ZeroFox Cyber Intelligence Daily Brief - February 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 27, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Hunters International Increases Ransomware Activity
- CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure
- White House Report Urges Tech Companies to Switch to Memory-Safe Programming Languages
ZeroFox Intelligence Flash Report - Hunters International Increases Ransomware Activity
Ransomware and digital extortion (R&DE) collective Hunters International has significantly increased its operational tempo, having so far conducted at least 29 attacks in February 2024. Hunters International is a ransomware-as-a-service (RaaS) operation that was first observed in October 2023. Over the following quarter, affiliates leveraged the ransomware against a diverse set of global targets from an array of industries. Since Q4 2023, over 60 percent of R&DE attacks leveraging Hunters International ransomware targeted organizations based in North America. The most targeted industries are manufacturing, construction, and healthcare.
CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure
CISA and other international cybersecurity organizations have issued a joint advisory that provides an overview of recent TTPs deployed by Russian Foreign Intelligence Service (SVR) cyber actors, also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard. In addition to outlining these TTPs used to gain initial access into the cloud environment, the advisory also includes advice to detect and mitigate such activities. The authoring agencies urged the network defenders and organizations to review the joint advisory for recommended mitigations.
White House Report Urges Tech Companies to Switch to Memory-Safe Programming Languages
The White House Office of the National Cyber Director (ONCD) has released a report urging tech companies to use memory-safe programming languages to improve software security. The report states that the best way to reinforce systems against exploitations is “ to secure one of the building blocks of cyberspace: the programming language.” Memory-safe languages, like Rust, can reduce commonly exploited memory safety vulnerabilities. Threat actors can exploit memory safety flaws to gain unauthorized access to or execute malicious codes on vulnerable systems.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHouse: Wangkanai Suga
- RansomHouse: Rapid Granulato
VULNERABILITIES
- CVE-2023-32307: Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to GHSA-8599-x7rq-fr54, several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and stun_parse_attr_uint32 were found because the lack of attributes length check when Sofia-SIP handles STUN packets. The previous patch of GHSA-8599-x7rq-fr54 fixed the vulnerability when attr_type did not match the enum value, but there are also vulnerabilities in the handling of other valid cases. The OOB read and integer-overflow made by attacker may lead to crash, high consumption of memory or even other more serious consequences. These issue have been addressed in version 1.13.15. Users are advised to upgrade.
- CVE-2023-38852: Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the unicode_decode_wcstombs function in xlstool.c:266.
EXPLOITS
- CVE-2021-31605: furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
- CVE-2021-31604: furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
BREACHES
- Combolist: 'message.txt' (111,835 Records): Email Address, Password
- Combolist: 'mixed_eu_mail_access_14k.txt' (14,967 Records): Email Address, Password
Tags: DIB, tlp:green