zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Mexican Firms Targeted in Spear-Phishing Campaign Delivering AllaKore RAT Malware
  • Kansas City Public Transportation Authority Hit by Ransomware
  • Pro-Ukraine Hackers Wiped Two Petabytes of Data from Russian Research Center

Mexican Firms Targeted in Spear-Phishing Campaign Delivering AllaKore RAT Malware

A spear-phishing campaign distributing a modified version of a remote access trojan called AllaKore RAT has been targeting large Mexican firms across various industries. Cybersecurity researchers have linked this campaign to an unidentified Latin America-based threat actor. The malware strain can enable threat actors to commit financial fraud by letting them send stolen banking credentials and unique authentication information back to a command-and-control (C2) server.

Kansas City Public Transportation Authority Hit by Ransomware

A ransomware attack on the Kansas City Area Transportation Authority (KCATA) reportedly impacted all its communication systems. The ransomware attack was claimed by the Medusa ransomware group, which posted data samples allegedly belonging to the organization on their extortion portal on the dark web. The ransom demand amounted to USD 2,000,000, and the organization was provided 10 days to negotiate a resolution.

Pro-Ukraine Hackers Wiped Two Petabytes of Data from Russian Research Center

According to the Main Directorate of Intelligence of the Ministry of Defense of Ukraine, pro-Ukraine hackers breached Russia’s Far Eastern Scientific Research Center of Space Hydrometeorology “Planet” database. The hacking group “BO Team” wiped off 2 petabytes of data from 280 servers, seriously inhibiting operations and incurring a loss of at least USD 10 million. In addition to wiping off the database, the center’s air conditioning and humidification systems and the emergency power supply were also affected.

VULNERABILITIES

  • CVE-2024-24736: The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558.
  • CVE-2024-0996: A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd.

BREACHES

Tags: DIB, tlp:green