ZeroFox Cyber Intelligence Daily Brief - February 1, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- “Secure by Design” Alert Urges Manufacturers to Eliminate Defects in SOHO Routers
- Brazilian Law Enforcement Operation Dismantles Grandoreiro Banking Trojan
- ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity
“Secure by Design” Alert Urges Manufacturers to Eliminate Defects in SOHO Routers
CISA and the FBI have published guidelines on security design improvements for small office/home office (SOHO) device manufacturers, amid ongoing attacks on SOHO routers by the China-sponsored Volt Typhoon group. This is the third publication of the new “Secure by Design” (SbD) series of alerts. The advisory focuses on eliminating exploitable defects—during the product design and development phases—in web management interfaces as well as implementing secure default device configurations.
Brazilian Law Enforcement Operation Dismantles Grandoreiro Banking Trojan
The Federal Police of Brazil has served five temporary arrest warrants and 13 search and seizure warrants in five states as part of an operation to investigate the threat actors responsible for Grandoreiro banking malware. The banking trojan is distributed via phishing emails containing a malicious link that leads to its deployment, letting threat actors remotely control the infected system. Threat actors can then exfiltrate data, including bank log-in information. Grandoreiro operators are suspected of moving at least EUR 3.6 million through fraud since 2019.
ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity
On January 22, threat actor “KonstLiv3” caused outrage in dark web community “RAMP” by claiming to have conducted a successful attack against a Russia-based organization using the LockBit malware strain–a claim that would violate the unwritten rules about using the strain to attack entities in Russia and other CIS (Commonwealth of Independent States) countries. On January 26, LockBit representatives made several posts in the forum, one of which claimed that the attack had been conducted by “Signature”-likely referring to a threat actor pseudonym. This was very likely an attempt to deny involvement, sanctioning or knowledge of the attack. It is likely the attack took place, and threat actor KonstLiv3 is in possession of the stolen data. It is likely that a customized version of LockBit malware was leveraged. The negative community response to this event is almost certainly indicative of the extremely low tolerance within dark web forums for attacks against victims based in the CIS.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Champion168: Actor Claims to Leak Data From Industrial and Commercial Bank of China
- BreachForums user InterSystems: Actor Claims to Leak Data From European Parliament
VULNERABILITIES
- CVE-2024-24333: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.
- CVE-2023-48202: Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.
BREACHES
- Combolist: '4336.txt' (4,336 Records): Email Address, Password
- Combolist: 'b42dd8978730.txt' (180 Records): Email Address, Password
Tags: DIB, tlp:green