.com/2022/10/these-dropper-apps-on-play-store.html) retrieve Anatsa payloads from GitHub, disguised as **text recognizer add-ons** for Adobe Illustrator. Anatsa then steals financial information through overlaying phishing pages and keylogging. 

[![Targeting Banking Information](https://media.mailhop.org/duocircle/images/2023/07/smtp-service.jpg)](https://media.mailhop.org/duocircle/images/2023/07/smtp-service.jpg)

The trojan targets nearly 600 [financial apps](https://thehackernews.com/2023/03/nexus-new-rising-android-banking-trojan.html) and utilizes the stolen information for on-device fraud, making it challenging for anti-fraud systems to detect. The stolen funds are converted into cryptocurrency and circulated through a network of **money mules**.

_Users are advised to **exercise caution**, avoid dubious publishers, check reviews for suspicious behavior patterns, and refer to the ThreatFabric_ _[report](https://www.threatfabric.com/blogs/anatsa-hits-uk-and-dach-with-new-campaign#:~:text=ever%2Dchanging%20fraud.-,Appendix,-Anatsa%20droppers) for identifying and removing Anatsa-related apps._

## Malvertising Emerges as a Sneaky Pathway for Infostealers and Ransomware Attacks

Malvertising is making a stir lately in the cybersecurity landscape. New research by Malwarebytes reveals a concerning rise in malvertising, with over 800 attacks reported in 2023, averaging almost 5 per day. 

Infostealer malware varieties like IcedID, Aurora Stealer, and BATLOADER are commonly delivered through these malicious ads, compromising **user credentials** and paving the way for future [ransomware attacks](/resources/ryuk-ransomware-attacks).

Ransomware gangs often **purchase stolen credentials** from initial access brokers, while some use malvertising directly to launch their attacks. Detecting malvertising is challenging as threat actors pose as legitimate brands, making it deceptive for users. Even Google experts struggle to identify malicious redirects. 

Organizations should focus on **advanced** [cybersecurity tools](https://www.zdnet.com/article/china-says-nsa-used-multiple-cybersecurity-tools-in-attacks-against-chinese-university/) to combat malvertising rather than solely relying on brand imitation detection. 

## AEI Reports Threat Actors Focus on High-Profit Organizations

[![Threat Actors ](https://media.mailhop.org/duocircle/images/2023/07/phishing-protection-7960.jpg)](https://media.mailhop.org/duocircle/images/2023/07/phishing-protection-7960.jpg)

An AEI (American Enterprise Institute) study found that [malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/) prefer to target highly profitable organizations with **abundant cash reserves** and significant advertising expenditures. 

The research analyzing cyberattacks from January 1999 to January 2022 suggests that successful organizations may be targeted for [industrial espionage](https://www.investopedia.com/terms/i/industrial-espionage.asp). The study also highlighted that many organizations fail to comply with the SEC (Securities and Exchange Commission) rules by **not reporting** cyberattacks.

However, the likelihood of reporting such incidents increases when subjected to external investor scrutiny and media coverage. The FBI [said](https://www.ic3.gov/Media/PDF/AnnualReport/2022%5FIC3Report.pdf) there is an increase in **potential losses** from cyberattacks and cyber fraud, reaching $10.2 billion last year compared to $6.9 billion in 2021.

FBI Deputy Director Paul Abbate [warned](https://www.fbi.gov/news/speeches/deputy-director-paul-abbates-remarks-at-the-2023-boston-conference-on-cyber-security) of the escalating threats, with over 100 ransomware variants wreaking havoc on businesses. Furthermore, ransomware, malware, and distributed denial of service (DDoS) attacks were identified as the **most damaging**, impacting organization valuations by turning off IT systems and denying access to data and services. 

The AEI researchers emphasized that the consequences of cybercrime extend beyond targeted establishments, adversely affecting peer organizations and the broader economy. Organizations linked to the primary victims experience average [losses of 44%](https://www.aei.org/wp-content/uploads/2023/06/Scherbina-Schlusche-The-Effect-of-Malicious-Cyber-Activity-WP-updated.pdf?x91208) of the **financial damage** suffered by the immediate victim.

The researchers urged organizations to enhance their **ransomware protection** and cybersecurity measures to combat [cyber threats](https://tech.hindustantimes.com/tech/news/the-chatgpt-powered-cyber-threats-you-should-absolutely-know-about-71687843691873.html) effectively.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=LetMeSpy%20Privacy%20Breach%2C%20Anatsa%20Trojan%20Targets%2C%20Malvertising%20Threatens%20Cybersecurity%2C%20Cybersecurity%20News%20%5B26%20June%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-26-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"LetMeSpy Privacy Breach, Anatsa Trojan Targets, Malvertising Threatens Cybersecurity, Cybersecurity News [26 June 2023]","description":"Here is the latest edition of the weekly cybersecurity bulletin to update you about the most recent news associated with the digital security landscape.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/","datePublished":"2023-07-04T11:49:25.000Z","dateModified":"2025-05-15T17:37:47.000Z","dateCreated":"2023-07-04T11:49:25.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":847,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/dkim-selector.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"LetMeSpy Privacy Breach, Anatsa Trojan Targets, Malvertising Threatens Cybersecurity, Cybersecurity News [26 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"LetMeSpy Privacy Breach, Anatsa Trojan Targets, Malvertising Threatens Cybersecurity, Cybersecurity News [26 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"LetMeSpy Privacy Breach, Anatsa Trojan Targets, Malvertising Threatens Cybersecurity, Cybersecurity News [26 June 2023]","description":"Here is the latest edition of the weekly cybersecurity bulletin to update you about the most recent news associated with the digital security landscape.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/","datePublished":"2023-07-04T11:49:25.000Z","dateModified":"2025-05-15T17:37:47.000Z","dateCreated":"2023-07-04T11:49:25.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-26-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":847,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/dkim-selector.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
