{"id":529,"date":"2022-02-07T12:38:05","date_gmt":"2022-02-07T11:38:05","guid":{"rendered":"http:\/\/scpo-cybersecurityassociation.com\/?p=529"},"modified":"2022-03-07T15:20:32","modified_gmt":"2022-03-07T14:20:32","slug":"cyber-monitoring-3-january-2022","status":"publish","type":"post","link":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/2022\/02\/07\/cyber-monitoring-3-january-2022\/","title":{"rendered":"Cyber Monitoring #3 (January 2022)"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"341\" src=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/The-Cyber-Newsletter-4-1024x341.png\" alt=\"\" class=\"wp-image-620\" srcset=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/The-Cyber-Newsletter-4-1024x341.png 1024w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/The-Cyber-Newsletter-4-300x100.png 300w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/The-Cyber-Newsletter-4-768x256.png 768w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/The-Cyber-Newsletter-4.png 1500w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Cyberattacks in Ukraine:\u00a0<\/strong>In the\u00a0<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=574f14bb88&amp;e=9f1453c0d1\">latest round of cyber incidents in Ukraine<\/a>, attackers hijacked many government-run websites and some agencies even lost important data. Microsoft was the first security research team to discover the attack, who dubbed it &#8220;WhisperGate.&#8221; Security experts and government leaders are\u00a0<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=1dfd26f430&amp;e=9f1453c0d1\">struggling with how to address these cyber attacks<\/a>. Given the sensitivity around Ukraine and Russia currently, it&#8217;s unclear if these could be constituted as an act of war or anything that could lead to kinetic warfare. The U.S. Department of Homeland Security warned Americans that\u00a0<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=081d60282e&amp;e=9f1453c0d1\">Russian state-sponsored actors could launch cyber attacks against critical infrastructure<\/a>\u00a0should the U.S. object to any kinetic warfare in Ukraine. Russian forces are currently gathering near the Ukrainian border, leading to concerns of a military conflict.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"1080\" data-id=\"530\" src=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16.png\" alt=\"\" class=\"wp-image-530\" srcset=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16.png 1080w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16-300x300.png 300w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16-1024x1024.png 1024w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16-150x150.png 150w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/16-768x768.png 768w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"1080\" data-id=\"531\" src=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17.png\" alt=\"\" class=\"wp-image-531\" srcset=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17.png 1080w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17-300x300.png 300w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17-1024x1024.png 1024w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17-150x150.png 150w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/17-768x768.png 768w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"1080\" data-id=\"532\" src=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18.png\" alt=\"\" class=\"wp-image-532\" srcset=\"https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18.png 1080w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18-300x300.png 300w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18-1024x1024.png 1024w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18-150x150.png 150w, https:\/\/scpo-cybersecurityassociation.com\/wp-content\/uploads\/2022\/02\/18-768x768.png 768w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/figure>\n<\/figure>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>Cyberattacks in Canada:<\/strong>&nbsp;Threat actors&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=3e6871abc7&amp;e=9f1453c0d1\">targeted Canada&#8217;s foreign ministry&#8217;s network<\/a>, disrupting some services, though the agency said it did not affect anything critical. The country&#8217;s leadership had also just recently warned of potential attacks from Russian state-sponsored actors.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>Arrests of members from the REvil threat group:<\/strong>&nbsp;Russian authorities&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=87129ca8df&amp;e=9f1453c0d1\">arrested several alleged members of the REvil ransomware group<\/a>&nbsp;at the request of U.S. authorities. It also seized multiple millions of dollars in international currencies that likely came from cyber attacks.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>A malware that steals and wipes:&nbsp;<\/strong>A well-known banking trojan targeting Android phones recently&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=9826c8c879&amp;e=9f1453c0d1\">added a new feature that could completely wipe a target&#8217;s phone<\/a>. The malware, Brata, factory resets the phone after it executes an unauthorized wire transaction.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>Some dark web news:<\/strong>&nbsp;UniCC, one of the largest darknet forums for selling stolen credit card information,&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=31765b9833&amp;e=9f1453c0d1\">shut down last week<\/a>&nbsp;when its founder retired. The creator of the forum claims to have made $358 million during the site&#8217;s lifespan.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>A huge Internet blackout:&nbsp;<\/strong>The&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=9f1bdadf05&amp;e=9f1453c0d1\">entire country of North Korea lost internet access<\/a>&nbsp;for about six hours this week, possibly due to a distributed denial-of-service attack. This is the second time in as many weeks this happened to the country.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>Threat group officially attributed to Iranian Intelligence:&nbsp;<\/strong>U.S. Cyber Command&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=d6b8fbd5e6&amp;e=9f1453c0d1\">formally attributed the MuddyWater threat actor<\/a>&nbsp;as an Iranian state-sponsored actor related&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=1d9a76de57&amp;e=9f1453c0d1\">to the Iranian Ministry of Intelligence (MOIS)<\/a>. The government also released an outline of the group&#8217;s tactics, techniques and procedures (TTPs) and likely entry points into victims&#8217; networks.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-wide\"\/>\n\n\n\n<p><strong>A European DNS?<\/strong>&nbsp;The European Union is interested in building its own&nbsp;<a href=\"https:\/\/sciencespo.us5.list-manage.com\/track\/click?u=2fd462bf43b63ef48b70f41ee&amp;id=5abcbb1eaf&amp;e=9f1453c0d1\" target=\"_blank\" rel=\"noreferrer noopener\">sovereign and recursive DNS service<\/a>&nbsp;that will be made available to EU institutions and the general public for free. The proposed service, named&nbsp;<strong>DNS4EU<\/strong>, is currently in a project planning phase.<br><em><strong>But what is a DNS?<\/strong><\/em>&nbsp;On the surface, browsing the web appears to be quite a simple process. Behind the scenes, after you type a URL in your device\u2019s address bar, your device sends a query to a Domain Name Server (DNS) to translate the URL to a machine-readable IP address. Once your device receives the corresponding IP address, it opens the website. The EU said that DNS4EU would come with built-in filtering capabilities that will be able to block DNS name resolutions for bad domains, such as those hosting malware, phishing sites, or other cybersecurity threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check out what happened in the cyberspace during the month of January!<\/p>\n","protected":false},"author":7,"featured_media":275,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-529","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/posts\/529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/comments?post=529"}],"version-history":[{"count":3,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/posts\/529\/revisions"}],"predecessor-version":[{"id":621,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/posts\/529\/revisions\/621"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/media\/275"}],"wp:attachment":[{"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/media?parent=529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/categories?post=529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scpo-cybersecurityassociation.com\/index.php\/wp-json\/wp\/v2\/tags?post=529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}