0Ktapus phishing campaign

0ktapus campaign has been underway since at least March 2022, aiming to steal Okta identity credentials and 2FA codes and use them to carry out subsequent supply chain attacks.

In Aug. 2022 SMS phishing messages baited Twilio’s employees into clicking the embedded links by warning them that their passwords had expired or were scheduled to be changed.

Maui ransomware

Maui ransomware started attacks in April 2021 (based on build timestamps), maintaining an apparent focus on healthcare organizations in the United States. In Aug22 researchers at Kaspersky made the link between Maui and Andariel, attributing it with medium confidence.

GwisinLocker Ransomware

Ransomware family ‘GwisinLocker’ targets South Korean healthcare, industrial, and pharmaceutical companies with Windows and Linux encryptors, including support for encrypting VMware ESXi servers and virtual machines.

PLAY

The PLAY ransomware operation that launched in June 2022, belongs to a very notorious type of malware family. The ransomware appends the “.Play” extension to encrypted files.

ROADSWEEP

ROADSWEEP is a ransomware tool, which upon execution will enumerate files on the device and encrypts the content in blocks using RC4. Window API names, malware configuration parameters, and the basis of a ransomware note are RC4 encrypted within ROADSWEEP. During execution, ROADSWEEP will decrypt these encrypted strings and dynamically resolve necessary imports. ROADSWEEP was reportedly used in the July 2022 attack on Albanian government systems.