Threat Analysis: Russian Email Attack Extended to Outlook, New NPM Risks

Threats & Attacks

Threat Analysis: Russian Email Attack Extended to Outlook, New NPM Risks

Hello, Mauven here. Let’s dive straight into today’s cyber threat landscape affecting UK SMBs. We have two significant developments.

Russian State-Sponsored Email Attacks Targeting Outlook

A sophisticated campaign from Russian cyber actors has emerged, using a ‘half-click’ method to compromise Outlook accounts. This method involves booby-trapped emails that, when opened, embed a persistent browser implant. The worrying part? It survives password changes and device resets, posing a significant risk to business operations and data integrity.

While the NCSC and Microsoft have published guidance on securing email accounts, this evolving threat demonstrates that state actors are continuously adapting. Organizations should be wary of emails, even from known contacts, and ensure their security software is up-to-date to detect unusual activities.

NPM Registry Hosting New Supply Chain Attacks

A new worm-like attack has infiltrated the npm environment, affecting several popular packages. This attack targets developer environments to steal GitHub credentials and AWS secrets. The approach is similar to past supply chain breaches, but with increased sophistication by leveraging blockchain transactions for payload downloads.

For businesses relying on open-source software, especially in development, it’s a reminder of the critical need for due diligence in package management. Regularly review and vet dependencies, and consider using tools to detect anomalous behavior in code.

Conclusion and Call to Action

It’s clear that while state-sponsored attacks threaten critical infrastructure, developers and businesses reliant on open source tools are also in the cross-hairs. Proactive measures, including robust security policies and updated threat intelligence, remain essential.

Before the next story: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.

Sources

NameTitleURL
The RegisterRussian spies take their half-click email attack from Zimbra to OutlookLink
AlienVault OTXRecent threat-intel pulses on NPM WormsLink
MSRCWindows Admin Center (WAC) Remote Code Execution VulnerabilityLink
BlackPoint CyberDjinn in the Machine: TaskWeaver’s Node.js Intrusion ChainLink
Hunt.ioFlying Eagle Android RAT and Night Dragon PlatformLink

Filed under

  • smb-security
  • uk-business
  • social-engineering
  • nation-state-attacks
  • supply-chain-risk
  • credential-theft