---
title: "Cyber Security News Update, Week 36 of 2021 | DuoCircle"
description: "Cybersecurity headlines are again crowded with news of unfortunate cyber attacks."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/"
---

Quick Answer

Cybersecurity headlines for the week of September 4, 2021\. Researchers debated whether moving security to the cloud is automatically a win, citing recent misconfigurations and supply chain incidents. Trend Micro tracked the Earth Baku APT (linked to APT41) targeting governments and tech firms in the Indo-Pacific with the StealthVector loader. DeFi rug pulls and exit scams continued to climb, with one project draining roughly $30 million in user funds. Phishing pages and Discord scams promised early access to Kanye West's Donda album to steal credentials and cryptocurrency. SentinelOne linked the ShadowPad backdoor to multiple Chinese state-aligned groups, including APT41 and Tonto Team. Bumble fixed a flaw that exposed users' precise location through trilateration of distance values returned by its API.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2036%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2036%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2036%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F "Share via Email") 

![Cybersecurity](https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3333.jpg) 

Cybersecurity headlines are again crowded with news of unfortunate cyber attacks, which serve as a good reminder of why it is crucial to have **adequate cybersecurity** measures in place at the organizational level and follow cyber hygiene [best practices](/content/protection-from-phishing) at the individual level. Following are the major security headlines of this week.

## Is Cloud Really The Best Security Option?

_A 40-year-old California man named Hao Kuo Chi has been providing hacker-for-hire services_ and helping people [steal private videos or pictures](https://threatpost.com/man-hacked-icloud/168923/) of iCloud users. Going by the name of _icloudripper4you_, Chi has stolen over **620,000 sensitive images** and videos of Apple users who may have used the iCloud service to store their private content safely.

Chi pretended to be an Apple customer support technician and used [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) to get the iCloud user ID and password of **over 4700 users** who had willingly sent their details to two legitimate-looking fake email accounts he created. Chi has been allegedly in this business since March 2018, but when the _FBI could trace back a victim’s compromising pictures to the IP address of Chi’s home computer_, they could get a search warrant. The raid at Chi’s house provided ample evidence of his malicious cybercrime. Finally, Chi agreed to plead guilty for three incidents of gaining unauthorized access to victim computers and one instance of conspiracy. _He is likely to be sentenced to five years in prison for each of these cybersecurity breaches_.

[![social engineering ](https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3332.jpg)](https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3332.jpg)

## Earth Baku Targets Industries in The Indo-Pacific Region

As per the latest reports from Trend Micro, the threat actor Earth Baku, or APT41, has been [targeting organizations in the Indo-Pacific region](https://web.archive.org/web/20230325195750/https://cyware.com/news/earth-baku-apt41-active-target-victims-in-indo-pacific-region-69b9cefc) with cyberespionage attacks since July last year. Earth Baku uses several attack vectors like installer tool InstallUtil\[.\]exe, malicious email attachment, **SQL injection**, and the CVE-2021-26855 vulnerability to attack public and private entities working in the Indo-Pacific region. The APT41 threat actor group also used shellcode loaders (StealthMutant and StealthVector) and a backdoor (ScrambleCross) to attack the Indo-Pacific region countries, including India, Vietnam, Taiwan, Indonesia, Malaysia, and the Philippines.

_Earth Baku has been operating since November 2018_, but it seems like some new and skilled experts in low-level programming and software development have joined the group. Since their recent attacks are primarily targeted at the industries in the Indo-Pacific region, cybersecurity tools must be adopted by stakeholders in these nations as there can be more **APT41 attacks** in the near future.

## DeFi Scams on The Rise, Investors Beware

_DeFi platforms have attracted a lot of global crypto investors over the last year_. And it is also turning out to be a goldmine for cyber attackers who are eventually discovering ways of hacking into these newly emerged digital trading platforms. A report by Atlas VPN suggests that 76% of all [financial hacks](https://www.techrepublic.com/article/dont-get-rugged-defi-scams-go-from-zero-to-129-million-in-a-year-to-become-top-financial-hack/) in the first half of 2021 targeted DeFi platforms as opposed to a mere 25% in the previous year. _The rise of DeFi hacks is evident in the attack stats of the last three years_, where $0 was lost to hacks in 2019, **$129 million** in 2020, and $361 million in the first half of 2021.

_It isn’t surprising that DeFi attacks are the most common cause of financial loss in recent times_, having surpassed the losses from ransomware and **phishing attacks**. Cybersecurity experts at Atlas VPN remark that developer incompetencies in DeFi projects are a significant factor in inviting malicious actors. _Millions are being lost to rug pull where scammers hype up the value of a coin and then disappear with all the investors’ money_. Investors must watch out for new coins promising significant gains because, as tempting as they may look, they may rob you of all your invested amount.

## Beware of Scams That Promise Early Access to Kanye’s New Album

When the world goes hysterical, and there is the hype about something, be it a pandemic, vaccination drive, or an album release (as in this case), _the adversaries view this as an opportunity to trick people and make them download malware_. The [latest cybersecurity](/announcements) incident to draw the attention of Kaspersky experts is the spread of malicious _Black Window_ files by adversaries in the name of [Kanye West’s latest album](https://www.techrepublic.com/article/kanyes-upcoming-album-is-a-scam-magnet-kaspersky-finds/#ftag=RSS56d97e7), “Donda.”

Though this **attack scheme** isn’t being used on a broader scale, the adversaries are still trying to deceive people with the bait of early access to Kanye’s album. _An excited fan cannot reason and makes an impulsive click when they find any file promising to be the latest album or song_. This lack of precaution is causing attackers to spread two adware files among Kanye fans. These files go by the name of _DONDA (Explicit) (2021) Mp3 320kbps \[PMEDIA\] \_\_, Downloader.exe_ and _Download-File-KanyeWestDONDA320.zip\_88481.msi_. The adversaries either send a link to directly download Kanye’s new album or fill a survey form first. This form collects the PII (Personally Identifiable Information) of unsuspecting users before redirecting them to the website, where they are promised early access to the album but instead have [malware downloaded](/email-security/your-business-runs-on-email-dont-let-it-fall-to-malware/) into their systems.

## ShadowPad And Chinese Hacker Groups

_Chinese threat actors have been actively using a backdoor malware called ShowdowPad since 2017_. This [Windows backdoor](https://web.archive.org/web/20211020175552/https://cyware.com/news/shadowpad-a-high-in-demand-chinese-espionage-tool-593efcd1) comes with a lot of malicious advantages.

The espionage groups Operation Redbonus, APT41, Operation Redkanku, Tick & Tonto Team, and Fishmonger are among the primary users of ShadowPad as it provides them with anti-detection features at reduced maintenance costs. This **malware-as-a-service** is sold privately, where buyers are offered plugins for the malware platform separately. Further, it is open to deploying new plugins to a backdoor as long as one can correctly produce a plugin. Such _innovation and freedom to enhance malware is bad news for the lay netizen_. It motivates and empowers threat actors to adapt, innovate and experiment with malware at the expense of the cybersecurity of innocent users.

[![Hacker Groups](https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3331.jpg)](https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3331.jpg)

## Bumble Fixes Security Flaw Exposing Users’ Location

_A software engineer at Stripe, Robert Heaton, recently discovered a security vulnerability in the dating app Bumble_. The flaw could let attackers pretend to be app users looking for a date to pinpoint their location via a [trilateration attack](https://portswigger.net/daily-swig/trilateration-vulnerability-in-dating-app-bumble-leaked-users-exact-location). This flaw in Bumble’s interface was enabling malicious actors to stalk their potential victims.

Fortunately, _Bumble quickly responded to Heaton and fixed the issue within 72 hours of being approached_. In addition, Bumble introduced additional [email security](/) measures to prevent matching users to suspicious users or those not in their match queue.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2036%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 36 of 2021","description":"Cybersecurity headlines are again crowded with news of unfortunate cyber attacks.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/","datePublished":"2021-09-04T18:08:28.000Z","dateModified":"2025-05-16T15:03:05.000Z","dateCreated":"2021-09-04T18:08:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1059,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3333.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 36 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 36 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 36 of 2021","description":"Cybersecurity headlines are again crowded with news of unfortunate cyber attacks.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/","datePublished":"2021-09-04T18:08:28.000Z","dateModified":"2025-05-16T15:03:05.000Z","dateCreated":"2021-09-04T18:08:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1059,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/09/dkim-selector-3333.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
