<div>
<div>
<div>
<img alt="" src="https://quointelligence.eu/wp-content/uploads/2020/03/[email protected]" title="" />
</div><div>
<div><p>QuoIntelligence’s Weekly Intelligence Snapshot for the week of<strong> 20 May – 27 May 2020</strong> is now available!</p>
<div><h2>CYBER</h2>
Current Threat
Industries impacted: ANY
Microsoft announced a new Java-based ransomware family dubbed PonyFinal deployed in “human-operating” ransomware attacks. Microsoft describes the attack scenario for PonyFinal as attackers first gaining access via brute-force attacks against the target company’s systems management server, then running additional tools for data exfiltration and bypassing event logging.
Threat Actor
Industries impacted: ANY, Consumer Discretionary, Financials, Materials, Information Technology
In the last week, QuoINT identified new activty attributed to Golden Chickens involving two Malware-as-a-Service tools using a previously unknown digital certificate, and released a technical brief detailing attack activity and various tools with noteable code observed throughout March and April. QuoIntelligence covered both topics in a Warning and the technical brief, respectively, which were distributed to Premium customers.
Researchers at ESET detailed a new backdoor malware dubbed PipeMon, discovered in February 2020 and used in an attack campaign attributed to the Winnti Group, which targeted several unnamed video gaming companies in South Korea and Taiwan
<div><p><strong>Rollups</strong></p>
- Berserk Bear: Targeting German Companies Through Supply Chain Attacks
- Facebook Profile Data of 500 Million Users For Sale on Underground Forum
- New ZLoader Banking Malware Variant Discovered and Observed in over 100 Campaigns Since January 2020
-
A New Campaign Distributes Ragnar Locker Within A Virtual Machine To Evade Detection
- Researcher Revealed Proof-of-Concept (PoC) of a Privilege Escalation Vulnerability in Docker Desktop Service for Windows
- APT39: Targeting Air Transportation and Government Organization in the Middle East
<div><h2>GEOPOLITICS</h2>
Industries impacted: Government
China’s government is currently holding the annual ‘two sessions’, which comprises of meetings of the National People’s Congress (NPC) – the national legislature of China – and the Chinese People’s Political Consultative Conference (CPPCC), after initially being delayed from March due to COVID-19.
<div><h2></h2>
Rollups
- UK’s Data Protection Authority Releases Report on Data Security Incidents
- Israel’s Prime Minister Netanyahu Speaks of ”historic opportunity” to Claim Parts of West Bank
</div> <div>
<div>
<div>
<a href="https://quointelligence.eu/#offering" rel="noreferrer" target="_blank">Learn more about our Threat Intelligence service</a>
</div><div>
<div><h2>Join our Newsletter!</h2><div>
Subscribe to our newsletter with your business email to receive intelligence summaries, analytic product updates, and more!
<div>
<div></div>
<div>
<h2>Thanks! You will soon receive a confirmation email!</h2>
</div>
<div>
<p>
First Name
</p>
<p>
Last Name
</p>
<p>
Email
</p>
<p>
<a href="https://quointelligence.eu" rel="noreferrer" target="_blank">
Subscribe
</a>
</p>
</div>
</div>
</div>
</div>
</div>
</div>
The post Weekly Intelligence Snapshot – Week 22 appeared first on QuoIntelligence - Our Finished Intelligence, Tailor-made for Your Organization.