More malware deployed in Eastern Europe. Cozy Bear is typosquatting. CuckooBees swarm around intellectual property. Tracking the DPRKs hackers. Quiet persistence in corporate networks.

Published: May 4, 2022, 8:45 p.m.

An upswing in malware deployed against targets in Eastern Europe. Cozy Bear is typosquatting. CuckooBees swarm around intellectual property. Tracking the DPRK\u2019s hackers. Quiet persistence in corporate networks. CISA issues an ICS advisory. Caleb Barlow on backup communications for your business during this period of "shields up." Duncan Jones from Cambridge Quantum sits down with Dave to discuss the NIST algorithm finalist Rainbow vulnerability. And, hey, officer, honest, it was just a Squirtle\u2026.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/11/86\n\nSelected reading.\nUpdate on cyber activity in Eastern Europe (Google)\xa0\nMultiple government hacking groups stay busy targeting Ukraine and the region, Google researchers say (CyberScoop)\nGoogle: Nation-state phishing campaigns expanding to target Eastern Europe orgs (The Record by Recorded Future)\nSolarWinds hackers set up phony media outlets to trick targets (CyberScoop)\xa0\nSOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse (Recorded Future)\xa0\nExperts discover a Chinese-APT cyber espionage operation targeting US organizations (VentureBeat)\nOperation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation (Cybereason Nocturnus)\xa0\nOperation CuckooBees: Deep-Dive into Stealthy Winnti Techniques (Cybereason)\xa0\nChinese hackers cast wide net for trade secrets in US, Europe and Asia, researchers say (CNN)\xa0\nResearchers tie ransomware families to North Korean cyber-army (The Record by Recorded Future)\nThe Hermit Kingdom\u2019s Ransomware Play (Trellix)\nNew espionage group is targeting corporate M&A (TechCrunch)\xa0\nCyberespionage Group Targeting M&A, Corporate Transactions Personnel (SecurityWeek)\xa0\nUNC3524: Eye Spy on Your Email (Mandiant)\xa0\nYokogawa CENTUM and ProSafe-RS (CISA)\xa0\nCops ignored call to nearby robbery, preferring to hunt Pok\xe9mon (Graham Cluley)\nLearn more about your ad choices. Visit megaphone.fm/adchoices