
CosmicEnergy: OT and ICS malware from Russia, maybe for red teaming. Updates on Volt Typhoon. Legion malware upgraded for the cloud. Natural-disaster-themed online fraud.
CyberWire Daily
00:00
The Atlantic Hurricane Season and Social Engineering Techniques
Legion, a commercial malware tool, has been upgraded to target Amazon Web Services from which it extracts credentials for authentication over SSH. Cato's security released a report on the threat emphasizing the progression towards exploiting more cloud services. Legion is known for its use of Telegram as an avenue of exfiltration and sending spam messages to dynamically generated US mobile numbers by making use of the stolen SMTP credentials.
Play episode from 05:54
Transcript


