---
title: "Cybersecurity News Update, Week 49 of 2022 | DuoCircle"
description: "The malicious activities of cybercriminals never stop, and neither does the cybersecurity news that we bring to keep you updated with the best of security."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/"
---

Quick Answer

Week 49 of 2022 covered six items. Cluster25 documented MirrorStealer, a credential-harvesting tool used in spear-phishing against Japanese politicians by the suspected APT group MirrorFace. Google rolled out client-side end-to-end encryption for Gmail on the web in beta, allowing Workspace administrators to use customer-managed encryption keys so message content stays unreadable to Google's servers. The FTC fined Epic Games $520 million for COPPA violations and dark patterns in Fortnite that pushed children into unwanted purchases. New York prosecutors charged two men with bribing JFK airport taxi dispatchers' systems on behalf of Russian hackers to skip the queue. LastPass disclosed that its August breach extended to a copy of its production customer vault data, including encrypted password vaults. Vice Society was observed deploying a custom encryptor named PolyVice using ChaCha20-NTRU as it shifted to a more durable affiliate platform.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2049%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2022%2F&title=Cybersecurity%20News%20Update%2C%20Week%2049%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2049%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2022%2F "Share via Email") 

![cybersecurity updates](https://media.mailhop.org/duocircle/images/2022/12/what-is-dkim-selector.jpg) 

The malicious activities of cybercriminals never stop, and neither does the cybersecurity news that we bring to keep you updated with the best of security. This week’s top [cybersecurity](/) news includes malware targeting Japanese politicians, **Gmail’s end-to-end encryption**, Epic Games’ $520 million fine, JFK’s taxi dispatch system hacking, LastPass’ cloud storage breach, and the new PolyVice encryptor. Let us take a look.

## MirrorStealer Malware Campaign Targeting Japanese Politicians

The MirrorFace hacking group has been targeting Japanese politicians with its [MirrorStealer malware](https://www.bleepingcomputer.com/news/security/hackers-target-japanese-politicians-with-new-mirrorstealer-malware/). The MirrorStealer campaign targeted politicians weeks before the election for the House of Councilors in July 2022.

ESET’s researchers who [discovered](https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/) the campaign reported that the threat actors left behind traces that led to the campaign’s discovery. The threat actors used **LODEINFO**, their signature information-stealing malware. LODEINFO has links to **APT10 infrastructure** and communicates with the C2 (Command and Control) server of the same. Back in October, Kaspersky also outlined the deployment of LODEINFO targeting Japanese targets and the development of a custom backdoor capability.

[![spear-phishing emails](https://media.mailhop.org/duocircle/images/2022/12/spf-record-checker-2536.jpg)](https://media.mailhop.org/duocircle/images/2022/12/spf-record-checker-2536.jpg)

During the July attacks, the **MirrorFace cybercriminal group**, which comprises members from APT10 and Cicada groups, sent out [spear-phishing emails](/content/spear-phishing-protection/spear-phishing-examples) impersonating PR agents of their political parties and sent video files, WinRAR archives, and more which contained an encrypted copy of the LODEINFO malware along with malicious [DLL (Dynamic-link library)](https://www.techtarget.com/searchwindowsserver/definition/dynamic-link-library-DLL#:~:text=A%20dynamic%20link%20library%20%28DLL%29%20is%20a%20collection%20of%20small,function%20of%20the%20original%20program.) loader.

LODEINFO deployed MirrorStealer on compromised systems which targeted **login credentials** stored in email clients and web browsers that were exfiltrated and sent to the C2 server. ESET discovered the campaign as APT10 did not remove the MirrorStealer text files with stolen credentials and left them on the compromised systems.

## End-to-end Encryption for Gmail Web

Google has announced its [E2EE (End-to-End Encryption)](https://www.geeksforgeeks.org/what-is-e2eeend-to-end-encryption/) for Gmail. The E2EE will allow individuals using Google Workspace or Gmail to send and **receive encrypted emails** both inside and outside the domain.

_Google’s E2EE has been in the market for some time and is available on Google Drive, Docs, Sheets, Slides, Meet, and Calendar._ Google’s E2EE can be **enabled to encrypt data** to ensure that any data as part of an email, including the body and any attachments, are not decrypted by Google’s servers. The only thing not encrypted is the email header, as it includes timestamps and recipient lists.

Individuals will be able to use their **own encryption keys** for organizational data or utilize the default encryption provided by Google. Google provides its [CSE (Client Side Encryption)](https://support.google.com/a/answer/10741897) that encrypts all content in the client’s browser before data transmission. While using Google’s CSE, you can also choose whether to share it internally or externally.

Google E2EE is still in the beta phase, available to customers of _Google Workspace Enterprise Plus, Education Plus, and Education Standard._ You can submit an application to [apply for the beta](https://support.google.com/a/answer/13069736#zippy=%2Cprepare-your-account%2Capply-for-the-gmail-cse-beta) or wait for it to go public.

## Epic Games fined $520 Million for Privacy Violations

Fortnite creator Epic Games has been fined a whopping $520 million by the FTC (Federal Trade Commission) for violating **children’s privacy laws** and using dark patterns for unintentional in-game purchases.

Fortnite is free to download and play, but in-game costumes and dance moves require players to pay. With a player base of over 400 million worldwide, the FTC has [decided on a $520 million fine](https://www.ftc.gov/system/files/ftc%5Fgov/pdf/2223087EpicGamesComplaint.pdf), $275 million of which is the monetary penalty for violating COPPA (Children’s Online Privacy Protection Act), a federal law in the United States that regulates the collection of personal information from children under the age of 13, and the remaining $245 million is the refund for players affected by **dark patterns and billing practices**.

The FTC’s fine against Epic Games is the most significant monetary penalty, the **largest administrative order**, and the most significant gaming case refund to date. Epic Games was found guilty of harvesting children’s personal information without verifiable parental consent and enabling **real-time voice and text chat** communications by default, opening them up to bullying and harassment.

The fine resulted since Epic did not turn off the default settings even after employees urged the organization to do it as back as in 2017 and multiple children being **harassed sexually** while playing the game. Epic games also confuse players with purchase prompts and misleading offers to make purchases unintentionally.

## JFK’s Taxi Dispatch System Hacked by Russians for Profit

Two US citizens were arrested for conspiring with **Russian threat actors**. The [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) and these citizens hacked the taxi dispatch system of JFK (John F. Kennedy International Airport) to move taxis in a queue for a $10 fee.

JFK’s taxi dispatch system is a system that ensures all taxis are dispatched from the airport to reach the appropriate terminal for the fare correctly. The system provides proper operations for taxi drivers since there is a significant demand for taxis at the airport. The US DoJ (United States Department of Justice) [explained](https://www.justice.gov/usao-sdny/press-release/file/1558891/download) that the help of Russian hackers **Daniel Abayev** and **Peter Leyman** breached this system for nearly a year between September 2019 and 2021.

The accused attempted various mechanisms to access the system, including a bribe for **malware infection** using a flash drive, obtaining unauthorized access, and stealing tablets connected to the dispatch system. The US DoJ also found **discussions between the two** to hack into the dispatch system.

The hackers communicated with the taxi drivers using chat applications and private groups, making “Shop Open” and “Shop Closed” announcements, where the taxi drivers had to pay $10 via cash or mobile payment to skip a line. The accused will have to forfeit all property related to the offenses and may face a sentence of up to **10 years in prison**.

## Cloud Storage Breach, Hackers Steal Customer Vault Data from LastPass

Threat actors stole critical customer vault data after breaching **LastPass’s cloud storage**. Last month, **Karim Toubba**, the organization’s CEO, claimed that the threat actors only gained access to “certain elements.”

The threat actor gained access to Lastpass’s cloud storage using an access key and dual storage container decryption keys that they stole from the **developer environment**. After gaining access, the threat actors copied information and got access to _customer account information, organization names, end-user names, email addresses, billing addresses, contact numbers, and IP (Internet Protocol) addresses._

The data stolen by the threat actors are not entirely at risk since it is still encrypted with [256-bit AES encryption](https://www.techopedia.com/definition/29703/256-bit-encryption) and can be decrypted using each **individual’s master password**, which is not known to LastPass as the enterprise never maintains it.

> LastPass has [warned](https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/) its customers that [brute force attacks](https://www.cybersecuritydive.com/news/brute-force-attacks-cloud-services/627100/) on their master passwords might occur, so their **sensitive information**, such as usernames, passwords, attachments, auto form fills, and secure notes are safely encrypted.

[![ransomware gang](https://media.mailhop.org/duocircle/images/2022/12/spf-record-6487.jpg)](https://media.mailhop.org/duocircle/images/2022/12/spf-record-6487.jpg)

## New Custom Encryptor for Vice Society Ransomware Gang

The [Vice Society ransomware gang](https://www.bleepingcomputer.com/news/security/vice-society-ransomware-gang-switches-to-new-custom-encryptor/) has switched to a new ransomware encryptor based on NTRUEncrypt and ChaCha20-Poly1305.

Named PolyVice, the new ransomware encryptor gives the threat actors a unique signature and appends **“ViceSociety”** to all locked files. The encryptor first appeared in July 2022 and leaves ransom notes under a new name, includes hardcoded master keys, wallpapers, and provides a builder enabling buyers to **generate multiple lockers/ decryptors**.

PolyVice also uses a hybrid encryption scheme with the payloads importing pre-generated **192-bit NTRU public keys** and another ransom key pair on the compromised system, unique for each target. PolyVice encrypts files under 5 MBs, partially encrypts the ones from 5MB, 100 MB, and breaks files over 100 MB into even chunks for each chunk.

SentinelOne’s [findings](https://www.sentinelone.com/labs/custom-branded-ransomware-the-vice-society-group-and-the-threat-of-outsourced-development/) show the advanced capabilities of PolyVice and threat actors employing the encryptor can cause catastrophic damage to demand ransoms.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 49 of 2022","description":"The malicious activities of cybercriminals never stop, and neither does the cybersecurity news that we bring to keep you updated with the best of security.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/","datePublished":"2022-12-23T19:54:58.000Z","dateModified":"2025-05-27T11:48:31.000Z","dateCreated":"2022-12-23T19:54:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1250,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/12/what-is-dkim-selector.jpg","caption":"cybersecurity updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 49 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 49 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 49 of 2022","description":"The malicious activities of cybercriminals never stop, and neither does the cybersecurity news that we bring to keep you updated with the best of security.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/","datePublished":"2022-12-23T19:54:58.000Z","dateModified":"2025-05-27T11:48:31.000Z","dateCreated":"2022-12-23T19:54:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1250,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/12/what-is-dkim-selector.jpg","caption":"cybersecurity updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
