zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 13, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 13, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Ransomed[.]vc Sunsets Operations, Auctions Off Infrastructure
  • LockBit Ransomware Unleashes Over 40 GB of Boeing Data
  • ZeroFox Flash Report: Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability
  • Data broker / initial-access broker / hacktivist group: Anonymous Collective DDoS attack
  • Vulnerabilities: CVE-2023-21392
  • Exploits: CVE-2022-24342
  • Breaches: Combolist: 'Craftrise.txt'

ZeroFox Intelligence Flash Report - Ransomed[.]vc Sunsets Operations, Auctions Off Infrastructure

Ransomware and data extortion (R&DE) collective Ransomed[.]vc has announced that it no longer wanted to continue running the project and was selling all aspects of its infrastructure. At the time of writing, one Ransomed[.]vc leak site has been closed down, and the other hosts a closing note on its home page. However, its ransomware forum remains active, likely to assist in the sale of the group’s infrastructure and assets. Threat actors will likely be motivated to purchase the infrastructure to target victims, create spin-off extortion operations, or leverage for further malicious activity. Ransomed[.]vc’s closure is very unlikely to have any considerable impact on the broader R&DE threat.

LockBit Ransomware Unleashes Over 40 GB of Boeing Data

On October 26, ZeroFox Intelligence observed Russia-linked ransomware group LockBit listing Boeing as a victim on its darknet leaksite. LockBit claimed to have stolen a “tremendous amount of data'' from the aerospace company. On November 2, Boeing reportedly confirmed that it was aware of the attack. Boeing’s name was removed from the list thereafter, indicating that negotiations between the two parties had begun. However on November 12, LockBit published a package of data allegedly stolen from Boeing. The ransomware group released more than 43 GB of data, including backups for various systems, after Boeing reportedly refused to pay a ransom.

ZeroFox Flash Report: Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability

Microsoft recently reported a zero-day vulnerability (CVE-2023-47246) in the SysAid IT support software that was exploited in limited attacks by Lace Tempest. ZeroFox Intelligence has published a flash report on the vulnerability, discussing its impact as well as the threat actor (and the associated ransomware) commonly referred to as Clop. The report recommends updating SysAid systems to version 23.3.36, along with a thorough inspection of SysAid servers and deletion of any unauthorized files or account. It is likely that CVE-2023-47246 will be exploited in further ransomware attacks by Cl0p and other operators against vulnerable SysAid consumers, which span across at least 140 countries.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-21392: In Bluetooth, a use after free bug could lead to local escalation of privilege when connecting to a Bluetooth device with no additional execution privileges needed.

EXPLOITS

  • CVE-2022-24342: JetBrains TeamCity - URL parameter injection leading to OAuth2 CSRF

BREACHES

Combolist: 'Craftrise.txt' (17,066 Records) Email address and password

Tags: DIB, tlp:green