zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukraine Claims Revenge Hack Against Moscow Internet Provider
  • ZeroFox Intelligence Flash Report: Alleged Sale of Three Exploits, Including Two Zero-Days
  • ZeroFox Intelligence Flash Report: LockBit Ends 2023 with Record Number of Attacks

Ukraine Claims Revenge Hack Against Moscow Internet Provider

The Ukrainian Blackjack hacker group conducted a cyberattack on Moscow-based Internet provider M9 Telecom. The attack resulted in the destruction of M9 Telecom's servers, wiping-off approximately 20 terabytes of data, including the company's official website, branch sites, mail server, and cyber protection services. Following the cyberattack, some residents in Moscow experienced disruptions in internet and television services. The hackers have reportedly warned that this attack is the start of a larger attack which will be “serious revenge for Kyivstar.”

ZeroFox Intelligence Flash Report: Alleged Sale of Three Exploits, Including Two Zero-Days

Untested Russian-speaking threat actor DrakenSnow announced the sale of three exploits on the predominantly Russian-language dark web forum exploit[.]in. The actor claimed to have discovered the exploits on behalf of a well-known company that discontinued its bug bounty program, which prompted the actor to seek profit within the dark web ecosystem. Despite the typically low credibility of sales of zero-day and one-day exploits, ZeroFox observed their increasing prevalence on deep and dark web (DDW) forums in 2023. Historically, such sales have been quickly dismissed as scams. The noticeable absence of negative commentary by forum posters about them and increased prevalence of these types of sales indicates a growing confidence amongst buyers in the legitimacy of zero-day/one-day exploits.

ZeroFox Intelligence Flash Report: LockBit Ends 2023 with Record Number of Attacks

ZeroFox reports that ransomware & digital extortion (R&DE) threat collective LockBit conducted more attacks during Q4 2023 (October-December) than in any other quarter, despite their activity accounting for a significantly reduced proportion of the wider threat landsape’s activity. A greater proportion of LockBit’s attacks were leveraged against the manufacturing and retail industries in Q4 2023, both of which are above the threat landscape average. LockBit’s targeting has increased almost uniformly across the landscape, with a greater number of victims across the majority of geographies and industries. A significant proportion of LockBit’s increased activity results from affiliates’ increased targeting of organizations in the manufacturing sector.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-51678: Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.
  • CVE-2023-52148: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.

BREACHES

Tags: DIB, tlp:green