ZeroFox Cyber Intelligence Daily Brief - February 16, 2024
|by Alpha Team

ZeroFox Daily Intelligence Brief - February 16, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Government Neutralizes Botnet Operated by Russian APT28
- Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
- LockBit Claims Cyberattack on Fulton County
U.S. Government Neutralizes Botnet Operated by Russian APT28
The U.S. government has neutralized a Russian APT28 cyber-espionage operation using a small office/home office (SOHO) router botnet of several Ubiquiti Edge OS routers. The Justice Department revealed that hackers not associated with Russian Intelligence first infected the target routers with Moobot malware. Subsequently, APT28, connected to the Russian GRU, repurposed these compromised routers as a global espionage platform. Authorized by court order, U.S. law enforcement neutralized the botnet by copying and deleting stolen data from compromised routers. The operation also temporarily modified firewall rules to block remote access.
Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
CISA and the Multi-State Information Sharing & Analysis Center (MS-ISAC) investigated a state government organization's network environment after documents containing host and user information, along with metadata, were discovered on a dark web brokerage site. The assessment confirmed that an unidentified threat actor accessed the documents via the account of a former employee after connecting to the victim's VPN [T1133] in an attempt to blend in with legitimate traffic and avoid detection. A Cybersecurity Advisory (CSA) has been released by CISA and MS-ISAC to offer network defenders with the tactics, techniques, and procedures (TTPs) used by the threat actor and methods to protect against similar exploitation of both unnecessary and privileged accounts.
LockBit Claims Cyberattack on Fulton County
On February 14, ZeroFox Intelligence observed the notorious LockBit 3.0 ransomware group claiming an attack on Fulton County, saying it has access to confidential documents. The cyberattack continues to disrupt technological systems at the county government, including justice and property tax systems and two-thirds of phone lines. The threat actor has stated it aims to “give maximum publicity to this situation” and that the documents, once public, will be of interest to many.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Ynnian: Actor Claims to Leak Data From New York University
- Telegram user Anonymous Sudan: Actor Claims DDoS Attack Against Swedish Healthcare and ChatGPT
VULNERABILITIES
CVE-2023-6451: Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
CVE-2024-0036: In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
EXPLOITS
- CVE-2020-12502: Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.
- CVE-2021-46398: A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.
BREACHES
- Combolist: 'nice.txt' (1,415 Records): Email Address, Password
- Combolist: '2_1.txt' (49,698 Records): Email Address, Password
Tags: DIB, tlp:green