ZeroFox Cyber Intelligence Daily Brief - February 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Chinese Threat Actors Targeting Philippines over Sea Disputes
- Rhysida Ransomware Decryptor Released
- New Microsoft Critical Exchange Bug Exploited as Zero-Day
ZeroFox Intelligence Flash Report - Chinese Threat Actors Targeting Philippines over Sea Disputes
China is likely escalating its military and cyber activity against its neighbors to project power in disputed waters. Recent Chinese activity has been directed towards the Philippines, with tensions rising amidst repeated confrontations between Chinese and Philippine vessels in the South China Sea. China is engaged in similar territorial disputes with several of its other neighbors, all of which have established closer ties to the United States in recent years. This escalating activity has now spread to include offensive cyber campaigns. On February 5, 2024, the Philippines’ Department of Information and Communication Technology (DICT) announced that it had thwarted attempts from China-backed hackers to break into the Philippine Coast Guard (PCG)’s websites, as well as the email systems of the president and government agencies.
Rhysida Ransomware Decryptor Released
Cybersecurity experts, including some from the Korea Internet and Security Agency (KISA), have successfully uncovered an implementation vulnerability in Rhysida ransomware, marking the first-ever decryption of the 2023-born ransomware. The experts used an analysis exposing the ransomware's utilization of LibTomCrypt, intermittent encryption, and a predictable pseudo-random number generator. The decryption applies only to the Windows PE version of the Rhysida. It does not apply to the ESXi or the PowerShell payload versions. KISA is distributing a Rhysida ransomware recovery tool free of charge to help victims of the ransomware.
New Microsoft Critical Exchange Bug Exploited as Zero-Day
Microsoft has issued a warning about a critical vulnerability (CVE-2024-21410) in the Exchange Server that was exploited as a zero-day. This flaw allows malicious threat actors to escalate privileges in NTLM relay attacks targeting vulnerable Microsoft Exchange Server versions such as Outlook. To address this vulnerability, users can install The Exchange Server 2019 Cumulative Update 14 (CU14) and enable NTLM credentials Relay Protections (also known as Extended Protection for Authentication or EPA). Microsoft has also announced that Extended Protection (EP) will automatically be enabled by default on all Exchange servers after the installation of this month's 2024 H1 Cumulative Update (aka CU14). This will help strengthen Windows Server auth functionality by mitigating authentication relay and man-in-the-middle (MitM) attacks.
Tags: DIB, tlp:green