ZeroFox Cyber Intelligence Daily Brief - January 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hacker Spins-Up 1 Million Virtual Servers to Illegally Mine Crypto
- ZeroFox Intelligence Flash Report - German Protests Supported by Pro-Russian Threat Actor
- ZeroFox Intelligence Flash Report - Rise in Digital Extortion Attacks Against Healthcare in North America
Hacker Spins-Up 1 Million Virtual Servers to Illegally Mine Crypto
A cybercriminal in Ukraine orchestrated a large-scale cryptojacking attack by using hacked accounts to create 1 million virtual servers dedicated to mining approximately USD 2 million worth of cryptocurrency. The attack involved the exploitation of compromised accounts to gain administrative privileges. The suspect had reportedly been active since 2021 and used TON cryptocurrency wallets for illegal transactions. The attack wore-out the CPU and GPU performance of compromised organizations, leading to increased power costs and other damages. The arrested individual now faces criminal charges for unauthorized interference in accordance with the Criminal Code of Ukraine.
ZeroFox Intelligence Flash Report - German Protests Supported by Pro-Russian Threat Actor
NoName057(16), a pro-Russian threat actor group that normally targets supporters of Ukraine, hacked German websites in a show of support for protesting farmers. The group is likely opportunistically supporting the farmer protests because elements of the movement may be in favor of reducing the level of aid provided to Ukraine. ZeroFox anticipates activity by pro-Russia groups will likely escalate ahead of the elections. Threat actors such as NoName057(16) likely view successful anti-government protests in countries that support Ukraine, like Germany, as key to reducing Western support for Ukraine.
ZeroFox Intelligence Flash Report - Rise in Digital Extortion Attacks Against Healthcare in North America
Ransomware & Digital Extortion (R&DE) attacks against the North American healthcare sector reached the highest levels on record in Q4 2023 (October-December) following a sustained rise throughout the year. The North American healthcare industry R&DE threat landscape is highly diverse, and the increase in targeting has been driven by various groups. The rise in attacks against North American healthcare organizations is likely driven by several factors, including increased targeting of widely-leveraged software services, a possibly higher likelihood they will opt not to pay ransom demands, and a perception amongst threat actors that healthcare targets are more viable than those in other locations.
VULNERABILITIES
- CVE-2024-0538: A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical.
- CVE-2024-0552: Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the remote server.
BREACHES
- Combolist: '249.9K Best UHQ USA Social Target CombolistStrong PWD.txt' (246,205 Records): Email Address, Password
- Combolist: 'Hungary_98K.txt' (98,478 Records): Email Address, Password
Tags: DIB, tlp:green