zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 26, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • LockBit Ransomware Group Resurfaces After Law Enforcement Takedown
  • “SlashAndGrab” ScreenConnect Vulnerability Widely Exploited for Malware Delivery
  • RCMP Investigating Cyberattack as Its Website Remains Down

LockBit Ransomware Group Resurfaces After Law Enforcement Takedown

The LockBit ransomware group, despite recent law enforcement actions seizing their servers, has reemerged on the dark web with new infrastructure. They have shifted their data leak portal to a new .onion address on the TOR network and have listed 12 new victims. The group admitted that some of their websites were seized due to a PHP vulnerability (CVE-2023-3824) which they failed to update because of negligence. Additionally, it was revealed that the server seized by authorities contained over 1,000 decryption keys, with nearly 20,000 decryptors, half of which were protected, and constituted about half of all decryptors generated since 2019.

“SlashAndGrab” ScreenConnect Vulnerability Widely Exploited for Malware Delivery

ConnectWise recently addressed critical security vulnerabilities in its system, including an authentication bypass flaw and a path traversal issue. These flaws, initially without CVE identifiers, were patched on February 19. Later on, the company issued a warning about active exploitation attempts. The authentication bypass vulnerability allows attackers to create administrator-level accounts, while the path traversal flaw enables arbitrary code execution. Researchers assigned CVE-2024-1709 for the authentication bypass and CVE-2024-1708 for the path traversal bug, and named the vulnerabilities SlashAndGrab.

RCMP Investigating Cyberattack as Its Website Remains Down

The Royal Canadian Mounted Police (RCMP) has reported that its networks were targeted by a cyberattack. The national police force has initiated an investigation to determine the extent of the security breach. According to reports, the police force is managing a "cyber event" and has advised employees to remain cautious. Due to the alarming nature of the breach, the RCMP has taken significant measures to identify and prevent these types of threats. Additionally, no evidence has been found to suggest that foreign police and intelligence services have been affected by the cyber incident. The Office of the Privacy Commissioner (OPC) has been informed of the cyberattack.

BREACHES

Tags: DIB, tlp:green