RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityAugust 3, 2023

The Week in Security: Malware gives remote access to air-gapped devices, cyber attackers target Italy

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Kate Tenerowicz black white headshot
Kate TenerowiczKate Tenerowicz
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
The Week in Security: Malware gives remote access to air-gapped devices, cyber attackers target Italy

This week: Hackers use new malware to gain remote access to air-gapped devices. Also: Cybercriminals are using WikiLoader to attack Italian organizations.

This Week’s Top Story

Hackers use new malware to breach air-gapped devices in Eastern Europe

The last frontier of safety from remotely executed attacks, air-gapped devices, has been conquered. A quick online search on air-gapped devices tells you that they are computers or networks that are isolated from any external connection. To transfer any data to or from them, one needs a removable media device (a USB, for example). It seems foolproof, being totally removed from the wider world of connected devices. However, this this has now been shown to be just an illusion: State-sponsored Chinese hackers have created a new malware that can steal data from these air-gapped systems without the use of repelling, identity theft, or retina scans. Researchers at Kaspersky discovered this new malware and have linked it to the cyber-espionage group APT31, a.k.a. Zirconium.

The methodology of Zirconium is quite elaborate. Its attack is executed in three stages, using at least 15 distinct implants, plus the group’s iconic FourteenHi malware family. The first stage uses implants to establish persistence and remote access to the compromised systems while also collecting reconnaissance data. The second stage involves implanting a more specialized malware that can steal the data from the systems using USB propagation. Finally, to exfiltrate the data, the hackers use more implants to upload the stolen information to their command-and-control servers.

For those wondering about the details of the malware — roughly 15 of them, plus FourteenHi — Kaspersky has managed to study the Stage 1 and Stage 2 malware in close detail. Despite the large number of implants involved, the attacks remain stealthy and contain a multitude of tactics, techniques, and procedures (TTPs).

News Roundup

Here are the stories we’re paying attention to this week.

Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan (The Hacker News)

Organizations in Italy are being targeted by a phishing campaign that uses a new strain of the malware WikiLoader with the goal of installing Ursnif (Gozi), a banking Trojan, stealer, and spyware. The phishing campaigns center on the use of emails containing either Microsoft Excel, Microsoft OneNote, or PDF attachments. Once launched or downloaded, these attachments deploy WikiLoader, which in turn downloads Ursnif. This campaign appears to be ongoing and may be tricky to catch since WikiLoader is heavily obfuscated and comes with evasive maneuvers.

Pentagon investigating compromise in Air Force communications (CSO Online)

An engineer working at Arnold Air Force Base in Tennessee stole government radio technologies and gained unauthorized administrator access. The technologies were used to launch campaigns against the U.S. Department of Defense, affecting roughly 17 installations. This marks the second compromise of the Pentagon within three months.

US internet hosting company appears to facilitate global cybercrime, researchers say (CyberScoop)

Cloudzy, an Internet hosting company with a New York phone number, may be aiding hackers from Iran, Russia, and North Korea. The company either knowingly or unwittingly provides a platform for illicit digital activity, acting as a command-and-control provider. It is recommended that anyone doing business with Cloudzy pause as its legality comes into question.

Canon warns of Wi-Fi security risks when discarding inkjet printers (Bleeping Computer)

Canon is warning users of its ink-jet printers that the devices’ Wi-Fi network is vulnerable to exposure. The Wi-Fi connection settings stored in the devices’ memories were not wiped during the initialization process as they should have been. This flaw means that anyone who extracts the printer memory can gain many of the details of a user’s Wi-Fi network. The exact details that can be accessed vary from model to model, but most printers store at least the network SSID, the password, the network type (WPA3, WEP, etc.), the assigned IP address, the MAC address, and the network profile — enough information for a third party to gain unauthorized network access, steal data, and deploy a variety of malicious software.

Apple Users Open to Remote Control via Tricky macOS Malware (Dark Reading)

Apple users are vulnerable to remote control due to a new data-stealing malware with a sneaky approach that uses hidden virtual network computing (hVNC). The hVNC is a doppelgänger of VNC, which is typically used by IT teams to provide remote technical support to users. Once bad actors have remote control through the hVNC, they can access login credentials, personal data, financial information, and more. Most concerning is the malware’s resilience to system reboots and other methods of removal.

Keep learning

  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get key insights into why Gartner® identified binary analysis a must-have control in its recent CISO Playbook for Commercial Software Supply Chain Security.
  • Get up to speed on the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Plus: Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Tags:AppSec & Supply Chain Security

More Blog Posts

Agentic AI architecture

Agentic AI risk isn't a model problem. It's an architecture problem.

Agentic AI is moving the perimeter from components to data — and most strategies aren't built for that.

Learn More about Agentic AI risk isn't a model problem. It's an architecture problem.
Agentic AI risk isn't a model problem. It's an architecture problem.
AI coding agents

The race to secure AI coding: 4 steps to rein agents in

Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Learn More about The race to secure AI coding: 4 steps to rein agents in
The race to secure AI coding: 4 steps to rein agents in
Shai-hulud worm DevOps

Update to npm blocks install scripts: What it means for AppSec

Disabling scripts by default closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.

Learn More about Update to npm blocks install scripts: What it means for AppSec
Update to npm blocks install scripts: What it means for AppSec
MCP is the new API

MCP security tracks API's playbook — we know how that ends

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

Learn More about MCP security tracks API's playbook — we know how that ends
MCP security tracks API's playbook — we know how that ends

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top