ZeroFox Cyber Intelligence Daily Brief - February 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 12, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Chinese Threat Actors Targeting Philippines over Sea Disputes
- New Fortinet RCE Bug is Actively Exploited, CISA Confirms
- U.S. Offers USD 10 Million Bounty for Info Leading to Arrest of Hive Ransomware
ZeroFox Intelligence Flash Report - Chinese Threat Actors Targeting Philippines over Sea Disputes
China is likely escalating its military and cyber activity against its neighbors to project power in disputed waters. Recent Chinese activity has been directed towards the Philippines, with tensions rising amidst repeated confrontations between Chinese and Philippine vessels in the South China Sea. China is engaged in similar territorial disputes with several of its other neighbors, all of which have established closer ties to the United States in recent years. This escalating activity has now spread to include offensive cyber campaigns. On February 5, 2024, the Philippines’ Department of Information and Communication Technology (DICT) announced that it had thwarted attempts from China-backed hackers to break into the Philippine Coast Guard (PCG)’s websites, as well as the email systems of the president and government agencies.
New Fortinet RCE Bug is Actively Exploited, CISA Confirms
CISA confirms that the new Fortinet RCE bug is actively being exploited. An out-of-bounds write weakness found in the FortiOS operating system led to the vulnerability (CVE-2024-21762) that enables unauthenticated attackers to remotely execute arbitrary code using maliciously crafted HTTP requests. CISA has added the vulnerability to its Known Exploited Vulnerabilities Catalog, warning that such bugs are “frequent attack vectors for malicious cyber actors” that pose significant risks to the federal enterprise. CISA has also ordered the Federal Civilian Executive Branch (FCEB) to fix this vulnerability by February 16.
U.S. Offers USD 10 Million Bounty for Info Leading to Arrest of Hive Ransomware
The U.S. Department of State has announced up to USD 15 million for information about the Hive ransomware group members and their whereabouts that could lead to arrests and / or convictions. In the past, the law enforcement seized Hive’s darknet infrastructure and made one arrest in late 2023. The enforcement also thwarted around USD 130 million in ransom payments to Hive and likely curtailed the activities of their affiliates, potentially preventing further attacks. Researchers estimate that at least USD 210.4 million in payments were averted. Additionally, researchers note a trend towards big game hunting, targeting larger companies for larger ransoms. Moreover, ransom payments are increasingly being laundered through cross-chain bridges, instant exchangers, and gambling services, indicating a shift away from centralized exchanges and mixers by e-crime groups.
BREACHES
- Combolist: 'combo.txt' (44,246 Records): Email Address, Password
- Combolist: '50KCombos%20%40%20E-mail_pass%20Spain%20%28es%29.txt' (50,814 Records): Email Address, Password
Tags: DIB, tlp:green