zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Increased Demand for X Accounts in Dark Web Forum
  • CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure
  • LockBit Ransomware Group Resurfaces After Law Enforcement Takedown

ZeroFox Intelligence Flash Report: Increased Demand for X Accounts in Dark Web Forum

A new shop with exceptionally high numbers of social media accounts for sale, which first began trading under the name fireaccs[.]biz on the dark web forum XSS on January 4, is gaining momentum amongst threat actors. On the store, X (formerly Twitter) accounts are significantly more numerous and in demand compared to other social media platforms. This is very likely indicative of their favor amongst a wide array of threat actors, given the perceived benefits of operating on X to advertise, brag, or disseminate content to a wider audience than on other platforms.

CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure

CISA and other international cybersecurity organizations have issued a joint advisory that provides an overview of recent TTPs deployed by Russian Foreign Intelligence Service (SVR) cyber actors, also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard. In addition to outlining these TTPs used to gain initial access into the cloud environment, the advisory also includes advice to detect and mitigate such activities. The authoring agencies urged the network defenders and organizations to review the joint advisory for recommended mitigations.

LockBit Ransomware Group Resurfaces After Law Enforcement Takedown

The LockBit ransomware group, despite recent law enforcement actions seizing their servers, has reemerged on the dark web with new infrastructure. They have shifted their data leak portal to a new .onion address on the TOR network and has listed 12 new victims. The group admitted that some of their websites were seized due to a PHP vulnerability (CVE-2023-3824) which they failed to update because of negligence. Additionally, it was revealed that the server seized by authorities contained over 1,000 decryption keys, with nearly 20,000 decryptors, half of which were protected, and constituted about half of all decryptors generated since 2019.

Tags: DIB, tlp:green