ZeroFox Cyber Intelligence Daily Brief - March 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: LockBit and ALPHV Activity Likely Consistent with Exit Scams
- North Korean Hackers Target South Korean Semiconductor Firms Using LoTL Tactics
- Additional Critical Security Issues Affecting TeamCity On-Premises
ZeroFox Intelligence Flash Report: LockBit and ALPHV Activity Likely Consistent with Exit Scams
Operators behind both the LockBit and ALPHV ransomware and digital extortion (R&DE) operations are exhibiting behavior likely consistent with imminent exit scams against their affiliates, at the time of writing. Both operations have claimed to be continuing operations following recent law enforcement (LE) activities, consistently downplaying the impact of disruptive action despite a significant reduction in observed activity. While ZeroFox can neither confirm nor deny the veracity of claims of scamming made by alleged LockBit and ALPHV affiliates, similar activity has been conducted by other notable ransomware collectives in the days preceding the cessation of their operations. Victims of outstanding or ongoing extortion attacks by LockBit and ALPHV are unlikely able to assume their stolen data will be deleted following payment of ransom demands. Regardless of whether they choose to pay ransom demands, victims are at an increased risk of stolen data not being deleted and, instead, sold on the deep and dark web (DDW) to the highest bidders.
North Korean Hackers Target South Korean Semiconductor Firms Using LoTL Tactics
The National Intelligence Service (NIS) of South Korea has issued a press release highlighting its discovery of North Korean hackers targeting domestic semiconductor firms from the second half of 2023 till recently. The press release talks about two cyberattacks in December 2023 and February 2024, targeting two companies that had their configuration management server and security policy server hacked, respectively. The attackers also stole product design drawings and facility site photos. NIS has urged all related industries to be wary of such attacks. It believes North Korea is manufacturing its own semiconductor devices after sanctions against the country made it difficult to procure chips.
Additional Critical Security Issues Affecting TeamCity On-Premises
Newly discovered vulnerabilities (CVE-2024-27198 and CVE-2024-27199) in JetBrains TeamCity On-Premises software can potentially allow threat actors to bypass authentication checks and gain administrative control of the server. JetBrains confirms in their advisory that no one has been attacked and that these vulnerabilities have been fixed in version 2023.11.4. The company also lists mitigations that can help users patch their environment if they are unable to update their servers. In its notice, JetBrains confirms that none of their customers were attacked.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user govhunter: Actor Claims Data Breach Against the Mr. Green Gaming
- Telegram user Team_r70: Actor Claims Web Defacement Attack Against Cyber Recycling Company, Australia
VULNERABILITIES
- CVE-2024-21838: Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre.
- CVE-2024-21815: Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users.
EXPLOITS
- CVE-2021-31762: Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
- CVE-2021-25158: A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
BREACHES
- Combolist: 'results-fuckintelxfreebot.txt' (123,783 Records): Email Address, Password
- Combolist: 'message-999.txt' (250,202 Records): Email Address, Password
Tags: DIB, tlp:green