ZeroFox Cyber Intelligence Daily Brief - February 15, 2024
|by Alpha Team

ZeroFox Daily Intelligence Brief - February 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - New Tax Fraud Scheme Leveraging Employee Identification Numbers
- South Korea Says Presumed North Korean Hackers Breached Personal Emails of Presidential Staffer
- New Microsoft Critical Exchange Bug Exploited as Zero-Day
ZeroFox Intelligence Flash Report - New Tax Fraud Scheme Leveraging Employee Identification Numbers
On February 11, well-regarded Russian-speaking threat actor “Journalist” disclosed a method of leveraging the legitimate gocardless[.]com service to identify corporate employee identification numbers (EINs) to conduct tax fraud schemes against U.S. citizens, on the Russian-speaking community “Coockie Pro.” Threat actors can use EINs to create fake tax documents such as the W2 form and raise tax refund claims. ZeroFox anticipates schemes of this nature will continue to propagate among financially-motivated actors ahead of the April 15 U.S. tax return deadline. Tax refund and related schemes surge on the deep and dark web (DDW) in the run up tax season in the U.S. year-on-year.
South Korea Says Presumed North Korean Hackers Breached Personal Emails of Presidential Staffer
The South Korean President’s office observed a breach into one of the President’s staff member’s personal emails. The attack was presumed to be North Korean hackers who stole data, the nature of which has not been revealed yet. North Korea has denied these claims although it is known in the past for its large-scale cyber crimes including data breaches. The attack was detected ahead of Yoon Suk Yeol’s visit and reportedly has not been of any consequence to the overall security system.
New Microsoft Critical Exchange Bug Exploited as Zero-Day
Microsoft has issued a warning about a critical vulnerability (CVE-2024-21410) in the Exchange Server that was exploited as a zero-day. This flaw allows malicious threat actors to escalate privileges in NTLM relay attacks targeting vulnerable Microsoft Exchange Server versions such as Outlook. To address this vulnerability, users can install The Exchange Server 2019 Cumulative Update 14 (CU14) and enable NTLM credentials Relay Protections (also known as Extended Protection for Authentication or EPA). Microsoft has also announced that Extended Protection (EP) will automatically be enabled by default on all Exchange servers after the installation of this month's 2024 H1 Cumulative Update (aka CU14). This will help strengthen Windows Server auth functionality by mitigating authentication relay and man-in-the-middle (MitM) attacks.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Ynnian: Actor Claims to Leak Data From Massachusetts Institute of Technology
EXPLOITS
- CVE-2022-25359: On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- CVE-2022-24124: The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
BREACHES
- Combolist: 'EU_Mix (4).txt' (19,204 Records): Email Address, Password
- Combolist: 'epic inbox x450.txt' (429 Records): Email Address, Password
Tags: DIB, tlp:green