Powergrid attacks, DDoS, and doxing in a hybrid war. Notes on botnets, and a threat actor changes its phish hooks. Patch Tuesday. Sentence passed in a sanctions evasion case.

Published: April 13, 2022, 8:15 p.m.

Indestroyer2 and Ukraine's power grid. More on last week's distributed denial-of-service attack against Finland. Anonymous claims to have doxed Russia's Ministry of Culture. Hafnium gets evasive. Enemybot is under development but worth keeping an eye on. Changing the phish hook. Patch Tuesday notes. Tim Eades from Cyber Mentor Fund on digital & security transformations. Our guest is Aaron Shilts from NetSPI onproactive public-private sector security collaboration. Sanctions evasion is serious business.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/11/71\n\nSelected reading.\nWhy Russia\u2019s Cyber Warriors Haven't Crippled Ukraine (The National Interest)\nIn Ukraine, a \u2018Full-Scale Cyberwar\u2019 Emerges (Wall Street Journal)\xa0\nRussian hackers tried to bring down Ukraine\u2019s power grid to help the invasion (MIT Technology Review)\xa0\nRussia's Sandworm Hackers Attempted a Third Blackout in Ukraine (Wired)\nUkraine Thwarts Cyberattack on Electric Grid, Officials Say (Wall Street Journal)\xa0\nZhadnost strikes again\u2026 this time in Finland. (SecurityScorecard)\nAnonymous Hits Russian Ministry of Culture- Leaks 446GB of Data (HackRead)\xa0\nTarrask malware uses scheduled tasks for defense evasion (Microsoft Security Blog)\xa0\nEnemybot: A Look into Keksec's Latest DDoS Botnet (Fortinet Blog)\xa0\nEnemybot: a new Mirai, Gafgyt hybrid botnet joins the scene (ZDNet)\xa0\nQbot malware switches to new Windows Installer infection vector (BleepingComputer)\xa0\nMicrosoft Releases April 2022 Security Updates (CISA)\nGoogle Releases Security Updates for Chrome (CISA)\xa0\nCitrix Releases Security Updates for Multiple Products (CISA)\nApache Releases Security Advisory for Struts 2 (CISA)\xa0\nValmet DNA (CISA)\xa0\nMitsubishi Electric MELSEC-Q Series C Controller Module (CISA)\xa0\nInductive Automation Ignition (CISA)\xa0\nMitsubishi Electric GT25-WLAN (CISA)\xa0\nAethon TUG Home Base Server (CISA)\xa0\nU.S. crypto researcher sentenced to five years for helping North Korea evade sanctions (Reuters)\nLearn more about your ad choices. Visit megaphone.fm/adchoices