ZeroFox Cyber Intelligence Daily Brief - December 20, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 20, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: ALPHV Ransomware and Digital Extortion Operations Disrupted
- Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa
- 3,500 Arrested and USD 300 Million Seized in Interpol-Run Operation HAECHI IV
ZeroFox Intelligence Flash Report: ALPHV Ransomware and Digital Extortion Operations Disrupted
ZeroFox Intelligence has highlighted a joint international law enforcement effort to seize the victim leak site (and other associated websites) of the ALPHV/BlackCat ransomware group. This operation follows numerous incidents of ALPHV victim site disruption in December 2023, which has very likely contributed to the significantly reduced attack tempo observed by ZeroFox and the pivoting of affiliates toward other Ransomware-as-a-Service (RaaS) offerings. One seized website is ALPHV’s previous leak site, where the details and data belonging to victim organizations would be published. While ALPHV affiliates may continue to conduct attacks, the collective is likely to remain less prominent moving into 2024. ALPHV has publicly downplayed the significance of the operation, claiming the seized infrastructure is not used and is outdated.
Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa
Iran-based threat actor MuddyWater (also known as Seedworm) is reportedly attacking telecommunications sectors in Egypt, Sudan, and Tanzania using a newly discovered command-and-control (C2) framework—MuddyC2Go. Active since 2017, this group is reportedly linked to Iran's Ministry of Intelligence and Security (MOIS) and primarily targets groups in the Middle East. MuddyC2Go is equipped with a PowerShell script, automatically connecting to Seedworm's command-and-control server, granting remote access to compromised systems, and eliminating the need for manual intervention by the attackers.
3,500 Arrested and USD 300 Million Seized in Interpol-Run Operation HAECHI IV
A trans-continental police operation against financial cybercrimes, termed Operation HAECHI IV, has resulted in the arrests of 3,500 suspects and the seizure of USD 300 million worth of assets across 34 countries. The six-month operation targeted threat actors involved in seven types of cyber-enabled scams, including voice phishing, romance scams, online sextortion, investment fraud, and money laundering associated with illegal online gambling. Additionally, investigators used INTERPOL’s Global Rapid Intervention of Payments (I-GRIP), a stop-payment mechanism, to detect and freeze more than 82,000 bank accounts related to fraudulent activities.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Milw0rm: Actor Claims to Sell Data from China
- Telegram user Predatory Sparrow / Gonjeshke Darande: Actor Claims to have Attacked Iran Petrol Stations
VULNERABILITIES
- CVE-2023-49854: Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
- CVE-2023-49855: Cross-Site Request Forgery (CSRF) vulnerability in BinaryCarpenter Menu Bar Cart Icon For WooCommerce By Binary Carpenter.This issue affects Menu Bar Cart Icon For WooCommerce By Binary Carpenter: from n/a through 1.49.3.
EXPLOITS
- CVE-2020-6627: The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
- CVE-2020-14883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
BREACHES
- Combolist: 'Vietnam 129K.txt' (129,433 Records): Email Address, Password
- Combolist: 'Germany 124K.txt' (124,699 Records): Email Address, Password
Tags: DIB, tlp:green