zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Second New RaaS of 2024 Announced in Dark Web Forum
  • KV-Botnet Operators Restructure to Come Back After U.S. Federal Agency Takedown
  • Verizon Insider Data Breach Hits Over 63,000 Employees

ZeroFox Intelligence Flash Report - Second New RaaS of 2024 Announced in Dark Web Forum

On February 2, English-speaking threat actor “koley” announced the launch of a Ransomware-as-a-Service (RaaS) project named Ransomhub while seeking affiliates for the same. Ransomhub allegedly offers affiliates a host of new features, such as daily re-encryption and access to a control panel comprising a unique .onion domain address. The announcement about Ransomhub in English aligns with the recently-observed trend of English-speaking actors being willing to enter the traditionally Russian-dominated ransomware scene, as well as post in Russian-speaking dark web forums. The recent increase in new RaaS operations observed by ZeroFox is likely contributed to by the recent disruption of several prolific ransomware and digital extortion (R&DE) threat collectives.

KV-Botnet Operators Restructure to Come Back After U.S. Federal Agency Takedown

The KV-botnet underwent "behavioral changes" in response to U.S. law enforcement commands aiming to neutralize it. The botnet, comprising compromised routers and firewalls globally, served as a covert data transfer system for groups like Volt Typhoon. After the U.S. government's disruption efforts in late December 2023, the JDY cluster, primarily for reconnaissance, fell silent for roughly 15 days. Cybersecurity researchers are now reporting that the botnet operators have begun to restructure, showing heightened activity. In early December 2023, there was a notable increase in attempts to exploit the payload server, suggesting that the adversary was likely trying to re-exploit devices upon detecting their infrastructure going offline.

Verizon Insider Data Breach Hits Over 63,000 Employees

Over 63,000 employees from Verizon Communications were exposed to an insider data breach that exposed sensitive employee information. The exposed data varies per employee and includes information such as full name, physical address, social security number, national ID, gender, union affiliation, date of birth, and compensation information. To avoid similar instances, Verizon is proactively working towards strengthening its internal security and advised the exposed employees to enroll in a two-year identity theft protection and credit monitoring service.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-51761: In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.
  • CVE-2023-49716: In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

EXPLOITS

  • CVE-2022-29806: ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
  • CVE-2022-25090: Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

BREACHES

Tags: DIB, tlp:green