---
title: "Cybersecurity News Update, Week 45 of 2022 | DuoCircle"
description: "Fighting cybercriminals and staying safe demands the knowledge of cybersecurity’s latest."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/"
---

Quick Answer

Week 45 of 2022 covered six items. CISA warned that energy-sector firms were being breached through unpatched web server flaws including Log4Shell, with attackers establishing persistence months after initial compromise. The Sharkbot Android banking trojan reappeared in two file-management apps on Google Play that quietly side-loaded the malware after install. Robinhood disclosed a credential-stuffing-driven theft of roughly $300,000 worth of crypto from customer accounts that lacked MFA. A malicious Chrome extension named VenomSoftX targeted cryptocurrency users by intercepting transactions and rewriting wallet addresses inside the browser. The alleged leader of the Zeus and Maksik banking-malware crew was arrested in Switzerland after years on the run. Researchers tied a fresh wave of attacks against European government and defense organizations to North Korea's Lazarus group, using fake job lures and signed loaders.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2045%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F&title=Cybersecurity%20News%20Update%2C%20Week%2045%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2045%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F "Share via Email") 

![cybersecurity update](https://media.mailhop.org/duocircle/images/2022/11/spf-validator.jpg) 

Fighting cybercriminals and staying safe demands the knowledge of cybersecurity’s latest. This week’s [cybersecurity](/) bulletin shares the latest cybersecurity news from around the world, sharing energy sector breaches, **Sharkbot** malware’s return via Android, $300,000 stolen in credential stuffing, crypto stealing chrome extensions, the arrest of [Zeus gang leader](https://securityaffairs.co/wordpress/138648/cyber-crime/zeus-gang-leader-arrested.html), and North Korean hackers targeting European organizations for financial gains.

## Energy Enterprises Breached due to Web Server Bugs

Malicious actors have breached multiple energy enterprises due to Microsoft web server bugs. Microsoft discontinued the web server in 2015, but the **security vulnerabilities** in the web server used by energy sector organizations have led to the breach.

The threat actors are believed to be **Chinese state-sponsored** cybercriminal groups that have targeted multiple electrical grid operators in India to compromise the country’s national emergency response system. They gained network entry utilizing Internet-facing **DVR/IP camera devices** for C2 (Command and Control) of malware infections and open-source tools. The attacks were discovered by Recorded Future in April 2022, which said that the threat actors compromised the Boa web server, a component used for login and access of [IoT (Internet of Things)](https://www.techtarget.com/iotagenda/definition/Internet-of-Things-IoT) device consoles.

The servers are being compromised due to an arbitrary file access vulnerability, the [CVE-2017-9833](https://nvd.nist.gov/vuln/detail/CVE-2017-9833), and an information disclosure vulnerability, the [CVE-2021-33558](https://nvd.nist.gov/vuln/detail/CVE-2021-33558). These vulnerabilities allow the attack’s threat actors to carry out **RCE (Remote Code Execution)** without authentication requirements.

[![Hive ransomware attack](https://media.mailhop.org/duocircle/images/2022/11/smtp-server-mail-3592.jpg)](https://media.mailhop.org/duocircle/images/2022/11/smtp-server-mail-3592.jpg)

Microsoft has clarified that the Boa servers ran IP (Internet Protocol) addresses listed in the **IOC (Indicators of Compromise)** published by Recorded Future. One of the most significant attacks where the Boa server was compromised was the [Hive ransomware attack](https://techcrunch.com/2022/10/25/tata-power-hive-ransomware/) on Tata Power last month, India’s largest power organization. 

## Sharkbot Malware Infecting Android File Manager Applications

The [Sharkbot banking Trojan](https://www.deccanherald.com/business/technology/banking-trojan-sharkbot-laced-app-detected-on-google-play-store-1165234.html) has been targeting devices posing as malicious Android File Manager applications on **Google Play**. The applications evade detection as they do not contain malware but fetch the malicious payload from remote sources after installation.

**The Sharkbot malware** has stolen financial information and login credentials by utilizing fake login forms over legitimate ones in banking applications. Analysts at Bitdefender have [uncovered](https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs/) the latest File Manager disguise of the Sharkbot malware and have reported them to Google, which has removed the **malicious applications** from Google Play. Still, thousands of innocent individuals have these applications installed and may be in harm’s way. These malicious applications are:

- _X-File Manager by Victor Soft Ice LLC, 10,000 downloads_
- _File Voyager by Julia Soft Io LLC, 5000 downloads_

Both applications perform anti-emulation checks for evasion detection and load the Sharkbot malware on Italian or Great British SIMs, making the **malware attack** a targeted campaign. Individuals who have the applications installed should remove these immediately and stick to official applications from genuine vendors for security purposes.

## $300,000 Stolen in Credential Stuffing Attack

**DraftKings**, a sports betting organization, was the victim of a [credential-stuffing attack](https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack/) where hackers made away with $300,000\. DraftKings is still [investigating](https://twitter.com/DK%5FAssist/status/1594547937115185152) the reports of multiple customers experiencing the attack.

All the hijacked accounts had a common **initial $5 deposit**, following which the threat actor altered the password and enabled [2FA (Two Factor Authentication)](https://www.investopedia.com/terms/t/twofactor-authentication-2fa.asp) using another number so the account holder could not access the account. Following the compromise, the threat actor withdrew as much finances as possible.The organization has revealed that they believe that the login information of compromised accounts was accessed from other websites where customers used the **same passwords** and has found no evidence that their own systems were breached.

Multiple affected customers have taken to social media channels to share their disdain. However, DraftKings has [clarified](https://twitter.com/DK%5FAssist/status/1594769117894279168) that a little **less than $300,000** were stolen by [cybercriminals](https://www.theguardian.com/technology/2022/nov/27/gangs-of-cybercriminals-are-expanding-across-africa-investigators-say), and the organization will compensate the customers who have been victims of the account.

DraftKings has also recommended that unaffected customers should **immediately implement 2FA** on their accounts, remove their financial information such as card numbers, and unlink bank accounts linked to their accounts _until the platform is safe_.

## Crypto Stealing Google Chrome Extension

**VenomSoftX**, a Google Chrome extension, is stealing information and cryptocurrency by copying the clipboard content while individuals browse the web. The extension has been stealing crypto since 2020 and has been disclosed by multiple security researchers before.

Fortinet’s researchers [identified](https://www.fortinet.com/blog/threat-research/vipersoftx-new-javascript-threat) the Chrome extension installed by [ViperSoftX Windows malware](https://thesecmaster.com/what-is-vipersoftx-malware-how-to-protect-from-vipersoftx-malware/), a RAT (Remote Access Trojan) and a cryptocurrency stealer. Avast has stopped nearly **93,000 ViperSoftX infection attempts** detected in Italy, Brazil, India, and the US. ViperSoftX is also distributed via torrent files linked to game cracks and software activators.

The extension downloads a malware loader that decrypts [AES (Advanced Encryption Standard)](https://www.geeksforgeeks.org/advanced-encryption-standard-aes/), creates various files to compromise devices and **diverts cryptocurrency transactions** to the threat actors’ wallet addresses that are hardcoded in the extension. The extension masquerades as “Google Sheets 2.1” or **“Update Manager”** to stay hidden on the victim’s devices and steals crypto by hooking API (Application Programming Interface) requests on popular exchanges that the victims have accounts on.

Individuals are advised to **check extensions** adequately before downloading them and should visit the browser’s extension page to determine if Google Sheets is installed as an extension and remove it. Cryptocurrency enthusiasts and investors should remove these extensions and clear the browsing data to ensure their removal.

[![ransomware](https://media.mailhop.org/duocircle/images/2022/11/email-sending-services-7904.jpg)](https://media.mailhop.org/duocircle/images/2022/11/email-sending-services-7904.jpg)

## Zeus Cybercriminal Ring Leader Arrested

Tank, the leader of the **JabberZeus cybercriminal gang**, has reportedly been arrested. The cybercriminal is awaiting extradition to the US but can still appeal the Swiss FOJ’s (Federal Office of Justice) decision.

**Vyacheslav Igorevich Penchukov**, known as Tank, was [arrested](https://krebsonsecurity.com/2022/11/top-zeus-botnet-suspect-tank-arrested-in-geneva/) last month in Geneva and has been attributed to multiple cyberattacks ranging from bank account theft to [ransomware](/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/). The threat actor is also a manager of the [Maze and Egregor ransomware](https://www.mimecast.com/content/egregor-maze-ransomware/) that popularized **double-extortion attacks**. The threat actor stole valuable information and pursued victims to demand ransoms.

_The **Tank** was also a prime suspect in 2021’s Ukrainian international law enforcement operation to target the ransomware gang’s members but evaded prosecution due to his political connections_. As a leader of the **Zeus cybercriminal gang**, Tank has stolen financial information and has been charged with conspiring to participate in “racketeering activity, conspiracy to commit computer fraud and identity theft, aggravated identity theft, and multiple counts of bank fraud,” along with eight other individuals.

The [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) conspirators were also apprehended earlier, who pleaded guilty in 2014, extradited from the UK and sentenced to 2 years and 10 months in prison.

## European Organizations Targeted by North Korean Hackers

**North Korean hackers** are using a new and updated version of the [DTrack backdoor](https://www.infosecurity-magazine.com/news/lazarus-dtrack-target-europe-and/) to target European and Latin American organizations. The tool is a modular backdoor with advanced capabilities that can be used as spyware, performing file operations, and exfiltrating data.

The DTrack backdoor was [analyzed](https://securelist.com/dtrack-targeting-europe-latin-america/107798/) by Kaspersky and had been increasing its activity in _India, Brazil, Germany, Mexico, Switzerland, Turkey, the US, and Italy_, targeting government research centers, policy institutes, IT and telecommunication service providers, and educational institutes.

DTrack is distributed disguised as files of authentic executables and is installed by breaching organizational networks using **stolen credentials** or exploiting Internet-exposed servers. The malware decrypts once installed, the payload is loaded by process hollowing and runs directly from the system’s memory. The new DTrack backdoor uses **API hashing** to load functions and libraries and has half the number of C2 servers as its predecessor at 3.

Kaspersky believes that **Lazarus**, a North Korean cybercriminal group is behind the DTrack backdoor and highlights that the threat actor uses the backdoor when there is potential for financial gains.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2045%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2022%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 45 of 2022","description":"Fighting cybercriminals and staying safe demands the knowledge of cybersecurity’s latest.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/","datePublished":"2022-11-25T19:37:43.000Z","dateModified":"2025-05-28T11:51:53.000Z","dateCreated":"2022-11-25T19:37:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1236,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/11/spf-validator.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 45 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 45 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 45 of 2022","description":"Fighting cybercriminals and staying safe demands the knowledge of cybersecurity’s latest.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/","datePublished":"2022-11-25T19:37:43.000Z","dateModified":"2025-05-28T11:51:53.000Z","dateCreated":"2022-11-25T19:37:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1236,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/11/spf-validator.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
