December 18: Get Wise With The Threat Intelligence Report

December 18, 2023
1 min read

Key Points:

  • Ukraine’s largest mobile operator, Kyivstar, was hit by the “largest cyber attack on telecom infrastructure in the world” which left millions without mobile and internet services.
  • Data storage and management company MongoDB revealed a cybersecurity breach that led to the exposure of customer data.
  • The Central Bank of Lesotho suffered a cyber attack which hindered inter-bank transfers and potentially disrupted currency exchange rates.
  • American provider of radiology and oncology services, Akumin, was reportedly targeted by two ransomware groups, leading to a data breach.
  • Cybersecurity firm Check Point Research published a report detailing the capabilities of the new Rhadamanthys stealer version 0.5.0.

In a recent cyber threat intelligence report, several major data breaches and cyber attacks were reported. Notably, Ukraine’s largest mobile operator, Kyivstar, suffered a massive cyber attack which disrupted services for millions of users. The onslaught is considered the “largest cyber attack on telecom infrastructure in the world”. Additionally, the breach affected air raid sirens, ATMs, and point-of-sale terminals. Solntsepek, a Russian-affiliated group, claimed responsibility for the attack.

In another major incident, MongoDB, a renowned database program company, confirmed a cybersecurity breach. The hackers reportedly gained unauthorized access and exposed sensitive customer data. The breach was detected on December 13, indicating that the threat actors may have had persistent access to the data for some time.

The Central Bank of Lesotho also faced a significant cyber attack, which caused multiple system outages. Although the bank confirmed that no financial losses occurred due to the attack, it had to suspend some of its system operations to halt further infiltration. This resulted in a temporary halt of inter-bank transfers, which could have indirect effects on the country’s currency exchange rates with neighboring South Africa.

Akumin, an American provider of radiology and oncology services, fell victim to two ransomware groups, identified as BlackSuit and BianLian. According to company statements and group published information, the hackers managed to exfiltrate and encrypt Akumin’s data. The groups reportedly obtained 5 TB of highly sensitive data, including Personal Health Information (PHI).

Cybersecurity firm Check Point Research also released a study detailing the advanced capabilities of the new version of the Rhadamanthys info stealer. The malware is constantly being updated by its author with diverse modules and features, making it a highly sought-after tool in the cyber-black market.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and