zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies
  • China's Ministry of Public Security Suffers Massive Data Breach
  • Meta Disrupts 8 Spyware Firms, Three Fake News Networks

ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies

Ransomware & Digital Extortion (R&DE) collective LockBit’s leak site was seized by law enforcement agencies in a joint operation between 11 countries dubbed “Operation Cronos.” LockBit’s affiliate panel source code, chats, and victim information have also reportedly been seized, with a free decryption key released for victims. As many as 22 known LockBit onion site links are either offline or displaying a seizure message. However, some of the collective’s other dark web sites remain operational. The extent to which LockBit’s infrastructure has been disrupted or degraded in the long term is unclear. Given the ongoing and developing nature of the operation, it is possible additional law enforcement activity will further disrupt LockBit’s operational infrastructure.

China's Ministry of Public Security Suffers Massive Data Breach

A significant data breach, allegedly linked to a private contractor, iSoon, associated with the Chinese Ministry of Public Security, has shaken China's corridors of power. The leaked data on GitHub is associated with a global surveillance program led by a Chinese company and the Chinese government. ZeroFox Intelligence has come across reports suggesting that the leaked documents allegedly detail software capable of obtaining users' Twitter emails and phone numbers, real-time monitoring, publishing tweets, reading DMs, and more.

Meta Disrupts Eight Spyware Firms, Three Fake News Networks

Meta has identified and disrupted six spyware networks associated with eight companies in Italy, Spain, and the United Arab Emirates, alongside three fake news operations originating from China, Myanmar, and Ukraine. Pseudo-legal vendors often disguise themselves through complex corporate ownership structures. Spyware customers, who may also be attackers, commonly employ multiple tools in their attack chains. Meta observed surveillance companies using social platforms to test their exploits. Fake news networks, known as "coordinated inauthentic behavior" (CIB), are also prevalent on Meta-owned platforms, with three recent takedowns. One CIB from China targeted US audiences, posing as anti-war activists and American military family members. Another from Myanmar impersonated ethnic minorities, reaching users across various platforms including Telegram and YouTube. Lastly, a cluster operating in Ukraine aimed at individuals in Ukraine and Kazakhstan.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-1669: Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
  • CVE-2024-1670: Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

EXPLOITS

  • CVE-2021-42840: SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.
  • CVE-2021-33491: OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

BREACHES

Tags: DIB, tlp:green