ZeroFox Cyber Intelligence Daily Brief - February 29, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 29, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Increased Demand for X Accounts in Dark Web Forum
- The White House Issues Executive Order to Protect Americans’ Sensitive Personal Data
- Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors
ZeroFox Intelligence Flash Report - Increased Demand for X Accounts in Dark Web Forum
A new shop with exceptionally high numbers of social media accounts for sale, which first began trading under the name fireaccs[.]biz on the dark web forum XSS on January 4, is gaining momentum amongst threat actors. On the store, X (formerly Twitter) accounts are significantly more numerous and in demand compared to other social media platforms. This is very likely indicative of their favor amongst a wide array of threat actors, given the perceived benefits of operating on X to advertise, brag, or disseminate content to a wider audience than on other platforms.
The White House Issues Executive Order to Protect Americans’ Sensitive Personal Data
The White House has issued an Executive Order to protect Americans’ sensitive personal data, including genomic data, biometric data, personal health data, geolocation data, financial data, and certain kinds of personally identifiable information from exploitation by countries of concern. The Department of Justice and Homeland Security are to work together to set high-security standards to prevent access by countries of concern to Americans’ data through other commercial means, such as data available via investment, vendor, and employment relationships.
Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors
A cyber espionage campaign targeting aerospace, aviation, and defense industries in the Middle East, including Israel and the U.A.E, has been attributed to an Iran-nexus threat actor called UNC1549. As per sources, other targets of the cyber espionage activities likely include Turkey, India, and Albania. The attacks use Microsoft Azure cloud infrastructure for command-and-control (C2) and social engineering to disseminate two backdoors, MINIBIKE and MINIBUS. The spear-phishing emails contain links to fake websites or phony job offers to deploy a malicious payload. The custom backdoors, upon establishing C2 access, act as a conduit for intelligence collection and further access into the targeted network. A tunneling software called LIGHTRAIL is also deployed to communicate with Azure cloud infrastructure.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Bogusleaker: Actor Claims to Leak Data From Texas Department of Transportation
- Telegram user WAIL_CRINAL_213: Actor Announces Cyber Attack Against UAE
VULNERABILITIES
- CVE-2024-1468: The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVE-2024-25979: The URL parameters accepted by forum search were not limited to the allowed parameters.
EXPLOITS
- CVE-2021-33544: Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33543: Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.
BREACHES
- Combolist: '19-FEB.txt' (5,787 Records): Email Address, Password
- Combolist: 'x859 netflix.txt' (819 Records): Email Address, Password
Tags: DIB, tlp:green