---
title: "Rising Cyberattacks and Emerging Risks Impacting the Cyber World | DuoCircle"
description: "With cybercrimes rising, you need to learn to ward off cyber attacks, which can only be done with proper."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/"
---

Quick Answer

Recent activity in the threat landscape: the Clop ransomware group claimed responsibility for the MOVEit Transfer data-theft campaign, exploiting a zero-day during the US Memorial Day weekend, with payroll provider Zellis among confirmed victims. CloudSEK identified a fresh batch of Android apps on Google Play infected with SpinOK malware, with combined installs over 30 million. The pattern, supply-chain zero-days timed to holidays, mobile malware riding legitimate app stores, reinforces the case for patch discipline, vendor risk review, and email-borne payload filtering.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Rising%20Cyberattacks%20and%20Emerging%20Risks%20Impacting%20the%20Cyber%20World&url=undefined%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F&title=Rising%20Cyberattacks%20and%20Emerging%20Risks%20Impacting%20the%20Cyber%20World "Share on Reddit") [ ](mailto:?subject=Rising%20Cyberattacks%20and%20Emerging%20Risks%20Impacting%20the%20Cyber%20World&body=Check out this article: undefined%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F "Share via Email") 

![Rising Cyberattacks](https://media.mailhop.org/duocircle/images/2023/06/spf-validator-4395.jpg) 

With cybercrimes rising, you need to learn to ward off cyber attacks, which can only be done with proper, **updated knowledge** of cybersecurity’s latest developments. Here is the latest [cybersecurity](/) news of the week. 

## MOVEit Extortion Attacks Attributed to Clop Ransomware

The notorious Clop ransomware group has claimed responsibility for the recent MOVEit Transfer **data-theft attacks**, revealing that they exploited a [zero-day vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/) during the US Memorial Day holiday weekend.

This confirmation aligns with Microsoft’s [attribution](https://www.bleepingcomputer.com/news/security/microsoft-links-clop-ransomware-gang-to-moveit-data-theft-attacks/) of the attacks to the malicious group known as ‘Lace Tempest’ or **TA505**. Clop is notorious for conducting **large-scale exploitation** campaigns during holidays when organizations are understaffed, as demonstrated in their previous Accellion FTA zero-day attack during the Christmas days of 2020.

[![Ransomware gang](https://media.mailhop.org/duocircle/images/2023/06/spf-record-generator-5176.jpg)](https://media.mailhop.org/duocircle/images/2023/06/spf-record-generator-5176.jpg)

The [ransomware gang](https://thehackernews.com/2023/05/buhti-ransomware-gang-switches-tactics.html) stated that they have not yet extorted their victims, opting to **review the stolen data** to identify valuable information that can be leveraged for ransom demands. 

Organizations like Zellis, a UK payroll and HR solutions provider, are **coming forward**, acknowledging being affected by the MOVEit attacks. 

## Increasing Number of Apps Found to Contain SpinOK Android Malware With 30 Million Installations

CloudSEK’s security team has discovered a new batch of Android apps on [Google Play](https://www.bleepingcomputer.com/news/security/cybercriminals-charge-5k-to-add-android-malware-to-google-play/) infected with the SpinOK malware, reportedly installed over 30 million times. 

The team found 193 apps carrying the **malicious SDK (Software Development Kit)** in addition to another 101 discovered by Dr. Web. Of them, [43 are still active](https://www.cloudsek.com/threatintelligence/supply-chain-attack-infiltrates-android-apps-with-malicious-sdk) on Google Play.

SpinOK, initially detected by Dr. Web in a set of apps downloaded over 400 million times, spreads through an **SDK supply chain attack**, posing as a legitimate **mini-game SDK** while secretly engaging in file theft and clipboard manipulation. Despite CloudSEK’s notification to Google, many identified [malicious apps](https://thehackernews.com/2023/05/google-blocks-143-million-malicious.html) remain available for download on Google Play.

_Avoiding random applications and **sticking to the essential** ones would be best to reduce the chances of falling victim to such malicious campaigns._ 

## Crypto Theft Surpasses $35 Million as a Result of Atomic Wallet Hacks

Atomic Wallet, a popular mobile and desktop **cryptocurrency wallet**, is investigating reports of a significant [crypto theft](https://www.aljazeera.com/news/2023/2/7/2022-was-record-year-for-north-korean-crypto-theft) from users’ wallets. 

Following reports of compromised wallets, Atomic Wallet has taken measures to investigate the situation, collaborating with third-party security organizations to **trace and block** the stolen funds. The download server for the wallet has been temporarily shut down to address security concerns.

Blockchain sleuth ZachXBT has been monitoring the stolen funds and estimates the total to exceed [$35 million](https://twitter.com/zachxbt/status/1665267820836319233) across various cryptocurrencies. Atomic Wallet users have **reported** **the theft** on social media, prompting the wallet’s team to collect information from victims to aid their investigation. 

It remains unclear how the compromise occurred, and users are advised to **transfer their assets** to alternative wallets while the security incident is under scrutiny.

## Credit Card Stealer Scripts Hosted on Legitimate Sites Following Hijacking by Threat Actors

In a new credit card stealing campaign similar to [Magecart](https://siliconangle.com/2023/05/08/magecart-malware-strikes-e-commerce-websites/), legitimate **websites are hijacked** to serve as makeshift C2 (Command and Control) servers.

Akamai researchers monitoring the campaign have [uncovered](https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains) compromises in the USA, Australia, the UK, Brazil, Peru, and Estonia. The attackers **exploit vulnerabilities** in legitimate sites, using them as C2 servers to deploy the credit card skimmer codes and evade detection by leveraging reputable third-party services.

The [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) stealthily execute data theft operations by employing obfuscation techniques like [Base64 encoding](https://www.tutorialspoint.com/what-is-base64-encoding) and mimicking **well-known services** such as Google Tag Manager and Facebook Pixel. 

_To safeguard against Magecart-style infections, website owners must secure their **admin accounts** and regularly update their CMS (Content Management Systems) and plugins_. Furthermore, customers can mitigate risks using electronic payment methods, virtual cards, or setting credit card transaction limits.

## Kimsuky Hackers Impersonate Journalists to Steal Intel, Warn NSA and FBI

The state-sponsored North Korean threat actors group known as Kimsuky, also called APT43, has been launching [spear-phishing](/content/spear-phishing-protection/spear-phishing-examples) campaigns by impersonating **journalists and academics** to gather intelligence. 

Multiple US and South Korean government agencies have [issued](https://media.defense.gov/2023/Jun/01/2003234055/-1/-1/0/JOINT%5FCSA%5FDPRK%5FSOCIAL%5FENGINEERING.PDF) a warning based on tracking and analyzing the group’s recent activities and attack themes. Kimsuky operates under North Korea’s Reconnaissance General Bureau and has conducted **large-scale espionage** campaigns since at least 2012.

The [adversaries](https://www.securityweek.com/33-new-adversaries-identified-by-crowdstrike-in-2022/) meticulously plan their spear-phishing attacks, utilizing email addresses that closely resemble real individuals and crafting **realistic content** to establish communication and gain the target’s trust. 

Users must use strong passwords, enable **MFA (Multi-Factor Authentication)**, and verify the validity of contact information through the official websites of media groups or journalists to **stay secure** from such attacks. 

## Ongoing Attacks Exploit Critical Flaw in Zyxel Firewall, Warn Experts

A critical [command injection](https://owasp.org/www-community/attacks/Command%5FInjection) vulnerability, identified as **CVE-2023-28771**, is being widely exploited by malicious actors to install malware on Zyxel networking devices. 

[![VPN](https://media.mailhop.org/duocircle/images/2023/06/spf-permerror-5176.jpg)](https://media.mailhop.org/duocircle/images/2023/06/spf-permerror-5176.jpg)

The flaw is present in the **default configuration** of affected firewall and [VPN](https://surfshark.com/download) devices, enabling unauthenticated remote code execution through UDP port 500 using a specially crafted [IKEv2 packet](https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-zyxel-firewall-flaw-in-ongoing-attacks/). Zyxel released patches on April 25, 2023, urging users of specific product versions to apply them promptly.

CISA (Cybersecurity & Infrastructure Security Agency) has [issued](https://www.cisa.gov/news-events/alerts/2023/05/31/cisa-adds-one-known-exploited-vulnerability-catalog) an alert concerning the active exploitation of CVE-2023-28771 and advising federal agencies to update by June 21, 2023\. Rapid7 has confirmed the flaw’s exploitation, including its use by **Mirai-based** **botnet malware**. 

System administrators must swiftly install the **latest security updates** to keep their organizations’ information systems secure and mitigate the risks of these vulnerabilities.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F) [ ](https://twitter.com/intent/tweet?text=Rising%20Cyberattacks%20and%20Emerging%20Risks%20Impacting%20the%20Cyber%20World&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Frising-cyberattacks-and-emerging-risks-impacting-the-cyber-world%2F) Copy 

Related Articles

- [ ![Email Threats](https://media.mailhop.org/duocircle/images/2023/07/hosted-email-server-3175.jpg)  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats? Blog ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)
- [ ![Hacker Taunts](https://media.mailhop.org/duocircle/images/2022/09/spf-record-tester-7545.jpg)  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach Blog ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)
- [ ![IntelBroker Threat Actors](https://media.mailhop.org/duocircle/images/2023/02/spf-record-generator-7980.jpg)  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers Blog ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)
- [ ![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2023/05/SPF-record-checker-7009.jpg)  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs Blog ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

## Related Articles

[  Privacy 5m  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats?  Jul 20, 2023 ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)[  Privacy 6m  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach  Sep 19, 2022 ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)[  Privacy 7m  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers  Feb 20, 2023 ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)[  Privacy 4m  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs  May 25, 2023 ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Rising Cyberattacks and Emerging Risks Impacting the Cyber World","description":"With cybercrimes rising, you need to learn to ward off cyber attacks, which can only be done with proper.","url":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/","datePublished":"2023-06-12T16:01:53.000Z","dateModified":"2025-05-08T20:00:13.000Z","dateCreated":"2023-06-12T16:01:53.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":877,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/spf-validator-4395.jpg","caption":"Rising Cyberattacks","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Privacy"},{"@type":"ListItem","position":3,"name":"Rising Cyberattacks and Emerging Risks Impacting the Cyber World","item":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Privacy","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Rising Cyberattacks and Emerging Risks Impacting the Cyber World","item":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Rising Cyberattacks and Emerging Risks Impacting the Cyber World","description":"With cybercrimes rising, you need to learn to ward off cyber attacks, which can only be done with proper.","url":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/","datePublished":"2023-06-12T16:01:53.000Z","dateModified":"2025-05-08T20:00:13.000Z","dateCreated":"2023-06-12T16:01:53.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/rising-cyberattacks-and-emerging-risks-impacting-the-cyber-world/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":877,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/spf-validator-4395.jpg","caption":"Rising Cyberattacks","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
