zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 20 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • International Federal Agencies Seize LockBit Ransomware Leak Site
  • North Korean Hackers Linked to Defense Sector Supply-Chain Attack
  • NSO Group Adds “MMS Fingerprinting” Zero-Click Attack to Spyware Arsenal

International Federal Agencies Seize LockBit Ransomware Leak Site

ZeroFox Intelligence has observed a message on the ransomware leak site of LockBit stating the National Crime Agency of the UK and the FBI have taken over the site. The message further confirms the disruption of LockBit’s operations because of an ongoing and developing International Law Enforcement action. At the time of reporting, the site continues to be seized. LockBit’s administrator has claimed that the disruption was caused by exploiting a PHP vulnerability (CVE-2023-3824). LockBit has reportedly emailed its affiliates about unauthorized access to their systems that can result in the exposure of their personal information. The email also comprises measures to protect the affiliates’ personal information.

North Korean Hackers Linked to Defense Sector Supply-Chain Attack

Germany's BfV and South Korea's NIS have jointly issued a warning about an ongoing cyber-espionage campaign orchestrated by North Korea, targeting the global defense sector. The objective of these attacks is to pilfer advanced military technology data, aiding North Korea in modernizing its conventional arms and developing new military capabilities. The threat actor initially compromises an IT services provider, leveraging this access to infiltrate well-defended organizations incrementally. The report recommends several security measures to counter these attacks, such as restricting IT service providers' access, closely monitoring access logs, implementing multi-factor authentication (MFA), and enforcing strict user authentication policies for patch management systems.

NSO Group Adds “MMS Fingerprinting” Zero-Click Attack to Spyware Arsenal

Cybersecurity researchers have discovered a previously unknown tactic called "MMS Fingerprint" that Israel's NSO Group has made available for use in campaigns. The technique came to light when looking into a contract between an NSO Group reseller and Ghana's telecom regulator. In the contract, it was described that by sending an MMS message to the target device, an NSO customer can obtain information about a target BlackBerry, Android, or iOS device and its operating system version. This allows them to drop its notorious Pegasus mobile spyware tool on mobile devices belonging to targeted individuals worldwide.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-1559: The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
  • CVE-2024-24258: freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

EXPLOITS

  • CVE-2021-43326: Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
  • CVE-2021-43857: Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

BREACHES

Tags: DIB, tlp:green