The CyberWire Daily Podcast 4.22.22
Ep 1563 | 4.22.22

The cyber phases of Russia's war against Ukraine. Sanctions and the criminal underworld. Conti’s fortunes. More_eggs resurfaces. BlackCat ransomware warning.

Show Notes

A look at Russian malware used against Ukrainian targets. Actual and potential targets harden themselves against Russia cyberattacks. Sanctions and the criminal underworld. Conti’s fortunes. A credential stealer resurfaces in corporate networks. BlackCat ransomware warning. Tomer Bar from SafeBreach discusses MuddyWaters. Dr. Christopher Emdin previews his new book "STEM, STEAM, Make, Dream." CISA releases three more ICS security advisories.

Selected reading.

Russia outlines when Ukraine war will end (Newsweek) 

Russia racing against clock to win Ukraine war before May 9 'Victory Day' (Newsweek) 

A deeper look at the malware being used on Ukrainian targets (The Record by Recorded Future)

Ukraine ramps up cyber defences to slow surge in attacks (The Straits Times)

Five Eyes Alert Warns of Heightened Risk of Russian Cyber Attacks (Bloomberg) 

Preparing for Energy Industry Cyberattacks (Wall Street Journal)

US sets dangerous precedents in cyberspace (Global Times) 

Russia’s War in Ukraine Has Complicated the Means Through Which Cybercriminals Launder Funds. Here’s How They’re Adapting (Flashpoint) 

U.S. Treasury Designates Facilitators of Russian Sanctions Evasion (U.S. Department of the Treasury)

Russia says nyet, sanctions Mark Zuckerberg, LinkedIn’s Roslansky, VP Harris and other US leaders (TechCrunch) 

Russia’s War in Ukraine Has Complicated the Means Through Which Cybercriminals Launder Funds. Here’s How They’re Adapting (Flashpoint) 

GOLD ULRICK continues Conti operations despite public disclosures (Secureworks) 

Costa Rica's Alvarado says cyber​​attacks seek to destabilize country as government transitions (Reuters)

Hackers Spearphish Corporate Hiring Managers with Poisoned Resumes, Infecting Them with the More_Eggs Malware, Warns eSentire (eSentire) 

BlackCat/ALPHV Ransomware Indicators of Compromise (IC3) 

FBI: BlackCat ransomware breached at least 60 entities worldwide (BleepingComputer) 

Delta Electronics ASDA-Soft (CISA) 

Johnson Controls Metasys SCT Pro (CISA) 

Hitachi Energy MicroSCADA Pro/X SYS600 (CISA)