ZeroFox Cyber Intelligence Daily Brief - February 19, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 19, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - ALPHV Extortion Campaigns Continue into 2024
- Winter Vivern Cyberespionage Campaign Targets Critical Infrastructure of EU Countries
- Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor
ZeroFox Intelligence Flash Report - ALPHV Extortion Campaigns Continue into 2024
Ransomware and digital extortion (R&DE) collective ALPHV is continuing extortion campaigns in 2024, with its attack tempo very likely back on an upward trajectory following a recent disruption. Since the law enforcement (LE) activity reported by ZeroFox on December 19, 2023, the proportion of ALPHV attacks targeting entities based in North America has increased significantly—from a 2023 average of approximately 59 percent to 85 percent. It is likely that the specific targeting of North America and the increasing attack tempo contributed to the U.S. Department of State offering a series of financial rewards for related information on February 15, 2024. ALPHV attacks are very likely to continue over the next two months, targeting mostly North America-based organizations. There is a roughly even chance that the current upward trajectory in activity will plateau or decline as a result of continued LE attention and scrutiny.
Winter Vivern Cyberespionage Campaign Targets Critical Infrastructure of EU Countries
In October, the Russia-linked Winter Vivern group exploited cross-site scripting (XSS) flaws in Roundcube webmail servers across Europe in a campaign targeting government, military, and critical infrastructure in Georgia, Poland, and Ukraine. The threat group, alias TAG-70, TA473, and UAC-0114, used a Roundcube zero-day exploit, employing sophisticated social engineering to gain unauthorized access to mail servers in over 80 organizations. The campaign aimed to gather intelligence on European political and military affairs, potentially undermining security and alliances. Winter Vivern, suspected of serving Belarus and Russia's interests, has been active in cyber espionage since December 2020, with geopolitical motives evident in targeting Ukraine, Iran, and Georgia.
Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor
Iran-based threat actor, Charming Kitten, known for its social engineering attacks, has reportedly targeted Middle East policy experts with a new backdoor called BASICSTAR. The threat actor deploys the backdoor by distributing a fake webinar portal. BASICSTAR is a Visual Basic Script (VBS) malware that can collect system information, execute commands from a command-and-control server, and download/display decoy PDF files. The attack strategy often involves RAR archives containing LNK files, enticing recipients to join fake webinars on topics of interest.
VULNERABILITIES
- CVE-2024-26318: Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.
- CVE-2024-21626: runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
BREACHES
- Combolist: '18k Valid Mail 16.txt' (18,557 Records): Email Address, Password
- Combolist: 'VPN COMBO by @Magic_Ckg.txt' (102,429 Records): Email Address, Password
Tags: DIB, tlp:green