ZeroFox Cyber Intelligence Daily Brief - December 27, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 27, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Infamous Carbanak Malware Reemerges in Ransomware Attacks
- Integris Health Patients get Extortion Emails After Cyberattack
- NASA Releases New Space Security Best Practices Guidelines
Infamous Carbanak Malware Reemerges in Ransomware Attacks
Cybersecurity agencies have observed infamous banking malware strain Carbanak in ransomware attacks with renovated strategies. The malware strain can now modify itself to assimilate attack vendors and improve its effectiveness. Last month, the return of Carbanak was marked with its distribution through compromised websites while masquerading as different business-related software systems. In the most recent documented attack, the compromised websites were hosting malicious installer files disguised as genuine utilities to facilitate Carbanak’s deployment.
Integris Health Patients Receive Extortion Emails After Cyberattack
Integris Health, a non-profit healthcare network in Oklahoma, experienced a confirmed cyberattack by unknown threat actors in November leading to the theft of patient data. Patients have received blackmail emails claiming their data will be sold to other threat actors unless an extortion demand is met. The hackers have allegedly stolen personal information of over 2 million patients, including information like Social Security numbers, phone numbers, insurance information, and employer details. The extortion emails include a link to a Tor site, listing over 4,600,000 data records, for recipients to pay the threat actors USD 50 to delete their data.
NASA Releases New Space Security Best Practices Guidelines
NASA’s Space Security: Best Practices Guide (BPG) has been designed to ensure the longevity and resilience of its space missions against cyber threats. Amongst the several principles NASA highlights, one suggests that space mission systems should be accessed only by authenticated and authorized personnel, devices, and software. Other recommended steps include incorporating an onboard cyber actor actions detection function and a fault management bypass protection. The guideline also suggests that systems should be capable of recovering from communications jamming and spoofing attempts besides being secured with MultiFactor authentication. Additionally, system software updates should be validated as free from malware. For a more comprehensive study of the guidelines, download the BPG brochure here.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegarm user ThreatSec: Actor Claims to Leak Data from Taiwanese Judiciary System
- Telegram user Dark Strom Team: Actor Claims Upcoming Attack Against Israel and United States
VULNERABILITIES
- CVE-2023-48107: Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.
- CVE-2023-27043: The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character.
BREACHES
- Combolist: 'lmrcl.com 40k.txt' (38,592 Records): Username, Password
- Combolist: 'Good (3).txt' (19,967 Records): Email Address, Password
Tags: DIB, tlp:green