Now, let’s get tactical.
A recent China-linked router hacking campaign demonstrated that small and medium-sized businesses(SMBs) with old routers have become a target for nation-state hackers. The FBI disclosed that the campaign compromised hundreds of SMB and home routers, forming a botnet that could be used for launching attacks against critical infrastructure. Using unsupported routers by SMBs makes them an easy target for threat actors, who can exploit vulnerabilities and go undetected.
Remote desktop software maker AnyDesk experienced a cyber attack that compromised its production systems. The company has revoked security certificates, replaced systems, and urged users to change passwords. While it is unknown if any information was stolen, there is no evidence of end-user systems being affected. AnyDesk recommends downloading the latest software version and has disclosed the incident to relevant authorities.
A new cyberattack campaign targeting macOS users has been discovered, using cracked copies of popular software products to distribute a backdoor. Its large-scale and novel, multistage payload delivery technique set this campaign apart. The threat actor behind the campaign is using cracked macOS apps with titles that would interest business users, putting organizations at risk if they do not restrict user downloads. The campaign may be an attempt to build a macOS botnet. The malware, called Activator, prompts users to copy two malicious executables to the Applications folder, disabling macOS’ Gatekeeper settings and initiating a series of malicious actions. Even if the cracked software is later removed, the infection remains.
The fact that the macOS campaign is unique caught my eye – a macOS botnet is a scary proposition.
If you need another reason to upgrade your customer’s old gear, the fact that it’s being specifically targeted and called out by the FBI should help. One would hope, right?

