ZeroFox Cyber Intelligence Daily Brief - December 15, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 15, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Anonymous Russia Announces War Against NATO
- ZeroFox Intelligence Flash Report - ALPHV and NoEscape Affiliates Very Likely Pivoting to Alternative Operations
- Idaho National Laboratory Confirms November Data Breach Impacted 45,000 Individuals
ZeroFox Intelligence Flash Report - Anonymous Russia Announces War Against NATO
On December 14, 2023, pro-Russian hacktivist collective Anonymous Russia announced on its Telegram channel that it is preparing for a cyber war against NATO. Anonymous Russia is known for its politically-motivated cyberattacks including defacements and data leaks, and Distributed Denial of Service (DDoS) attacks against pro-Ukrainian targets. The collective is unlikely to have the capability to conduct a highly-disruptive campaign against NATO targets of critical value, and any attacks are likely to have limited operational impact. However, ZeroFox cannot rule out that campaigns against NATO-aligned countries or entities could involve collaboration with more capable hacktivist groups.
ZeroFox Intelligence Flash Report - ALPHV and NoEscape Affiliates Very Likely Pivoting to Alternative Operations
Disrupting operations of prolific ransomware & digital extortion (R&DE) collectives ALPHV (aka BlackCat) and NoEscape will likely drive former affiliates to pivot to other R&DE offerings. ALPHV’s operation has most likely been distupted by a currently-undisclosed law enforcement operation against the cartel. NoEscape operators have reportedly conducted an exit scam, stealing ransom payments and closing down the group’s web panels and data leak sites. If affiliates and R&DE collective operators are unable to continue deploying these strains, they will very likely pivot to other well-known R&DE offerings or rebrand and launch their own extortion operations.
Idaho National Laboratory Confirms November Data Breach Impacted 45,000 Individuals
Idaho National Laboratory (INL), a U.S. Department of Energy (DOE) national laboratory primarily involved in nuclear research, has disclosed that cyberattackers have exfiltrated data of 45,047 current and former employees. On November 20, 2023, ZeroFox Intelligence observed SiegedSec, a hacktivist group, claiming to have breached the systems of the research lab and acquired a substantial amount of sensitive data, including the Social Security numbers of the impacted individuals. INL confirmed the data breach in an official alert, stating that it has affected the company’s Oracle HCM systems that support Human Resources applications. The lab has offered no-cost identity protection and credit monitoring services to all the victims.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHouse user RansomHouse: Dameron Hospita
- Telegram user Anonymous Russia: Actor Allegedly Announces War Against NATO
VULNERABILITIES
- CVE-2023-48371: ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
- CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
EXPLOITS
- CVE-2023-27253: A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
- CVE-2023-1258: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
BREACHES
- Combolist: 'valid.txt' (68,370 Records): Email Address, Password
- Combolist: 'x37_expressvpn.txt' (35 Records): Email Address, Password
Tags: DIB, tlp:green