---
title: "French Networks Hacked, Microsoft’s Spider Alert, Iranian Cyber Strikes, Cybersecurity News [October 23, 2023] | DuoCircle"
description: "Duocircle · French Networks Hacked, Microsoft’s Alert, Iranian Stay updated on the latest cybersecurity news."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/"
---

Quick Answer

Four items shaped the week of October 23, 2023\. The French ANSSI disclosed that Russian state hackers tracked as APT28 had breached French government, defense, aerospace, and research networks across multiple sectors, with intrusions dating back several years. Microsoft warned that the financially motivated Scattered Spider crew, previously known for SIM swap attacks, was now deploying ransomware including BlackCat after compromising help desks via social engineering. The Iranian group Tortoiseshell was observed delivering a refreshed IMAPLoader malware via fake job lures that abuses IMAP for command-and-control. European government email servers were compromised through an actively exploited zero-day in Roundcube webmail tracked as CVE-2023-5631, attributed to Russia-linked Winter Vivern.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=French%20Networks%20Hacked%2C%20Microsoft%E2%80%99s%20Spider%20Alert%2C%20Iranian%20Cyber%20Strikes%2C%20Cybersecurity%20News%20%5BOctober%2023%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F&title=French%20Networks%20Hacked%2C%20Microsoft%E2%80%99s%20Spider%20Alert%2C%20Iranian%20Cyber%20Strikes%2C%20Cybersecurity%20News%20%5BOctober%2023%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=French%20Networks%20Hacked%2C%20Microsoft%E2%80%99s%20Spider%20Alert%2C%20Iranian%20Cyber%20Strikes%2C%20Cybersecurity%20News%20%5BOctober%2023%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/10/hosted-email-server.jpg) 

Stay updated on the latest [cybersecurity](/) news, featuring crucial insights into **emerging threats** and [email protection](/email-services/what-is-post-delivery-email-protection-and-why-it-is-crucial/) measures with our weekly cybersecurity bulletin. Let’s take a look!

## France Reports Breach by Russian State Hackers Across Multiple Vital Networks

The [Russian](https://www.infosecurity-magazine.com/news/russia-apt28-attack-ukraine-power/) APT28 hacking group, known as ‘Strontium’ or ‘Fancy Bear,’ has been relentlessly targeting a **wide range of entities in France** since the latter half of 2021.

Considered an integral part of Russia’s military intelligence service GRU, APT28 was recently implicated in **exploiting CVE-2023-38831**, a Remote Code Execution (RCE) [vulnerability in WinRAR](https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/), and CVE-2023-23397, a zero-day privilege elevation flaw in Microsoft Outlook.

ANSSI’s [investigations](https://www.cert.ssi.gouv.fr/uploads/CERTFR-2023-CTI-009.pdf) unveiled APT28’s **sophisticated techniques**. Between March 2022 and June 2023, APT28 exploited the then [zero-day vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/), now identified as CVE-2023-23397, by sending emails to **Outlook users**. The core objective of these zero day attacks lies in data access and exfiltration. _ANSSI observed these threat actors retrieving **authentication details** using native utilities and pilfering emails containing sensitive information and correspondence_.

## Microsoft Issues Warning as Scattered Spider Broadens Tactics from SIM Swaps to Ransomware Attacks

The threat actor, Scattered Spider (Octo Tempest), has been observed adopting a cunning strategy in targeted organizations. They **impersonate newly hired** employees, seamlessly blending into standard on-hire procedures. This facade enables them to take over accounts and [breach organizations worldwide](https://edition.cnn.com/2023/06/15/politics/us-government-hit-cybeattack/index.html).

_Microsoft, shedding light on the activities of this financially motivated hacking crew, labeled them as “one of the most formidable financial criminal groups.”_ Microsoft [emphasized](https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/) its operational flexibility, integrating **SMS phishing**, [SIM swapping](https://www.bleepingcomputer.com/news/security/lapsus-hackers-took-sim-swapping-attacks-to-the-next-level/), and **help desk fraud** into its attack model seamlessly. Their ransomware attack campaigns feature Adversary-in-The-Middle (AiTM) techniques, social engineering, and SIM-swapping capabilities.

One of their signature techniques involves [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) attacks on support and help desk personnel. Their methods range from **purchasing employee credentials** on the criminal underground market to direct social engineering. They convince users to install [Remote Monitoring and Management (RMM)](https://www.techtarget.com/searchitchannel/definition/RMM-software-remote-monitoring-and-management-software) utilities, **visit fake login** portals using AiTM phishing toolkits, or even remove their FIDO2 tokens.

In a sinister evolution, Octo Tempest widened their targets to include **email and tech service providers**, gaming, hospitality, retail, [Managed Service Providers](/resources/best-msp-partner-programs-for-managed-service-providers) (MSPs), manufacturing, technology, and financial sectors. _Their end goals vary, ranging from cryptocurrency theft to data exfiltration for extortion and ransomware deployment._

[![Cybersecurity Threats ](https://media.mailhop.org/duocircle/images/2023/10/SMTP-server-mail.jpg)](https://media.mailhop.org/duocircle/images/2023/10/SMTP-server-mail.jpg)

## Tortoiseshell, an Iranian Cyber Group, Unleashes Fresh Wave of IMAPLoader Malware Attacks

The Iranian threat actor, Tortoiseshell, has recently been linked to **multiple watering hole** [malware attacks](https://www.bleepingcomputer.com/news/security/new-hiatusrat-malware-attacks-target-us-defense-department/) where a strain named IMAPLoader is deployed to target systems.

_IMAPLoader, described as a .NET malware, possesses the capability to identify victim systems using native Windows utilities._ It acts as a **downloader for subsequent payloads**, leveraging email as a Command-and-Control (C2) channel. Notably, it can execute payloads extracted from email attachments and is activated through new service deployments. Operating since at least 2018, Tortoiseshell has a well-documented history of employing strategic [website compromises](https://www.liquidweb.com/kb/what-indicates-a-compromised-website/) to distribute malware.

IMAPLoader, in fact, has replaced a **Python-based IMAP implant** previously utilized by Tortoiseshell in late 2021 and early 2022\. The change highlights the group’s adaptability, as the new malware exhibits similar functionality to its predecessor. The mechanism involves querying specific **hard-coded IMAP email accounts**. Additionally, PwC’s investigation [unveiled](https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/yellow-liderc-ships-its-scripts-delivers-imaploader-malware.html) several phishing sites created by Tortoiseshell.

High-stakes sectors like nuclear, aerospace, and defense [industries in the U.S.](https://www.bbc.com/news/world-asia-65705198) and Europe, along with IT MSPs in the Middle East, are under **imminent threat** from this sophisticated threat actor.

## European Government Email Servers Breached Utilizing Roundcube Zero-Day Exploit

The Winter Vivern Russian hacking group has been exploiting a recently discovered Roundcube Webmail zero-day vulnerability, posing a significant threat to **email servers** for various European government entities and think tanks since at least October 11.

The Roundcube development team swiftly **released crucial security updates**, addressing the [Stored Cross-Site Scripting (XSS)](https://crashtest-security.com/stored-xss-attack/) vulnerability (CVE-2023-5631) identified by diligent ESET researchers on October 16\. These security patches arrived just in time, five days after ESET [uncovered](https://www.welivesecurity.com/en/eset-research/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers/) Russian threat actors employing the zero-day attack in real-world attacks.

They utilized **HTML email messages** containing meticulously crafted [SVG documents](https://thehackernews.com/2022/12/hacking-using-svg-files-to-smuggle-qbot.html) to remotely inject arbitrary JavaScript code. In their deceptive phishing attempts, these hackers **impersonated the Outlook Team**. Tricking unsuspecting victims into opening malicious emails, which automatically triggered a first-stage payload exploiting the Roundcube email server vulnerability.

Recent attacks between August and September 2023 exploited the [Roundcube XSS vulnerability](https://cybersecuritynews.com/roundcube-webmail-xss-vulnerability/) (CVE-2020-35730), as per ESET telemetry data. _It’s worth noting that this **same vulnerability** was exploited by Russian APT28 military intelligence hackers._

Winter Vivern has shifted from known vulnerabilities in Roundcube and Zimbra, for which proofs of **concept are available online**, to using a zero-day vulnerability in Roundcube.

[![phishing protection](https://media.mailhop.org/duocircle/images/2023/10/smtp-service-7162.jpg)](https://media.mailhop.org/duocircle/images/2023/10/smtp-service-7162.jpg)

It would be highly beneficial to implement essential [phishing protection](/email/phishing-protection) solutions, such as advanced [email filtering](/content/email-filtering-service/email-filtering-security) and **security patches**, and also prioritize [phishing awareness training](/phishing-awareness-training) for employees to safeguard against such threats effectively.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=French%20Networks%20Hacked%2C%20Microsoft%E2%80%99s%20Spider%20Alert%2C%20Iranian%20Cyber%20Strikes%2C%20Cybersecurity%20News%20%5BOctober%2023%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"French Networks Hacked, Microsoft’s Spider Alert, Iranian Cyber Strikes, Cybersecurity News [October 23, 2023]","description":"Duocircle · French Networks Hacked, Microsoft’s Alert, Iranian Stay updated on the latest cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/","datePublished":"2023-10-30T17:59:37.000Z","dateModified":"2025-05-08T13:52:31.000Z","dateCreated":"2023-10-30T17:59:37.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":795,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/10/hosted-email-server.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"French Networks Hacked, Microsoft’s Spider Alert, Iranian Cyber Strikes, Cybersecurity News [October 23, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"French Networks Hacked, Microsoft’s Spider Alert, Iranian Cyber Strikes, Cybersecurity News [October 23, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"French Networks Hacked, Microsoft’s Spider Alert, Iranian Cyber Strikes, Cybersecurity News [October 23, 2023]","description":"Duocircle · French Networks Hacked, Microsoft’s Alert, Iranian Stay updated on the latest cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/","datePublished":"2023-10-30T17:59:37.000Z","dateModified":"2025-05-08T13:52:31.000Z","dateCreated":"2023-10-30T17:59:37.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":795,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/10/hosted-email-server.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
