zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Government-Led Operation Fights Chinese Hacking Group Volt Typhoon
  • Energy Giant Schneider Electric Hit by Cactus Ransomware Attack
  • ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity

U.S. Government-Led Operation Fights Chinese Hacking Group Volt Typhoon

The U.S. Government has launched an operation to tackle Volt Typhoon, a Chinese hacking group responsible for targeting thousands of internet-connected devices. Federal agencies have reportedly received legal authorization to remotely disable aspects of the campaign. In meetings with the private technology industry, the government has also sought assistance in tracking the threat group's activity. Intelligence officials consider Volt Typhoon part of a campaign to compromise Western critical infrastructure. There is also speculation that the threat-group-led cyberattacks could disrupt U.S. readiness in case of a geopolitical conflict in Taiwan.

Energy Giant Schneider Electric Hit by Cactus Ransomware Attack

Schneider Electric’s Sustainability Business division reportedly suffered a ransomware attack by the Cactus hacker group. According to the company, the ransomware group gained access and stole terabytes of data and is now extorting the company by threatening to leak the stolen data if a ransom demand is not paid. The attack also disrupted some of Schneider Electric's Resource Advisor cloud platform, which continues to suffer outages. The company says that it is actively engaged in remediation efforts to restore its business platforms to a secure environment.

ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity

On January 22, threat actor “KonstLiv3” caused outrage in dark web community “RAMP” by claiming to have conducted a successful attack against a Russia-based organization using the LockBit malware strain–a claim that would violate the unwritten rules about using the strain to attack entities in Russia and other CIS (Commonwealth of Independent States) countries. On January 26, LockBit representatives made several posts in the forum, one of which claimed that the attack had been conducted by “Signature”-likely referring to a threat actor pseudonym. This was very likely an attempt to deny involvement, sanctioning or knowledge of the attack. It is likely the attack took place, and threat actor KonstLiv3 is in possession of the stolen data. It is likely that a customized version of LockBit malware was leveraged. The negative community response to this event is almost certainly indicative of the extremely low tolerance within dark web forums for attacks against victims based in the CIS.

Tags: DIB, tlp:green