ZeroFox Cyber Intelligence Daily Brief - February 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft
- ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies
- NSO Group Adds “MMS Fingerprinting” Zero-Click Attack to Spyware Arsenal
ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft
The iSoon data disclosures reveal the priorities, tools, and tradecraft of ongoing cyber espionage and influence operations being perpetrated by China nation-state actors, shedding light on the relationship between government contractors and the breadth of cyber tools at the Chinese government’s disposal. On or about February 16, GitHub account “I-S00N” published what they claimed were files associated with China-based company iSoon (aka Anxun), an organization affiliated with China’s Ministry of Public Safety (MPS). The alleged leaker organized the data into eight sections, with the information dating between 2018 and 2022 on wide-ranging tools and programs. The materials included technical details about some automated offensive tools, like an all-in-one penetration testing software program that enabled the automation of brute forcing, network attacks, directory scanning, data collection, et cetera. There were also automated social engineering kits that could be utilized in phishing campaigns and social media account takeovers.
ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies
Ransomware & Digital Extortion (R&DE) collective LockBit’s leak site was seized by law enforcement agencies in a joint operation between 11 countries dubbed “Operation Cronos.” LockBit’s affiliate panel source code, chats, and victim information have also reportedly been seized, with a free decryption key released for victims. As many as 22 known LockBit onion site links are either offline or displaying a seizure message. However, some of the collective’s other dark web sites remain operational. The extent to which LockBit’s infrastructure has been disrupted or degraded in the long term is unclear. Given the ongoing and developing nature of the operation, it is possible additional law enforcement activity will further disrupt LockBit’s operational infrastructure.
NSO Group Adds “MMS Fingerprinting” Zero-Click Attack to Spyware Arsenal
Cybersecurity researchers have discovered a previously unknown tactic called "MMS Fingerprint" that Israel's NSO Group has made available for use in campaigns. The technique came to light when looking into a contract between an NSO Group reseller and Ghana's telecom regulator. In the contract, it was described that by sending an MMS message to the target device, an NSO customer can obtain information about a target BlackBerry, Android, or iOS device and its operating system version. This allows them to drop its notorious Pegasus mobile spyware tool on mobile devices belonging to targeted individuals worldwide.
Tags: DIB, tlp:green