---
title: "Syndicate Fraud Takedown, BazarCall Exploits, Backup Plugin Flaw, Cybersecurity News [December 11, 2023] | DuoCircle"
description: "Need top-of-the-line ins and outs of the cybersecurity landscape? Stay a step ahead of cybercriminals with the latest cybersecurity news of the week with us."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/"
---

Quick Answer

Week 50, 2023 cyber news: Microsoft seized infrastructure of Vietnam-based Storm-1152, which had registered 750 million fraudulent Outlook accounts and sold CAPTCHA-solving services to Storm-0252, Storm-0455, and Octo Tempest; BazarCall callback phishing now uses Google Forms to deliver fake payment receipts; CVE-2023-6553 (CVSS 9.8) in WordPress Backup Migration plugin enables unauthenticated RCE on 50,000+ unpatched sites (fixed in 1.3.8); IIIT Hyderabad researchers disclose AutoSpill, an Android autofill flaw that leaks credentials from password managers via WebView.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-50-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Syndicate%20Fraud%20Takedown%2C%20BazarCall%20Exploits%2C%20Backup%20Plugin%20Flaw%2C%20Cybersecurity%20News%20%5BDecember%2011%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-50-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-50-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-50-of-2023%2F&title=Syndicate%20Fraud%20Takedown%2C%20BazarCall%20Exploits%2C%20Backup%20Plugin%20Flaw%2C%20Cybersecurity%20News%20%5BDecember%2011%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Syndicate%20Fraud%20Takedown%2C%20BazarCall%20Exploits%2C%20Backup%20Plugin%20Flaw%2C%20Cybersecurity%20News%20%5BDecember%2011%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-50-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/12/check-DMARC-record-2.jpg) 

Need top-of-the-line **ins and outs** of the cybersecurity landscape? Stay a step ahead of cybercriminals with the latest [cybersecurity](/) news of the week with us.

From Microsoft taking down 750 million fraud accounts to new BazarCall phishing campaigns, critical WordPress plugin bugs, and **unfixed Android bugs** threatening your login information, we will share the details so you can stay informed and take necessary [phishing protection](/email/phishing-protection) measures to keep your devices safe. Let’s get started.

## Microsoft Takes Down Cybercrime Syndicate Responsible for 750 Million Fraudulent Accounts

The Digital Crimes Unit at Microsoft **took down** multiple domains that were used by Storm-1152.

[The Vietnam-based threat actor group](https://thehackernews.com/2023/05/vietnamese-threat-actor-infects-500000.html) had registered over 750 million accounts and collected millions by selling these to other cybercriminals for malicious purposes. The threat actor group is the **number one seller** of harmful Outlook accounts. _The threat actors also sell automatic CAPTCHA-solving services._

Since 2021, the threat actors have been obtaining millions of [MS Outlook email accounts](https://www.timesnownews.com/technology-science/microsoft-confirms-outlook-cloud-platform-was-hit-by-cyber-attacks-in-june-article-101076362) using fake names and selling these to malicious actors. Many of these accounts were used by Storm-0252, Storm-0455, and Octo Tempest in **mass phishing campaigns**, data theft, spreading ransomware, and [malware](/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/). Microsoft seized Storm-1152’s infrastructure on 7 December 2023 after obtaining a [court order](https://landingpage-h0gcc3bvhkd2aaez.z01.azurefd.net/notice-of-pleadings) from NY.

[![malicious websites](https://media.mailhop.org/duocircle/images/2023/12/sender-policy-framework-6832.jpg)](https://media.mailhop.org/duocircle/images/2023/12/sender-policy-framework-6832.jpg)

The [complaint](https://www.documentcloud.org/documents/24223189-storm-1152-complaint) by Microsoft also showcases how the threat actors developed code for many [malicious websites](https://therecord.media/chatgpt-phishing-fake-websites-hackers-malware), and also **published video guides** on using these accounts for fraudulent services.

## BazarCall Exploits Google Forms in Phishing Emails

A **new wave** of BazarCall attacks came to light this week which uses Google Forms.

The attacks generate and [send payment receipts to the victims](https://www.infosecurity-magazine.com/news/hackers-use-paypal-malicious/) to make the phishing campaign appear genuine. BazarCall was first documented in 2021 when the threat actors used an email containing a [payment notification](/email-security/received-an-email-regarding-pending-payment-for-subscription-stay-vigilant/) or subscription to lure victims. It asked victims to cancel highly charged subscriptions or fees. However, the emails contained links to phishing websites **impersonating real ones**. The page urged victims to cancel the charges over a call, which was answered by a threat actor. The threat actors tricked the victims into **installing malware** on their systems.

This time, Abnormal Reports [shared](https://abnormalsecurity.com/blog/bazarcall-attack-leverages-google-forms) a new variant of the BazarCall attack which uses Google Forms. The [threat actors](/email-security/threat-actors-are-using-google-ads-to-launch-sophisticated-phishing-campaigns/) make a **fake Google Form** with fake transaction details including payment methods, invoices, and such information. They send the form to the victim’s email and wait to carry out the attack.

Google Forms is an **authentic service**, so it is not blocked or flagged by emails. You should be on your guard, with proper [malware protection](/resources/malware-and-its-defense-mechanism) solutions, if you receive an email like this as it could be a phishing attempt.

## Critical Bug in Backup Plugin Exposes 50,000 WordPress Sites to RCE Attacks

A **critical severity** was found in a WordPress plugin that has over 90,000 installs.

The severity was [found](https://www.wordfence.com/blog/2023/12/critical-unauthenticated-remote-code-execution-found-in-backup-migration-plugin/) in **Backup Migration**, a plugin that allows you to automate site backups to local storage or Google Drive. Threat actors can misuse this to gain [RCE (Remote Code Execution)](https://www.techtarget.com/searchwindowsserver/definition/remote-code-execution-RCE) on systems and carry out malicious harm. Tracked as [CVE-2023-6553](https://www.cve.org/CVERecord?id=CVE-2023-6553), the bug has a **severity score of 9.8** and was discovered by the Nex Team. The bug impacts all versions of the plugin up to Backup Migration 1.3.6, and allows threat actors to **take over websites via RCE**.

[![REC attacks](https://media.mailhop.org/duocircle/images/2023/12/what-is-dkim-1.jpg)](https://media.mailhop.org/duocircle/images/2023/12/what-is-dkim-1.jpg)

These actors can use [PHP code injection](https://owasp.org/www-community/vulnerabilities/PHP%5FObject%5FInjection) using the /includes/backup-heart.php file. On line 118 of the file, an attempt is made to include bypasser.php from the BMI\_INCLUDES directory, formed by merging BMI\_ROOT\_DIR with the includes string. Yet, BMI\_ROOT\_DIR, determined by the content-dir HTTP header on line 62, is influenced by user input. A **patch was released promptly** with an updated version (Backup Migration 1.3.8).

There are still nearly 50,000 WordPress websites using an older, **vulnerable version** of the plugin. If you’re still using it, you should update it to the latest version.

## AutoSpill Attack Pilfers Credentials from Android Password Managers

Security researchers have developed a new attack called AutoSpill. It can **steal account login information** on [Android devices](/phishing-protection/microsoft-uncovers-high-severity-android-vulnerabilities/) during autofill.

Researchers from IIIT (International Institute of Information Technology) at Hyderabad shared the results of their tests at the Black Hat Europe security conference. They revealed how most **password managers** on Android are vulnerable to AutoSpill attacks without JavaScript injection. [Android applications use WebView controls for web content](https://www.kirupa.com/apps/webview.htm), and password managers often use it to autofill your passwords. But, it is possible to exploit weaknesses in this and capture the auto-filled credentials. _Android **does not enforce or define responsibility** for the secure handling of autofill data, resulting in this vulnerability._

The researchers [disclosed](https://www.documentcloud.org/documents/24202397-eu-23-gangwal-autospill-zero-effort-credential-stealing) their findings from multiple tests carried out on different Android versions and devices. They also shared proposals for addressing the [vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/). **No fixing plans have been shared** as of yet and the devices remain vulnerable.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Syndicate Fraud Takedown, BazarCall Exploits, Backup Plugin Flaw, Cybersecurity News [December 11, 2023]","description":"Need top-of-the-line ins and outs of the cybersecurity landscape? Stay a step ahead of cybercriminals with the latest cybersecurity news of the week with us.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/","datePublished":"2023-12-18T21:52:50.000Z","dateModified":"2025-05-15T12:15:02.000Z","dateCreated":"2023-12-18T21:52:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":788,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/12/check-DMARC-record-2.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Syndicate Fraud Takedown, BazarCall Exploits, Backup Plugin Flaw, Cybersecurity News [December 11, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Syndicate Fraud Takedown, BazarCall Exploits, Backup Plugin Flaw, Cybersecurity News [December 11, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Syndicate Fraud Takedown, BazarCall Exploits, Backup Plugin Flaw, Cybersecurity News [December 11, 2023]","description":"Need top-of-the-line ins and outs of the cybersecurity landscape? Stay a step ahead of cybercriminals with the latest cybersecurity news of the week with us.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/","datePublished":"2023-12-18T21:52:50.000Z","dateModified":"2025-05-15T12:15:02.000Z","dateCreated":"2023-12-18T21:52:50.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-50-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":788,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/12/check-DMARC-record-2.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
