zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 15, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 15, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - GhostSec Hacktivist Group Launches GhostLocker Ransom-as-a-Service
  • LockBit Targets 10,000 Servers Through Citrix Bleed Vulnerability
  • Russian and Moldovan Mastermind Behind IPStorm Botnet Pleads Guilty; FBI Dismantles Malicious Network
  • Data broker / initial-access broker / hacktivist group: Big-Bro and resetmyname
  • Vulnerabilities: CVE-2020-5307 and CVE-2023-47532
  • Exploits: CVE-2022-30075
  • Breaches: Credit Card Data Breach: 2023-11-13 (c2e7e0 | 2947) Credit Card

ZeroFox Intelligence Flash Report - GhostSec Hacktivist Group Launches GhostLocker Ransom-as-a-Service

ZeroFox Intelligence has published a flash report discussing a new generation ransomware-as-a-service (RaaS) called GhostLocker, launched by hacktivist group GhostSec on October 8, 2023. GhostLocker offers alleged military-grade encryption, undetectability, negotiation services, and low fees, setting it apart from other similar RaaS offerings. These advanced features imply that ransomware is constantly evolving, which may make it harder to detect. ZeroFox has observed recent posts on the GhostSec Telegram channel targeting Israeli organizations, suggesting that GhostLocker ransomware may be used in future attacks against Israel. Additionally, Stormous ransomware group has announced it will be incorporating GhostLocker ransomware into its operations.

LockBit Targets 10,000 Servers Through Citrix Bleed Vulnerability

LockBit ransomware group is exploiting a known vulnerability (CVE-2023-4966, “Citrix Bleed”) to infiltrate systems of large organizations, steal data, and encrypt files. Despite Citrix releasing fixes for CVE-2023-4966 over a month ago, numerous exposed endpoints in different countries, including the United States, remain vulnerable to these attacks. LockBit has been associated with prominent ransomware attacks on major organizations in 2023. In July this year, ZeroFox Intelligence observed Japan's largest and busiest port, the Port of Nagoya, fall victim to one such LockBit attack. More recently, on November 12, ZeroFox Intelligence observed LockBit publish a package of almost 43 GB of data allegedly stolen from Boeing.

Russian and Moldovan Mastermind Behind IPStorm Botnet Pleads Guilty; FBI Dismantles Malicious Network

Russian and Moldovan national Sergei Makinin has pleaded guilty to 3 counts of violating 18 U.S.C. § 1030(a)(5)(A) Fraud and Related Activity in Connection with Computers. The FBI revealed the takedown of his botnet proxy network linked to the IPStorm malware, which had infected systems worldwide. Online reports suggest that the botnet infrastructure first infected Windows systems before tainting Linux, Mac, and Android devices. From June 2019 to December 2022, Makinin orchestrated a scheme, transforming these infected devices into proxies sold on his websites, proxx[.]io and proxx[.]net. He also admitted to earning over USD 550,000, and the cryptocurrency wallets holding these proceeds have been seized by the authorities.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2020-5307: PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection
  • CVE-2023-47532: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.

EXPLOITS

  • CVE-2022-30075: TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated)

BREACHES

Tags: DIB, tlp:green