ZeroFox Cyber Intelligence Daily Brief - March 1, 2024
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- #StopRansomware: Phobos Ransomware
- Biden Administration Will Investigate National Security Risks Posed by Chinese-Made “Smart Cars”
- Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
#StopRansomware: Phobos Ransomware
The FBI, CISA and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released a joint Cybersecurity Advisory (CSA) on TTPs and IOCs associated with the Phobos ransomware variants. The Phobos ransomware group has frequently targeted municipal and county governments, emergency services, education, public healthcare, and other critical infrastructure entities. CISA, FBI and MS-ISAC urges organizations to adopt mitigations to limit future Phobos ransomware attacks, through measures like securing remote access software, implementing application controls, limiting the use of RDP and other remote desktop services, and disabling command-line and scripting activities and permissions.
Biden Administration Will Investigate National Security Risks Posed by Chinese-Made “Smart Cars”
The Biden administration is opening an investigation into Chinese-made "smart cars" to protect domestic information and communications technology from national security threats. The investigation aims to prevent China from using technology in electric cars and other connected vehicles to track drivers and their personal information. U.S. officials are concerned that driver assistance technology and other features could be used to spy on Americans. To investigate the national security risks posed by "connected vehicles" from China and other countries considered hostile to the United States, the Commerce Department is issuing an advanced notice of proposed rulemaking. The department will also seek information from the auto industry and the public on the nature of the risks and potential steps to mitigate them.
Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
Lazarus recently exploited a recently patched Windows flaw (CVE-2024-21338) as a zero-day. The patched flaw was a privilege escalation flaw in the Windows Kernel and exploited by Lazarus to obtain kernel-level access and disable security software on compromised hosts. A cybersecurity vendor has identified a serious exploit used by the Lazarus Group. The exploit targets a zero-day vulnerability in a driver called appid.sys, which is part of Windows' AppLocker system. This vulnerability allows attackers to manipulate the kernel directly, enabling them to execute their rootkit called FudModule. What's particularly concerning is that this exploit leverages a driver already present on the target system, making it harder to detect and defend against.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHouse user RansomHouse: HAL Allergy Grou
- BreachForums user Ddarknotevil: Actor Claims to Leak Data From HPC Compressed Air Systems
VULNERABILITIES
- CVE-2024-21338: Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-4886: A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
BREACHES
- Combolist: 'C:\Users\123\Downloads\Goods 29.02.24 15;46.txt' (1,308 Records): Email Address, Password
- Combolist: 'x356_Minecraft.txt' (352 Records): Email Address, Password
Tags: DIB, tlp:green