zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 21, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 21, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Europol Strike Wounds RagnarLocker Ransomware Group
  • Telegram Exploit Allows Hackers to Leak IP Addresses Through Calls
  • India targets Microsoft, Amazon tech support scammers in nationwide crackdown
  • Data broker / initial-access broker / hacktivist group: Exploit users: maveboy and nixploiter
  • Vulnerabilities: CVE-2023-3389 and CVE-2023-2124
  • Data Breach: Telegram: 'фб.zip' Botnet Breach and 'Erernity&Team [FREE LOGS].rar' Botnet Breach

Europol Strike Wounds RagnarLocker Ransomware Group

Europol, in collaboration with U.S. and Japanese law enforcement, has taken over RagnarLocker's Tor negotiation and data-leak sites in an ongoing law-enforcement operation. While the full scope of the operation and takedown has not been revealed at the time of reporting, Europol claimed it would publish details after “all the actions have been finalized.” The takedown of the sites may hinder organizations currently negotiating with ransomware attackers. Ragnar Locker is known for targeting the energy sector and has been linked to various attacks, including recent ones on Mayanei Hayeshua Medical Center and TAP Air Portugal.

Telegram Exploit Allows Hackers to Leak IP Addresses Through Calls

Popular messaging app Telegram could potentially expose the IP addresses of users, if an attacker is in their contact list and the user has accepted a call from them. A security researcher highlighted the issue and created an automated script for the exploit as proof of concept. The exploit is possible due to the app defaulting to peer-to-peer connections during voice calls. To prevent this, as a workaround users can navigate to Telegram's Settings > Privacy and Security > Calls and choose "Never" in the Peer-to-Peer menu. Other messaging apps are known to have faced similar IP address leakage issues.

India targets Microsoft, Amazon tech support scammers in nationwide crackdown

The Central Bureau of Investigation (CBI) in India, in collaboration with national and international agencies, and global private sector giants dismantled the infrastructure of several organized financial crime centers in "Operation Chakra-II". Searches were conducted involving 5 separate cases across 76 different locations that spanned multiple states. The accused duped foreign victims while posing as tech representatives of major multinational IT firms, contacting targets via internet pop-up messages that appeared as security alerts warning them of various technical issues. These centers were also responsible for targeting unsuspecting Indian victims with crypto-scams leading to a loss of over 1 billion in Indian currency.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-3389:: Local privilege escalation vulnerability in the Linux Kernel io_uring subsystem
  • CVE-2023-2124:: Out-of-bounds memory access flaw in the Linux kernel’s XFS file system

BREACHES

Tags: DIB, tlp:green