Top stories.
- Apple sends out threat notifications to users targeted by spyware.
- Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack.
- Chinese hack-for-hire group conducts espionage and cybercrime simultaneously.
Apple sends out threat notifications to users targeted by spyware.
Apple yesterday sent out threat notifications to users in 110 countries, warning them that their devices may have been targeted by mercenary spyware often used by governments, TechCrunch reports. The alerts will now appear on device lock screens as well as being delivered to users' email addresses and showing up on their Apple account pages. Apple recommends that users who have been targeted or believe they may be targeted enable Lockdown Mode on their devices, an extreme protection that reduces the attack surface by limiting many of the device's functionalities. The company also advises targeted users to seek expert help, such as security assistance provided by the Digital Security Helpline at the nonprofit Access Now.
Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack.
Researchers at SOCRadar say the supply chain attack that compromised over 2,500 organizations in March was primarily driven by a malicious build of Aqua Security's Trivy scanner rather than the LiteLLM package, as initially suspected. Data shows that 95% of the affected entities were exposed to the malware days before the poisoned LiteLLM packages were published. The Trivy attack is also attributed to the TeamPCP threat actor and led to the LiteLLM attack, but SOCRadar says the LiteLLM compromise “was the closing act, not the whole play.”
SOCRadar explains, “Attackers hijacked the trusted Trivy security scanner in LiteLLM’s build pipeline, used it to publish two poisoned LiteLLM releases to PyPI, then relied on a Python startup file to run a credential stealer on every host that installed them.”
Chinese hack-for-hire group conducts espionage and cybercrime simultaneously.
Symantec has published a report on Jewelbug, a China-based hackers-for-hire group that conducts financially motivated cryptocurrency fraud alongside espionage campaigns targeting foreign governments and militaries. The threat actor, which is linked to a registered contractor in Hunan Province, uses the same control panel to conduct both criminal and nation-state espionage operations. Symantec notes that this “pairing is the signature of a hack-for-hire entity that is running for-profit crime on the side.”