ZeroFox Cyber Intelligence Daily Brief - January 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Energy Giant Schneider Electric Hit by Cactus Ransomware Attack
- Scammers Use Couriers to Retrieve Cash and Precious Metals from Victims of Scams
- 1.8 TB Data of 750 Million Indian Mobile Users for Sale on Dark Web
Energy Giant Schneider Electric Hit by Cactus Ransomware Attack
Schneider Electric’s Sustainability Business division reportedly suffered a ransomware attack by the Cactus hacker group. The ransomware group gained access and stole terabytes of data and is now extorting the company by threatening to leak the stolen data if a ransom demand is not paid. The attack also disrupted some of Schneider Electric's Resource Advisor cloud platform, which continues to suffer outages. The company says that it is actively engaged in remediation efforts to restore its business platforms to a secure environment.
Scammers Use Couriers to Retrieve Cash and Precious Metals from Victims of Scams
The FBI released an advisory that warns the public about scams where criminals pose as tech support or U.S. government officials. These scammers employ various tactics, such as claiming the victim's financial accounts are hacked or at risk, convincing them to liquidate assets into cash or buy precious metals for protection. The scammers may use passcodes for authentication and assure victims that their assets will be safeguarded in a protected account. The warning advises the public to verify the legitimacy of such communications to prevent falling victim to these scams.
1.8 TB Data of 750 Million Indian Mobile Users for Sale on Dark Web
Cybersecurity researchers in India have come across hackers selling 1.8 TB data belonging to almost 750 million Indian mobile users on the dark web. In response to this observation, the Indian Department of Telecom has asked service operators to conduct security audits of their systems. The database on sale includes crucial information such as names, phone numbers, addresses, and Aadhar details. Hackers selling the data are demanding USD 3000 for the entire set.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user prapra123: Actor Claims to Leak Mail Access From Interpol Argentina
- Telegram user Anonymous Arabia: Actor Claims Attack Against Several Telecom Companies in India
VULNERABILITIES
- CVE-2023-3812: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- CVE-2023-5178: A use-after-free vulnerability was found in drivers/nvme/target/tcp.c
innvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation problem.
EXPLOITS
- CVE-2022-36267: In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
- CVE-2022-37393: Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
BREACHES
- Combolist: 'LinkSort #5 (10kk).txt' (5,693,584 Records): Email Address, Password
- Combolist: 'LinkSort #4 (10kk).txt' (8,195,498 Records): Email Address, Password
Tags: DIB, tlp:green