Defense Industry Under Attack

In partnership with

Gone Phishing Banner

Welcome to Gone Phishing, your weekly cybersecurity newsletter thatโ€™s popping like fresh ๐Ÿž๐Ÿฅ–๐Ÿฅจ๐Ÿฐ๐Ÿง

Patch of the Week๐Ÿฉน

First thingโ€™s first, folks. Our weekly segment goes by many names. Patch of the Week, Tweak of the week. Okay, thatโ€™s itโ€ฆ ๐Ÿ˜ณ 

Congrats to Windows, the cybercriminals are no matchโ€ฆ for your patch! ๐Ÿฉน

Check out this freshly hatched patch ๐Ÿฃ

One door closes, a Window opens ๐Ÿก

๐Ÿ›ก๏ธ Microsoft Patch Tuesday: 57 Bugs Fixed, 6 Zero-Days Under Attack! ๐Ÿ’€

Microsoft just dropped 57 security patches, including 6 zero-days being actively exploited! โš ๏ธ

Top risks include:

  • Win32 Kernel exploit (CVE-2025-24983) lets attackers gain SYSTEM privileges.

  • File system flaws allowing data theft & remote code execution.

  • Microsoft Management Console bypass (CVE-2025-26633) to evade security protections.

The U.S. CISA has added these to its Known Exploited Vulnerabilities (KEV) list, giving agencies until April 1, 2025 to patch. If you havenโ€™t updated yet, do it NOW to stay protected! ๐Ÿ”’

Now, on to this weekโ€™s hottest cybersecurity news stories: 

  • ๐Ÿ€ Dark Crystal targets Ukraine ๐ŸŽฏ

  • ๐Ÿ‘พ Basta crimes spreads Evel Knievel ๐Ÿ๏ธ

  • ๐Ÿ”Ž ClearFake it before you make it nigga โ˜ ๏ธ

CERTified loverboy, certified pedophile ๐Ÿ“€

๐ŸŽฏ Dark Crystal RAT Campaign Targets Ukrainian Defense Sector

The Computer Emergency Response Team of Ukraine (CERT-UA) warns of a new cyber espionage campaign deploying Dark Crystal RAT (DCRat) against defense industry employees and military personnel.

๐Ÿšจ How the Attack Works

๐Ÿ”น Malicious messages sent via Signal ๐Ÿ“ฒ

๐Ÿ”น Compromised accounts used to increase trust ๐Ÿ•ต๏ธโ€โ™‚๏ธ

๐Ÿ”น Fake meeting minutes sent as archive files ๐Ÿ“

๐Ÿ”น Contains a decoy PDF + DarkTortilla crypter ๐ŸŽญ

๐Ÿ”น Decryption leads to full remote access via DCRat ๐Ÿ’ป

๐Ÿ•ต๏ธ Whoโ€™s Behind It?

CERT-UA attributes the attack to UAC-0200, active since mid-2024.

๐Ÿ”ฅ Why Itโ€™s Dangerous

โœ… DCRat executes arbitrary commands ๐Ÿ› ๏ธ

โœ… Steals sensitive data & credentials ๐Ÿ”‘

โœ… Grants attackers remote control over infected systems

๐ŸŒ Cyber Tensions & Signal Controversy

๐Ÿ”ธ Reports claim Signal is no longer assisting Ukrainian authorities in countering Russian cyber threats

๐Ÿ”ธ Signal denies these claims, stating it does not collaborate with any government

๐Ÿ” How to Stay Safe

โœ… Be cautious of unexpected Signal messages ๐Ÿšง

โœ… Verify senders before opening attachments

โœ… Use endpoint protection & monitor for unauthorized activity ๐Ÿ”

Russian-linked cyber actors are increasingly targeting secure messaging platformsโ€”stay vigilant and protect sensitive data! ๐Ÿšจ

Optimize global IT operations with our World at Work Guide

Explore this ready-to-go guide to support your IT operations in 130+ countries. Discover how:

  • Standardizing global IT operations enhances efficiency and reduces overhead

  • Ensuring compliance with local IT legislation to safeguard your operations

  • Integrating Deel IT with EOR, global payroll, and contractor management optimizes your tech stack

Leverage Deel IT to manage your global operations with ease.

Basta crimes ๐ŸŽค

๐Ÿ•ต๏ธ Leaked Black Basta Chats Reveal Russian Ties & Cybercrime Expansion

A leak of 200,000 internal chat messages from the Black Basta ransomware gang suggests possible links to Russian authorities and major cybercrime operations.

๐Ÿšจ Key Revelations

๐Ÿ”น Leader Oleg Nefedov (GG/AA) allegedly escaped arrest in Armenia with Russian officialsโ€™ help

๐Ÿ”น Two suspected offices in Moscow ๐Ÿข

๐Ÿ”น Used ChatGPT for fraud, malware development, and debugging ๐Ÿค–

๐Ÿ”น Overlaps with other ransomware gangs (Rhysida, CACTUS) ๐ŸŽญ

๐Ÿ”น Developed a custom C2 framework (โ€œBreakerโ€) for persistence & stealth

๐Ÿ”ฅ Brute-Force Attacks with BRUTED

๐Ÿ”น Custom tool โ€œBRUTEDโ€ automates credential stuffing ๐Ÿ”‘

๐Ÿ”น Targets firewalls, VPNs, & edge network devices

๐Ÿ”น Used since 2023 for large-scale password attacks

๐Ÿ•ต๏ธ Whatโ€™s Next for Black Basta?

๐Ÿ”ธ Possible rebrand with new ransomware based on Contiโ€™s code

๐Ÿ”ธ Heavy investment in automated cyberattacks

๐Ÿ”ธ Scaling credential theft & network infiltration

๐Ÿ” How to Stay Protected

โœ… Enforce strong, unique passwords & MFA ๐Ÿ”„

โœ… Monitor for unusual login attempts & brute-force attacks ๐Ÿ”

โœ… Patch firewalls & VPNs to prevent exploitation ๐Ÿ”ฅ

With growing automation & state-level connections, Black Basta remains a top ransomware threatโ€”organizations must stay ahead! ๐Ÿšง

Itโ€™s clearly a ClearFake ๐ŸŽญ

๐ŸŽญ ClearFake Uses Fake reCAPTCHA to Spread Malware

The ClearFake campaign is tricking users with fake reCAPTCHA and Cloudflare Turnstile verifications, leading them to download Lumma Stealer and Vidar Stealer malware. At least 9,300 websites have been compromised.

๐Ÿ”ฅ How the Attack Works

๐Ÿ”น Users visit a hacked siteโ€”JavaScript loads from Binance Smart Chain (BSC) ๐Ÿ“œ

๐Ÿ”น Victim is tricked into running malicious PowerShell (ClickFix technique)

๐Ÿ”น Deploys Emmenhtal Loader (PEAKLIGHT) โ†’ Drops Lumma Stealer

๐Ÿ”น New variant encrypts HTML & expands Web3 capabilities ๐Ÿ•ต๏ธโ€โ™‚๏ธ

โš ๏ธ Why This Is Dangerous

โœ… Uses blockchain (BSC) for resilience & stealth

โœ… Compromised over 9,300 sites & exposed 200,000+ users

โœ… Targets both Windows & macOS users

โœ… Frequently updated to evade detection

๐Ÿ›ก๏ธ How to Stay Safe

โœ… Never download "browser updates" from pop-ups ๐Ÿšซ

โœ… Be cautious of CAPTCHA prompts on unfamiliar sites

โœ… Monitor PowerShell execution & network traffic ๐Ÿ”

โœ… Keep browsers & security tools updated

With widespread infections & rapid evolution, ClearFake remains a major global threatโ€”stay vigilant! ๐Ÿšจ

๐Ÿ—ž๏ธ Extra, Extra! Read all about it! ๐Ÿ—ž๏ธ

Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!

  • ๐Ÿ›ก๏ธ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday ๐Ÿ“…

  • ๐Ÿ’ตCrypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for ๐Ÿ†“

  • ๐Ÿ“ˆBitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future ๐Ÿ‘พ

Let us know what you think.

So long and thanks for reading all the phish!

Give us a rating?

Login or Subscribe to participate in polls.

footer graphic cyber security newsletter