---
title: "Cybersecurity News Update, Week 3 of 2023 | DuoCircle"
description: "Threat actors are leaving no quarter when it comes to carrying out malicious activities in the new year."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/"
---

Quick Answer

Six items. Threat actors are exploiting a CWP (Control Web Panel) flaw (CVE-2022-44877) for unauthenticated remote code execution; CISA added it to the KEV catalog. Doctor Web found seven Android TV box models, including AllWinner-T95, sold on Amazon with pre-installed malware. MetaMask warned of address-poisoning scams: attackers send zero-value transactions from spoofed addresses similar to ones the victim has previously used, hoping the victim will copy the wrong address from history. The Vice Society ransomware crew hit the Country Fire Authority of Australia. The Dark Pink APT is targeting government and military targets across the APAC region with the custom KamiKakaBot malware. And the Liquor Control Board of Ontario disclosed a Magecart skimmer on its e-commerce site that captured cardholder data over five days.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-3-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%203%20of%202023&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-3-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-3-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-3-of-2023%2F&title=Cybersecurity%20News%20Update%2C%20Week%203%20of%202023 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%203%20of%202023&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-3-of-2023%2F "Share via Email") 

![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/smtp-service-7512.jpg) 

Threat actors are leaving no quarter when it comes to carrying out **malicious activities** in the new year. This week’s headlines cover top cybersecurity news from around the world, from exploited CWP, Android TVs with pre-installed malware, new address poisoning crypto scams, vice society [ransomware](/resources/ryuk-ransomware-attacks) attacking Australian firefighters, custom info-stealing malware targeting APAC governments, and Ontario’s liquor control board being hacked. Let us get started.

## Threat Actors Exploiting Control Web Panel Flaws for RCE

Threat actors are exploiting the **CWP (Control Web Panel)** using a critical vulnerability identified as [CVE-2022-44877](https://nvd.nist.gov/vuln/detail/CVE-2022-44877).

With a critical severity score of 9.8, the vulnerability gives threat actors the ability of [RCE (Remote Code Execution)](https://www.crowdstrike.com/cybersecurity-101/remote-code-execution-rce/#:~:text=Remote%20code%20execution%20%28RCE%29%20refers,for%20user%20input%20from%20you.) without the need to authenticate. Researchers at Gais Cyber Security were the first to report the issue in October 2022\. The organizations released the CWP [version 0.9.8.1147](https://control-webpanel.com/changelog#1669855527714-450fb335-6194) to stop the threat actors from using this flaw for malicious purposes.

However, Shadowserver has recorded threat actors’ malicious activity, indicating that [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) are still using the CVE-2022-44877 to spawn terminals for interaction with machines. Hackers are **exploiting the CWP** to start reverse shells with encoded payloads that call the threat actor’s machine and spawn the terminal on the victim’s machine using pty Module of Python.

Since the vulnerability is being exploited right now, it would be best to update to the [latest version](https://control-webpanel.com/changelog) of CWP.

[![Cyber Security](https://media.mailhop.org/duocircle/images/2023/01/spf-record-tester-7513.jpg)](https://media.mailhop.org/duocircle/images/2023/01/spf-record-tester-7513.jpg)

## Android TV Boxes with Pre-Installed Malware

An Android TV box purchased from Amazon, delivered to a Canadian systems security consultant, came **preloaded with malware**.

Widely available on Amazon, a T95 Android TV box with an AllWinner T616 processor came pre-installed with malware. The device uses the [ADB (Android Debug Bridge)](https://www.makeuseof.com/tag/new-adb-make-process-simple-easy/), which is a suspicious configuration that threat actors can use to connect to home devices for **unrestricted access** to the filesystem, _execute commands, install malicious software, modify data, and control the device remotely._

Daniel Milisic, the individual who received the device, explains how he bought the device to run the **Pi-hole DNS sinkhole**. While analyzing the [DNS (Domain Name System)](https://www.techtarget.com/searchnetworking/definition/domain-name-system), Milisic discovered that his Android TV was connected to multiple IPs (Internet Protocols) associated with malware.

The malware on his device resembled [CopyCat](https://www.cnet.com/news/privacy/android-hack-copycat-malware-device-outdated-14-million/), an **Android malware** that has been around since 2017, which begs the question, “If the devices ordered from online services, which are supposed to be brand new, are coming with malware, how can any individual stay safe?”

Milisic has shared a [detailed analysis](https://github.com/DesktopECHO/T95-H616-Malware) of the experience and has shown steps you can follow to check if your devices contain malware.

## Address Poisoning Cryptocurrency Scams on the Rise, Warns MetaMask

MetaMask, one of the most significant cryptocurrency wallet providers worldwide, has warned [crypto enthusiasts](https://www.pcmag.com/encyclopedia/term/crypto-enthusiast#:~:text=A%20person%20who%20is%20a,problems%20both%20financially%20and%20politically.) and users of a new “**Address Poisoning**” scam being used by threat actors to trick individuals into sending funds to scammers.

Whenever crypto is traded, the transaction is added to the transaction list, allowing users to check its details, including the token, the crypto amount exchanged, and the shortened address of the third party. The new [scam](https://web.archive.org/web/20231101152810/https://www.outlookindia.com/business/crypto-year-ender-here-s-a-look-at-major-crypto-scams-of-2022-news-249348) involves poisoning the **wallet’s transaction history** by replacing trusted addresses with scamming ones similar to the ones replaced so the threat actors can gain crypto.

The threat actors select a target, use vanity address creators to create a similar address, and send the target some crypto to get into the wallet history in the hope that the individual will send crypto to their wallet since the address would appear similar to that of previous contacts.

To steer clear of the scam, MetaMask has [recommended](https://metamask.zendesk.com/hc/en-us/articles/11967455819035-Address-poisoning-scams) that its users use the Address Book Feature to save genuine crypto addresses as contacts. _You can access the feature by navigating to Settings > Contacts._

## Vice Society Ransomware Attack on Australian Firefighters

**Australia’s Fire Rescue Victoria** was the victim of a cyberattack in December, the details of which have been recently disclosed. The [Vice Society ransomware gang](https://www.bleepingcomputer.com/news/security/vice-society-ransomware-gang-switches-to-new-custom-encryptor/) is claiming responsibility for the data breach.

FRVP (Fire Rescue Victoria) has over 4500 operational and corporate employees that operate over 85 stations in Victoria. The cyberattack on FRVP occurred on 15 December 2022, affecting the internal servers of the organization. The threat actors disrupted FRVP’s IT systems and stole significant data about current and former employees, job applicants, and contractors. The FRVP released a [notice](https://www.frv.vic.gov.au/sites/default/files/2023-01/FRV-OAIC-Data-Breach-Notification-6-January-2023.pdf) outlining the stolen information, which includes:

- Full Name
- Date of birth
- Health information
- Superannuation details
- Government-issued identity information
- Driver’s license details
- Passport details
- Tax File numbers
- Birth, death, and marriage certificates
- Residential Address (current and previous)
- Email address (current and previous)
- Phone number (current and previous)
- Bank account details (BSB, account name, and number)
- Sensitive information like sexual orientation, race, disability, religion, qualifications, employment history, criminal history, and political or religious views.

The threat actors also accessed FRVP’s email system, which is still offline, meaning they could have accessed or **stolen email communications**. FRVP has recommended that all its staff reset their passwords, implement [MFA](https://www.onelogin.com/learn/what-is-mfa), and change reused passwords if any. On the other hand, Vice Society added an entry for FRVP on their Tor data leak site, with a link to the stolen information on 10 January 2023.

[![cybersecurity enterprise](https://media.mailhop.org/duocircle/images/2023/01/buy-smtp-7514.jpg)](https://media.mailhop.org/duocircle/images/2023/01/buy-smtp-7514.jpg)

## Dark Pink APT Targeting Governments with Custom Malware

Cyberattacks targeting **military bodies and government agencies** have been rising, with threat actors utilizing a new advanced custom malware designed to steal confidential data.

Called the **Dark Pink** by Group-IB’s researchers, the threat actors employ uncommon tactics with a custom toolkit that spreads malware via USB drives and steals information. Security researchers at Group IB have [outlined](https://www.group-ib.com/media-center/press-releases/dark-pink-apt/) that the threat actors behind the malware campaign steal information from the victim’s browsers, and messengers, exfiltrate documents and **eavesdrop via microphones** on infected devices.

Considered an [APT (Advanced Persistent Threat),](https://www.imperva.com/learn/application-security/apt-advanced-persistent-threat/#:~:text=What%20is%20an%20APT,to%20mine%20highly%20sensitive%20data.) the threat actors utilize spear phishing emails as the initial compromise, deploying its two custom info-stealing malware dubbed Cucky and Ctealer, target governments in the APAC (Asia-Pacific) region. With [DLL (Dynamic Link Library)](https://www.techtarget.com/searchwindowsserver/definition/dynamic-link-library-DLL) sideloading, event-triggered execution methods, and leveraging MS Office documents inside ISO files, the threat actors are a significant threat.

The threat actor group has had seven successful attacks in the second half of 2022, and Anheng Hunting Labs, a **Chinese cybersecurity enterprise**, is also tracking the threat actor’s activities.

## Liquor Control Board of Ontario Hacked to Steal Credit Cards

The [LCBO (Liquor Control Board of Ontario)](https://en.wikipedia.org/wiki/Liquor%5FControl%5FBoard%5Fof%5FOntario), the largest alcohol retailer in Canada, was breached by threat actors trying to **inject malicious code** to steal customer credit card information.

LCBO revealed that threat actors hacked its website, and the **third-party forensic investigators** that the organization hired revealed that they found a credit card stealing script which stayed active on LCBO’s website for an alarming 5 days between January 5, 2023, and January 10, 2023.

The organization has clarified in its [statement](https://web.archive.org/web/20250503171205/https://www.lcbo.com/content/lcbo/en/corporate-pages/about/media-centre/news/2023-01-12.html) that the customers who entered their personal information on **checkout pages** between the above dates and proceeded for payments may have been a victim of the attack and had their information compromised.

However, LCBO is investigating the attack and finding out all affected customers. The malicious script was active on the site allowing threat actors to harvest both personal and financial information at checkout. The stolen information includes customer names, email addresses, credit card information, Aeroplan numbers, and account passwords.

LCBO has over 8000 employees, with 680 retail stores and 5 regional warehouses. An attack on the organization shows that threat actors target all industries in novel ways each time.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 3 of 2023","description":"Threat actors are leaving no quarter when it comes to carrying out malicious activities in the new year.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/","datePublished":"2023-01-15T20:10:50.000Z","dateModified":"2025-05-20T13:20:27.000Z","dateCreated":"2023-01-15T20:10:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1222,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/01/smtp-service-7512.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 3 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 3 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 3 of 2023","description":"Threat actors are leaving no quarter when it comes to carrying out malicious activities in the new year.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/","datePublished":"2023-01-15T20:10:50.000Z","dateModified":"2025-05-20T13:20:27.000Z","dateCreated":"2023-01-15T20:10:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-3-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1222,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/01/smtp-service-7512.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
