
A series of cybersecurity threats have been identified involving state-sponsored cyber groups from China and North Korea. These groups have been linked to ransomware attacks targeting global governments and critical infrastructure. Notably, the Chinese threat actor group ChamelGang, also known as CamoFei, has been implicated in ransomware attacks on the Indian healthcare institution AIIMS and the Presidency of Brazil in 2022. The group is believed to use ransomware as part of their espionage operations. Research from SentinelOne and Recorded Future highlights these activities. Additionally, new malware strains targeting banking users and WordPress sites have emerged, including the Medusa Android Trojan, a new credit card skimmer, and the Snowblind banking malware that exploits the Linux Kernel.
šØ šæ A disturbing ransomware trend that blurs the lines between cyberespionage and cybercrime, highlighted in a new @LabsSentinel report: Threat actors in the cyberespionage ecosystem are using ransomware as a final stage in their operations for the purposes of financial gain,⦠https://t.co/gJVY2sS6Qh
New research from Recorded Future and @SentinelOne on #ChamelGang, a suspected Chinese APT group that targeted Indian healthcare institution AIIMS and the Presidency of Brazil in 2022 using CatB ransomware. https://t.co/6XieGOn1G5
A new strain of banking malware, dubbed "Snowblind," that affects Android mobile devices alters apps so it can read phone screens, disable 2FA, and steal victims' funds. š: https://t.co/ERWSrd7D9Z https://t.co/3VA2L15aKe








