ZeroFox Cyber Intelligence Daily Brief - January 12, 2024
|by Alpha Team

ZeroFox Daily Intelligence Brief - January 12, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure
- Juniper Networks Releases Security Bulletin a DoS Enabling Bug in CISA Alert
- Finland Warns of Akira Ransomware Wiping NAS and Tape Backup Devices
Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure
A China-based cyber espionage group called Volt Typhoon is engaging in a stealthy campaign targeting legacy Cisco devices. This campaign involves exploiting vulnerabilities from 2019 in routers to gain control over the devices. Volt Typhoon is reportedly employing a previously unknown web shell called "fy.sh" on the targeted Cisco routers and other network edge devices. The group has been observed targeting critical infrastructure sectors in the United States, United Kingdom, and Australia, including water utilities, power suppliers, transportation, and communication systems.
Juniper Networks Releases Security Bulletin a DoS Enabling Bug in CISA Alert
Juniper Networks has released a security advisory to address a vulnerability (CVE-2024-21611) in Junos OS and Junos OS Evolved. A cyber threat actor could exploit this vulnerability to cause a denial-of-service (DoS) attack. The affected Juno OS versions are 21.4 earlier than 21.4R3, 22.1 earlier than 22.1R3, and 22.2 earlier than 22.2R3. Juno OS Evolved versions 21.4-EVO earlier than 21.4R3-EVO, 22.1-EVO earlier than 22.1R3-EVO, and 22.2-EVO earlier than 22.2R3-EVO carry this flaw. Juniper has resolved the flaw in Junos OS versions 21.4R3, 22.1R3, 22.2R3, 22.3R1, and all subsequent releases and Junos OS Evolved versions 21.4R3-EVO, 22.1R3-EVO, 22.2R3-EVO, 22.3R1-EVO, and all subsequent releases.
Finland Warns of Akira Ransomware Wiping NAS and Tape Backup Devices
The Finnish National Cybersecurity Center (NCSC-FI) warns about increased Akira ransomware activity detected last December, with a focus on targeting companies in the country and wiping backups. Wiping backups adds to the severity of the attack, increasing pressure on victims by eliminating the option of restoring their data without paying a ransom. The attackers have destroyed backups, compromised various storage systems, including network-attached storage (NAS) devices commonly used by smaller organizations and tape backup devices, which serve as secondary systems for storing digital copies of data.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Beregini: Actor Claims to Recruite KillMilk Former Leader of Killnet
- Telegram user Bawless: New Telegram Group Emerges Selling an Android RAT
VULNERABILITIES
- CVE-2022-48620: uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.
- CVE-2023-51766: Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations.
BREACHES
- Combolist: '400x Minecraft Accounts.txt' (400 Records): Email Address, Password
- Combolist: 'Hotmail_Brazil_Private_Full_access__-_DXP.txt' (375 Records): Email Address, Password
Tags: DIB, tlp:green