zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 19, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 19, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • LockBit Ransomware Spills Over 40 GB of Boeing Data
  • Russian and Moldovan Mastermind Behind IPStorm Botnet Pleads Guilty; FBI Dismantles Malicious Network
  • ZeroFox Flash Report: Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability

LockBit Ransomware Spills Over 40 GB of Boeing Data

On October 26, ZeroFox Intelligence observed Russia-linked ransomware group LockBit listing Boeing as a victim on its darknet leaksite. LockBit claimed to have stolen a “tremendous amount of data'' from the aerospace company. On November 2, Boeing reportedly confirmed that it was aware of the attack. Boeing’s name was removed from the list thereafter, indicating that negotiations between the two parties had begun. However on November 12, LockBit published a package of data allegedly stolen from Boeing. The ransomware group released more than 43 GB of data, including backups for various systems, after Boeing reportedly refused to pay a ransom.

Russian and Moldovan Mastermind Behind IPStorm Botnet Pleads Guilty; FBI Dismantles Malicious Network

Russian and Moldovan national Sergei Makinin has pleaded guilty to 3 counts of violating 18 U.S.C. § 1030(a)(5)(A) Fraud and Related Activity in Connection with Computers. The FBI revealed the takedown of his botnet proxy network linked to the IPStorm malware, which had infected systems worldwide. Online reports suggest that the botnet infrastructure first infected Windows systems before tainting Linux, Mac, and Android devices. From June 2019 to December 2022, Makinin orchestrated a scheme, transforming these infected devices into proxies sold on his websites, proxx[.]io and proxx[.]net. He also admitted to earning over USD 550,000, and the cryptocurrency wallets holding these proceeds have been seized by the authorities.

ZeroFox Flash Report: Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability

Microsoft recently reported a zero-day vulnerability (CVE-2023-47246) in the SysAid IT support software that was exploited in limited attacks by Lace Tempest. ZeroFox Intelligence has published a flash report on the vulnerability, discussing its impact as well as the threat actor (and the associated ransomware) commonly referred to as Cl0p. The report recommends updating SysAid systems to version 23.3.36, along with a thorough inspection of SysAid servers and deletion of any unauthorized files or account. It is likely that CVE-2023-47246 will be exploited in further ransomware attacks by Cl0p and other operators against vulnerable SysAid consumers, which span across at least 140 countries.

Tags: DIB, tlp:green