• Mercenary APTs – An Exploration

    Mercenary advanced persistent threat (APT) groups, sometimes called “hackers-for-hire” – and dubbed private-sector offensive actors (PSOAs) by Microsoft – have become a significant part of the threat landscape in recent years. These cyber-soldiers of fortune have been executing increasing numbers of attack campaigns for their clients, usually nation-states, that are looking for surveillance capabilities. Not…

  • Geopolitical and Cybersecurity Weekly Brief – 25 October 2021

    In the Americas, the US Congressional-Executive Commission on China (CECC) on 19 October, lawmakers urged President Joe Biden to ease asylum requirements and take other actions to assist those fleeing Hong Kong and other parts of China where alleged human rights abuses have occurred. Legislators on the committee vowed to maintain pressure on Beijing over…

  • Darknet Quarterly Review – Q3 2021

    The third quarter of 2021 saw the disappearance of Televend, which was a significant blow to darknet vendors who had begun using the service to sell their products via instant messaging platforms as opposed to conventional darknet markets. This quarter also provided a better understanding of how certain major darknet forums were enforcing their ransomware…

  • Geopolitical and Cybersecurity Weekly Brief – 18 October 2021

    In the Americas, on 13 October President Joe Biden announced a plan to clear extensive supply-chain bottlenecks over the next 90 days. As part of the plan, the Port of Los Angeles, in California, will increase its operations to 24 hours per day, seven days a week. In addition, Biden said the government had reached…

  • Persistent AgentTesla campaign targeting the UAE

    Cyjax analysts have analysed a long-running AgentTesla infostealer campaign targeting Dubai and the United Arab Emirates (UAE). The campaign began in at least January 2021 and the samples we gathered continued, almost daily, until May 2021. We have also seen new samples compiled in October 2021. Unlike most AgentTesla campaigns, the targeting focused heavily on…

  • Ransomware Review – September 2021

    This month saw the return of the REvil ransomware group (also known as Sodinokibi). The group’s infrastructure went offline in July, soon after their high-profile supply-chain attack targeting Kaseya. At the time, it was unclear if this was a voluntary decision or stemmed from a potential operation by law enforcement entities. However, the group’s infrastructure…

  • Geopolitical and Cybersecurity Weekly Brief – 5 October 2021

    In the Americas, the central bank in Venezuela carried out a currency recalibration in a bid to simplify transactions and counter hyperinflation. However, the move is unlikely to affect the growing usage of the US Dollar and address the extremely high inflation rate. Diplomatic ties between Canada, the US and China will remain tense despite…

  • Geopolitical and Cybersecurity Weekly Brief – 27 September 2021

    In the Americas, Canadian Prime Minister Justin Trudeau’s Liberal Party will remain in government after winning most seats during the 20 September general election. Meanwhile, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Czech Republic-based cryptocurrency exchange SUEX OTC for allegedly facilitating illicit ransomware payments. This marked the first time…

  • Inspiring individuals & organisations to ROAR!

    Cyjax will be joining with Marilise de Villiers Basson, the pioneering founder of ROAR!, to bring her blueprint to the cybersecurity leadership community. Marilise’s full site can be found here. Check out our partnership with Marilise here.

  • Have you found your ROAR!? Marilise de Villiers Basson, TEDx talk

    ROAR! is Marilise’s blueprint for how to live life on purpose, in her power, and with the courage to speak her truth. She wants the same for you. Learn how to tame the bully inside and out. Click here for the full TEDx talk. And check out our collaboration with Marilise, on finding the ROAR!…

  • EMEA and APAC governments targeted in widespread credential harvesting campaign

    Cyjax analysts have uncovered a large credential harvesting campaign targeting multiple government departments in APAC and EMEA countries. Over 50 hostnames were analysed, many of which were posing as the Ministry of Foreign Affairs, Ministry of Finance, or Ministry of Energy, in various countries such as Uzbekistan, Belarus, and Turkey; as well as the Main…

  • Geopolitical and Cybersecurity Weekly Brief – 13 September 2021

    In the Americas, Howard University in Washington, D.C, was forced to suspend classes on 8 September due to a ransomware attack. Meanwhile, Taiwan’s foreign ministry accused China of using Honduras’ November general election to disseminate a ‘false image’ of unstable diplomatic ties between Taiwan and Honduras. New York State (NYS) have patched a recently disclosed…

Scroll to Top