ZeroFox Cyber Intelligence Daily Brief - January 31, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 31, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Government-Led Operation Fights Chinese Hacking Group Volt Typhoon
- China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz
- ZeroFox Intelligence Flash Report - Introducing Wing, New Ransomware-as-a-Service
U.S. Government-Led Operation Fights Chinese Hacking Group Volt Typhoon
The U.S. Government has launched an operation to tackle Volt Typhoon, a Chinese hacking group responsible for targeting thousands of internet-connected devices. Federal agencies have reportedly received legal authorization to remotely disable aspects of the campaign. In meetings with the private technology industry, the government has also sought assistance in tracking the threat group's activity. Intelligence officials consider Volt Typhoon part of a campaign to compromise Western critical infrastructure. There is also speculation that the threat-group-led cyberattacks could disrupt U.S. readiness in case of a geopolitical conflict in Taiwan.
China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz
Myanmar's Ministry of Defence and Foreign Affairs faced a cyberattack, reportedly by the threat actor known as Mustang Panda (also known as, Stately Taurus, BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, and Red Lich). The attack targets the country’s ministry in a double campaign by deploying backdoors and remote access trojans. This campaign in November saw the infection sequence start with a phishing email bearing a booby-trapped ZIP archive attachment, while the January campaign involves employing an optical disc image containing LNK shortcuts to trigger a multi-stage process.
ZeroFox Intelligence Flash Report - Introducing Wing, New Ransomware-as-a-Service
On January 28, positive-reputation English-speaking actor “blackhunt” announced a new Ransomware-as-a-Service (RaaS) operation known as Wing on the predominantly Russian-speaking dark web forum RAMP; it is the first RaaS launched on the forum in 2024. Wing Ransomware is touted as a state-of-the art ransomware tool with multiple features designed to facilitate effective deployment and defense evasion. At the time of reporting, ZeroFox has observed no instances of active deployment of the Wing Ransomware strain, although victims are likely to emerge in coming weeks. However, the announcement of the RaaS operation in English-only is indicative of the trend observed in Q4 2023 whereby English-speaking actors are willing to enter the ransomware scene, traditionally dominated by Russian-speaking operatives.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Aleksey_Petrov: Actor Claims to Leak Data From TranzactCard
- BreachForums user redcoat: Actor Claims to Leak Data From Skechers
VULNERABILITIES
- CVE-2023-50495: NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
- CVE-2023-48387: TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registry-related functions.
BREACHES
- Combolist: '200K UHQ PHEZZNA.txt' (131,087 Records): Email Address, Password
- Combolist: 'Valid combo.txt' (6,162 Records): Email Address, Password
Tags: DIB, tlp:green