---
title: "Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12, 2024] | DuoCircle"
description: "Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/"
---

Quick Answer

Week 8, 2024 cyber news: GoldFactorys Gold Pickaxe trojan (iOS via TestFlight + MDM and Android via fake Play sites) tricks Vietnam and Thailand victims into recording faces and uploading IDs; Aqua Nautilus shows Ubuntus command-not-found can be abused via Snap typosquatting (26% of APT commands at risk); IntelBroker leaks 200,000 Facebook Marketplace records via a Meta contractor breach; PlayDapp loses \~$290M after a private-key theft mints 1.79 billion PLA tokens; Bank of America notifies 57,028 customers after LockBit hit vendor Infosys McCamish Systems with a 50GB exfiltration.

Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News \[February 12, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/02/Malware-Fraud-Ubuntu-Malware-Distribution-Facebook-Data-Breach-–-Cybersecurity-News-February-12-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Malware%20Fraud%2C%20Ubuntu%20Malware%20Distribution%2C%20Facebook%20Data%20Breach%2C%20Cybersecurity%20News%20%5BFebruary%2012%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F&title=Malware%20Fraud%2C%20Ubuntu%20Malware%20Distribution%2C%20Facebook%20Data%20Breach%2C%20Cybersecurity%20News%20%5BFebruary%2012%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Malware%20Fraud%2C%20Ubuntu%20Malware%20Distribution%2C%20Facebook%20Data%20Breach%2C%20Cybersecurity%20News%20%5BFebruary%2012%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2024/02/SMTP-email.jpg) 

Want to stay a step ahead of the recent threats in cybersecurity? We’re here with our weekly [cybersecurity](/) news piece that will help you out. This week, we’ll be covering new Android and iOS malware, malicious use of Ubuntu features, the new Facebook marketplace data breach, the data compromise of Bank of America, and the PlayDapp Gaming platform breach. Check these out to **learn how to stay protected**.

## New Android, iOS’ Gold Pickaxe’ Malware Uses Facial Recognition for Fraud

There is a new iOS and Android trojan that is using a [social engineering](/email-security/a-young-hacker-unleashes-social-engineering-attack-on-uber/) scheme to dupe victims so they **scan their faces and IDs**. 

This Gold Pickaxe malware was [spotted](https://www.group-ib.com/media-center/press-releases/goldfactory-ios-trojan/) by Group-IB and is a creation of GoldFactory, a **Chinese threat actor group** that is also behind Gold Digger, Gold Digger Plus, and Gold Kefu threats. The threat actor has been targeting Asia-Pacific countries, mainly Vietnam and Thailand, and started with social engineering. They approach the victims via phishing or smishing on the LINE app and then trick them into installing [fraudulent applications](https://www.deccanherald.com/technology/gadgets/google-takes-down-17-spyloan-apps-for-fraudulent-practices-2802505) like **Digital Pension**. These apps are downloaded from a Google Play impersonation website.

On iOS, they direct victims to a [TestFlight URL](https://developer.apple.com/testflight/) to install the app and lure them into downloading malicious [MDM (Mobile Device Management)](https://en.wikipedia.org/wiki/Mobile%5Fdevice%5Fmanagement) profiles to take control of their devices. _The malware has many **advanced capabilities** and can also access SMS, navigate file systems, perform screen clicks, and upload recent photos from the album._ 

Gold Pickaxe steals images from iOS and Android devices and then tricks the victims into showing their faces on video via social engineering. However, it **does not hijack Face ID** data. 

[![Social engineering attacks](https://media.mailhop.org/duocircle/images/2024/02/SMTP-email-1.jpg)](https://media.mailhop.org/duocircle/images/2024/02/SMTP-email-1.jpg)

## Malicious Use of Ubuntu’s ‘command-not-found’ Feature to Distribute Malware

Ubuntu’s command-not-found package has a **logic flaw** that could allow threat actors to push [malware packages into the system](https://www.ft.com/content/8d90b1de-df1e-47ad-8bdb-5c0ee4f85e45).

The loophole was discovered by researchers at Aqua Nautilus who [highlighted](https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/) that 26% of the APT (Advanced Package Tool) commands are at risk of impersonation by malicious packages. This could pose a **huge supply chain risk** **for Linux and WSL**. The [Python script](https://thehackernews.com/2023/11/beware-developers-blazestealer-malware.html) is used for suggesting packages to allow you to run programs that are not currently installed on the system. The suggestion relies on an internal database of APTs and one from the Snap Store that is updated regularly.

The researchers showed how easy it is for threat actors to publish [malicious scripts](https://www.bleepingcomputer.com/news/security/malicious-web-redirect-scripts-stealth-up-to-hide-on-hacked-sites/) to the snap store, which would come into the database and cause all kinds of harm. The threat actors could also abuse the **auto-update feature** of snap packages to deliver new and advanced exploits to target new vulnerabilities. 

Snap packages are vulnerable to [impersonation](/email-security/reducing-the-risk-of-email-impersonation-attacks-6-email-security-measures-you-need-to-consider/) through typosquatting, unclaimed names, and mimicking existing APT packages. Attackers can trick users into installing malware disguised as familiar commands. While mitigation steps exist, like user vigilance and developer responsibility, the potential for **exploitation remains**.

## Facebook Marketplace Data Breach: 200,000 User Records Exposed on Cybercrime Forum

A threat actor leaked records of 200,000 individuals and claimed the data contained **sensitive information** about users of [Facebook Marketplace](https://www.techtarget.com/whatis/definition/Facebook-Marketplace). 

IntelBroker claims that the partial database was stolen by a person using “algoatson” Discord handle after hacking the device of a Meta contractor. The leaked database is **full of PII** (Personally Identifiable Information) like names, phone numbers, emails, Facebook IDs, and other profile information. The threat actors can use this information in many attacks, most of all impersonation and phishing. The leaked mobile numbers could be used in [SIM swap attacks](https://securityboulevard.com/2024/02/secs-x-breach-highlights-need-for-better-defense-against-sim-swap-attacks/), allowing the threat actors to steal [MFA (Multi-Factor Authentication)](/email-security/multi-factor-authentication-mfa-and-its-impact-on-email-security/) codes and **hijack the Facebook accounts** of the victims. 

The threat actor, IntelBroker became infamous after the [breach](https://www.bleepingcomputer.com/news/security/fbi-investigates-data-breach-impacting-us-house-members-and-staff/) of **DC Health Link** that led to a congressional hearing after the threat actors made away with [personal data](https://edition.cnn.com/2023/06/16/politics/cyberattack-us-government/index.html) of members of the US House of Representatives. 

## Unauthorized Creation of 1.79 Billion Cryptocurrency Tokens in PlayDapp Gaming Platform Breach

Hackers have stolen a **private key** to mint and steal nearly 1.79 billion [PLA tokens](https://phemex.com/academy/what-is-playdapp-pla) that are used within the PlayDapp ecosystem. 

_An unauthorized wallet minted 200 million PLA tokens on 9 February 2024, which had a value of $36.5 million at the time._ PeckShiled, a blockchain security enterprise that it could be due to a leaked private key. PlayDapp informed its community about the news and transferred all locked and unlocked PlayDapp held tokens to a new wallet.

They also sent an **offer of a $1 million white hat reward** to the threat actor in exchange for the stolen contracts. The offer was in vain as on 12 February, the threat actor minted 1.59 billion PLA tokens with a value of $253.9 million. The value of the stolen tokens is nearly $290 million, but Elliptic [shared](https://www.elliptic.co/blog/crypto-gaming-platform-playdapp-suffers-290-million-breach) that the threat actor would have to sell these below market value, which would impact PLA token holders. 

The platform has **suspended deposits and withdrawals** on the platform and has frozen [the hacker’s wallet](https://techcrunch.com/2024/01/31/hackers-steal-112-million-of-xrp-ripple-cryptocurrency/) on major crypto exchanges to control and mitigate the breach. 

## Bank of America Alerts Customers to Data Compromise Following Vendor Attack

[![data breach](https://media.mailhop.org/duocircle/images/2024/02/SMTP-providers-6482.jpg)](https://media.mailhop.org/duocircle/images/2024/02/SMTP-providers-6482.jpg)

Bank of America has warned customers of a [data breach](https://www.bbc.com/news/technology-68128396) that left their personal information exposed following a **vendor hack** last year.

The PII that has been exposed in the breach contains names, residential addresses, SSNs (Social Security Numbers), birth dates, and financial information such as account and **credit card numbers**. The bank has not disclosed the number of people affected by the data breach, but a notification [highlights](https://web.archive.org/web/20240710090442/https://apps.web.maine.gov/online/aeviewer/ME/40/c2da936e-14f0-421a-833e-a24cbdd79cfa.shtml) that 57,028 people were affected.

IMS (Infosys McCamish Systems) was one of the service providers of the Bank of America that was hacked last year in November when an [unauthorized third party](https://www.cpomagazine.com/cyber-security/dollar-tree-third-party-data-breach-exposes-sensitive-data-of-nearly-2-million-employees/) accessed its systems. The responsibility for the hack was claimed by the **LockBit ransomware** gang, who also revealed that they encrypted over 2000 of IMS’s systems during the attack.

They added an IMS entry on a dark web forum highlighting that anyone can buy the **50GB database** for a good enough price, and it will be published. The accounting firm handling the data, Ernst & Young, was also exposed during a breach in May 2023 by [Clop ransomware](https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/). 

No systems of the Bank of America were impacted by the breach, but the **data is still out there**, and the people are at risk.

These recent incidents underscore the importance of implementing robust [phishing protection](/email/phishing-protection) measures and providing comprehensive [phishing awareness training](/phishing-awareness-training). **Stay tuned** for further insights.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Malware%20Fraud%2C%20Ubuntu%20Malware%20Distribution%2C%20Facebook%20Data%20Breach%2C%20Cybersecurity%20News%20%5BFebruary%2012%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-8-of-2024%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12, 2024]","description":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/","datePublished":"2024-02-19T15:20:48.000Z","dateModified":"2025-04-25T14:18:25.000Z","dateCreated":"2024-02-19T15:20:48.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1078,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/02/SMTP-email.jpg","caption":"cybersecurity","width":900,"height":507},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12, 2024]","description":"Malware Fraud, Ubuntu Malware Distribution, Facebook Data Breach, Cybersecurity News [February 12.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/","datePublished":"2024-02-19T15:20:48.000Z","dateModified":"2025-04-25T14:18:25.000Z","dateCreated":"2024-02-19T15:20:48.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-8-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1078,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/02/SMTP-email.jpg","caption":"cybersecurity","width":900,"height":507},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
