---
title: "Cyber Security News Update, Week 44 of 2021 | DuoCircle"
description: "The pandemic has fueled the use of online applications and services."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/"
---

Quick Answer

Week 44 of 2021 covered six items. Researchers warned that fake versions of popular Android apps were no longer rare, with cloned banking and wallet apps appearing on third-party stores and even slipping past Google Play review. Juniper Networks released patches across Junos OS and Contrail Networking covering high-severity remote code execution and privilege escalation flaws. Attackers were observed abusing Discord's CDN to host malware payloads delivered through phishing and pirated software, taking advantage of trusted domains to bypass URL filtering. A US court sentenced a member of the FIN7 cybercrime group to 10 years in prison for his role in stealing tens of millions of payment card records. Separately, a defendant who profited from years of selling stolen credentials received a multi-year sentence. South African police arrested eight men running a romance scam ring that defrauded women on dating apps out of hundreds of thousands of dollars.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2021%2F "Share via Email") 

![Cyber Security News Update](https://media.mailhop.org/duocircle/images/2021/10/SPF-record-checker-6824.jpg) 

The [pandemic](/email-security/global-email-security-opportunities-challenges-and-its-importance-post-covid-19/) has fueled the use of online applications and services. And even malicious actors are well aware of it, who continue to launch cyberattacks to rob you of your information or monetary assets. _This week’s headlines cover how a group of cyber adversaries conned people_ over a dating app in South Africa, among other significant cyber developments worldwide.

## Fake Applications No Longer a Rarity

_Cybersecurity researchers at Cyble Research Labs have discovered a phishing campaign targeting Android customers of Japan-based telecommunication services_. The adversaries were found spreading a fake app under the brand name of a popular telecommunication provider. They were able to **steal 2,900 credentials** from 797 Android and 2,141 iOS users. In a typical scam, the adversaries ask users for a couple of admin permissions and make users disable any Wi-Fi they may be connected to.

[![phishing protection](https://media.mailhop.org/duocircle/images/2021/10/DMARC-report-service-6148.jpg)](https://media.mailhop.org/duocircle/images/2021/10/DMARC-report-service-6148.jpg)

_The fake app directly leads to the telecommunications payment service’s official page and requires users to log in using a secret PIN_. Once they get the required details, these stolen credentials reach the adversaries’ mailbox directly via Simple Mail Transfer Protocol (SMTP). Email [phishing protection](/email/phishing-protection) can still be assured, but users need to be really updated and vigilant to be able to distinguish between a fake and a genuine app.

## Juniper Networks Patches Vulnerabilities

_Popular networking and cybersecurity solutions provider Juniper Networks recently released over 40 advisories patching more than 70 vulnerabilities_. A majority of the patched flaws were described as critical and [high-severity vulnerabilities](https://www.securityweek.com/juniper-networks-patches-over-70-vulnerabilities). These flaws could be easily exploited to launch **denial-of-service** (DoS) attacks, privilege escalation, and remote code execution attacks. The patched flaws primarily affected Juniper’s Junos OS operating system.

Anyone looking for **critical severity flaws** must be looking at two particular advisories, one of which addresses a dozen vulnerabilities in third-party components and dates back to 2017\. The other provides fixes for an authentication bypass vulnerability in 128 Technology Session Smart Routers. _Workarounds and mitigations can also be found, along with updates for some vulnerabilities_. Fortunately, Juniper’s cybersecurity tools could not detect any evidence of the exploitation of any of the now patched vulnerabilities. The US Cybersecurity and Infrastructure Security Agency (CISA) advises organizations to implement Juniper’s patches as soon as possible.

## Attackers Using Discord to Deploy Malware

_Popular instant messaging application Discord is being actively used by adversaries to deploy malware on user devices_. **Over 140 million** users have been affected in 2021 by these [malicious files circulating on Discord](https://www.riskiq.com/blog/external-threat-management/discord-cdn-abuse-malware/). People use Discord to share texts and audio files in topic-based channels stored on its Content Delivery Network (CDN) servers. However, people don’t realize that many of these files hosted on Discord’s own CDN are malicious and spread malware.

Discord, initially introduced to gear communication among gamers, has now been widely accepted in workplaces. This oversight can cause bad traffic to enter any organization’s network using Discord for its official communications. _There were **27 unique malware** families reported in Discord’s CDN_, which comprises four malware types. These are backdoors (e.g., AsyncRat), Spyware (e.g., Raccoon Stealer), Trojans (e.g., AgentTesla), and Password Stealers (e.g., DarkStealer). This incident hints at the growing compromise of CDNs by adversaries.

## There is a Penalty for Every Cybercrime

_The US Department of Justice (DoJ) recently sentenced two Eastern European men_, Pavel Stassi and Aleksandr Skorodumov for providing a safe space to the threat actors’ community. Stassi and Skorodumov from Estonia and Lithuania ran a bulletproof hosting service to [help adversaries quickly deploy malware](https://www.zdnet.com/article/us-judge-sentences-duo-for-roles-in-providing-bulletproof-hosting/). They provided a range of malware, malicious e-commerce platforms, tools, and materials to deploy malware. Fortunately, [cybersecurity watchdogs](https://www.phishprotection.com/watchdog/) could spot these threat actors on time, and now they have been sentenced to 24 and 48 months in jail, respectively.

_Stassi and Skorodumov’s bulletproof hosting service housed a range of malware payloads_, including Citadel, SpyEye, Zeus, and the Blackhole exploit kit. It also facilitated the creation of botnets. The accused have been in business from 2015 to 2019, along with Russian allies Aleksandr Grichishkin and Andrei Skvortsov. Reportedly, Grichishkin and Skvortsov were the founding members and managers of the [hosting service](/email-hosting/what-you-need-to-know-about-how-covid-19-has-impacted-email-hosting/), Skorodumov functioned as the lead system, and Stassi took care of general admin and marketing tasks. They helped their clients escape from the clutches of law enforcement. The four suspects pleaded guilty to one RICO conspiracy. Grichishkin and Skvortsov await their sentence, which will probably extend up to **20 years of imprisonment**, considering the intensity of their crimes.

## Seven Years of Compromising Data Has its Price

Popularly known as _TheDearthStar, Justin Sean Johnson was recently sentenced to seven years in prison for hacking into the University of Pittsburgh Medical Center_ (UPMC) network and [stealing their data](https://www.bleepingcomputer.com/news/security/man-gets-7-years-in-prison-for-hacking-65k-health-care-employees/) for over seven years. In early December 2013, Johnson hacked UPMC’s network and sold the PII (Personally Identifiable Information) of tens of thousands of UPMC employees on the **dark web**. Other _adversaries used this data to file fake 1040 tax returns_. They claimed false tax refunds **exceeding $1.7 million** and converted them into Amazon gift cards. Apart from that, _Johnson stole and sold over 90,000 data sets_ (non-UPMC) between 2014 and 2017.

[![cybersecurity](https://media.mailhop.org/duocircle/images/2021/10/DMARC-reporting-service-6248.jpg)](https://media.mailhop.org/duocircle/images/2021/10/DMARC-reporting-service-6248.jpg)

With over 40 hospitals and 90,000 employees, UPMC is the largest [healthcare provider](/phishing-protection/now-we-know-why-the-healthcare-industry-is-so-vulnerable-to-ransomware/) and insurer in Pennsylvania. When Johnson broke into the human resources databases of UPMC, he stole the PII of over **65,000 employees** and sold it on the dark market. He was finally penalized for his crimes in 2020, and he pleaded guilty to stealing UPMC data a year later in 2021\. The compromised data of UPMC employees include their names, addresses, social security numbers, and salary details. During this time, _he frequently kept visiting the UPMC database to steal the PII of employees_. This is a scary scenario of an attacker constantly spying over a confidential network for years at a stretch. Such instances are evidence of [cybersecurity](/email-security/why-cybersecurity-compliance-is-of-utmost-importance-when-youre-starting-with-your-online-business/) taking a backseat and vulnerabilities in networks going unnoticed for years, thereby causing irreparable loss to the associated people.

## Eight Arrested in South Africa For Conning People on Dating Apps

Finding a companion online is every person’s dream today, but there are bad guys out there who use people’s emotional vulnerability for their benefit. The South African law enforcement agencies recently [arrested eight such fraudsters in Cape Town](https://www.straitstimes.com/world/south-africa-cracks-down-on-online-dating-scam). _These were eight foreign nationals who won the trust of widows and divorcees on online dating apps and stole over **US$6.9 million** from them_. These notorious threat actors created fake profiles on dating apps and established genuine romantic relationships with the victims. They then used sob stories to extract financial ‘help’ from these unsuspecting users. They stopped texting the victims once the money was transferred to their accounts.

During the raid, the South African police also found evidence of the use of [Business Email Compromise](/email-security/top-strategies-to-avoid-business-email-compromise-and-upgrade-email-security/) (BEC) tactics to divert funds. The USA played a significant role in the raid and arrests. It is suspected that the cyberattacks have ties to an international crime syndicate with roots outside South Africa. While the arrested eight adversaries will be penalized for committing mail and financial fraud, you must remember that thousands of such threat actors are waiting for you to fall into their trap. Hence, you must use dating applications or any online service with extreme caution by following basic [cyber hygiene practices](/email-security/comprehensive-email-security-checklist-for-any-business-domain/).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 44 of 2021","description":"The pandemic has fueled the use of online applications and services.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/","datePublished":"2021-10-29T14:48:46.000Z","dateModified":"2025-05-27T11:00:59.000Z","dateCreated":"2021-10-29T14:48:46.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1198,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/SPF-record-checker-6824.jpg","caption":"Cyber Security News Update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 44 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 44 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 44 of 2021","description":"The pandemic has fueled the use of online applications and services.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/","datePublished":"2021-10-29T14:48:46.000Z","dateModified":"2025-05-27T11:00:59.000Z","dateCreated":"2021-10-29T14:48:46.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1198,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/SPF-record-checker-6824.jpg","caption":"Cyber Security News Update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
