ESET Threat Report H2 2023
- ESET Expert

- Dec 19, 2023
- 2 min read

A view of the H2 2023 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
The second half of 2023 witnessed significant cybersecurity incidents. Cl0p, a notorious cybercriminal group known for carrying out ransomware attacks on a major scale, garnered attention through its extensive “MOVEit hack”, which surprisingly did not involve ransomware deployment. The attack targeted numerous organizations, including global corporations and US governmental agencies. A key shift in Cl0p’s strategy was its move to leak stolen information to open worldwide web sites in cases where the ransom was not paid, a trend also seen with the ALPHV ransomware gang. Other new strategies in the ransomware scene, according to the FBI, have included the simultaneous deployment of multiple ransomware variants and the use of wipers following data theft and encryption.
In the IoT landscape, our researchers have made a notable discovery. They have identified a kill switch that had been used to successfully render the Mozi IoT botnet nonfunctional. It is worth mentioning that the Mozi botnet is one of the largest of its kind we have monitored over the past three years. The nature of Mozi’s sudden downfall raises the question of whether the kill switch was used by the botnet creators or Chinese law enforcement. A new threat, Android/Pandora, surfaced in the same landscape, compromising Android devices – including smart TVs, TV boxes, and mobile devices – and utilizing them for DDoS attacks.
Amidst the prevalent discussion regarding AI-enabled attacks, we have identified specific campaigns targeting users of tools like ChatGPT. We also noticed a considerable number of attempts to access malicious domains with names resembling “chapgpt”, seemingly in reference to the ChatGPT chatbot. Threats encountered via these domains also include web apps that insecurely handle OpenAI API keys, emphasizing the importance of protecting the privacy of your OpenAI API keys.
We have also observed a significant increase in Android spyware cases, mainly attributed to the presence of the SpinOk spyware. This malicious software is distributed as a software development kit and is found within various legitimate Android applications. On a different front, one of the most recorded threats in H2 2023 is three-year-old malicious JavaScript code detected as JS/Agent, which continues to be loaded by compromised websites. Similarly, Magecart, a threat that goes after credit card data, has continued to grow for two years by targeting myriads of unpatched websites. In all three of these cases, the attacks could have been prevented if developers and admins had implemented appropriate security measures.
Lastly, the increasing value of bitcoin has not been accompanied by a corresponding increase in cryptocurrency threats, diverging from past trends. However, cryptostealers have seen a notable increase, caused by the rise of the malware-as-a-service (MaaS) infostealer Lumma Stealer, which targets cryptocurrency wallets. These developments show an ever-evolving cybersecurity landscape, with threat actors using a wide range of tactics.
I wish you an insightful read.

Gần đây mình có thấy nhiều người nhắc tới Sc88 bù link nha trên các diễn đàn giải trí nên cũng tranh thủ vào xem thử. Mình không tìm hiểu quá sâu mà chủ yếu quan sát cách họ thiết kế giao diện và sắp xếp nội dung. Cảm nhận chung là trang có bố cục rõ ràng, các danh mục được phân chia hợp lý nên rất dễ theo dõi. Với những ai thích trải nghiệm đọc nhanh và giao diện trực quan thì đây là kiểu thiết kế khá dễ tạo thiện cảm.
I noticed theplanetclicker.net linked in the comment section of another post so I got curious and checked it out. The page loaded quickly, didn't have to wait around like with some other game sites I've tried. The upgrade info is presented pretty clearly right from the start.
cổng game b52 dạo này thấy bạn bè nhắc hoài nên mình cũng ghé vào xem thử cho biết, kiểu tò mò thôi chứ không rành mấy vụ chơi bời. Vừa vào là thấy giao diện không giống mấy trang đại trà mình từng lướt, họ làm theo kiểu chủ đề “chiến đấu trên không” nhìn khá bắt mắt, có hiệu ứng 3D nên cảm giác lạ lạ. Mình thích nhất là phần thông tin cơ bản để ngay trên web, kiểu điều khoản sử dụng với chính sách bảo mật, khỏi phải mò sâu mới thấy. Lướt vài phút là biết chỗ nào cần đọc trước, vì các khối nội dung và mục chính sách được đặt khá rõ…
The best part about thedriftboss is how accessible it is. You can literally open the game in your browser and start drifting within seconds. It's perfect whether you only have five minutes or end up playing for an hour chasing a new personal best.