ZeroFox Cyber Intelligence Daily Brief - March 7, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 7, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- BEC Specialized Hackers Mimic U.S. Government Entities to Steal Sensitive Information
- Duvel Moortgat Brewery Victim of Cyber Attack, All Activities Stopped
- Third-Party Breach Affects Nearly 30,000 Customers of Fidelity Investments Life Insurance
BEC Specialized Hackers Mimic U.S. Government Entities to Steal Sensitive Information
TA4903, a hacker group specializing in business email compromise (BEC) attacks, has been impersonating several U.S. government agencies to deliver files with malicious links that redirect targets to fake bidding processes. Cybersecurity researchers have observed the threat actor masquerading as the U.S. Department of Transportation, the U.S. Department of Agriculture (USDA), and other federal departments. TA4903 carries out these financially motivated attacks to reportedly steal corporate credentials, infiltrate mailboxes, and conduct follow-on business email compromise (BEC) activity.
Duvel Moortgat Brewery Victim of Cyber Attack, All Activities Stopped
Duvel Moortgat Brewery, a Belgium-based brewery, experienced a ransomware attack that caused the company to stop production immediately. Duvel has not disclosed the extent of the attack and if any data was stolen. The company is not sure when they will start production but is certain that halting production will not affect distribution.
Third-Party Breach Affects Nearly 30,000 Customers of Fidelity Investments Life Insurance
An 2023 data breach at Infosys McCamish Systems (IMS) reportedly compromised financial information of over 28,000 people associated with Fidelity Investments Life Insurance Company. Fidelity has warned customers that the compromised data might include names, Social Security numbers, states of residence, bank account and routing numbers, and dates of birth. Fidelity urges customers to remain vigilant for fraudulent activity or identity theft and has offered affected customers two years of credit-monitoring services for free. Last month, a major American bank also disclosed a breach affecting 57,000 banking customers due to a cyberattack on IMS. In November 2023, Russia-linked LockBit ransomware group reportedly claimed IMS as a victim and posted a data-sale ad—purportedly from data stolen from over 2,000 compromised IMS systems—on its darknet site.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- X (twitter) user Incognito Market: Actor Reportedly Claims to Commit Exit Scam (Incognito Market)
- Twitter user Stormous: Actor Claims to Sell Tox Denial of Service (Stormous)
EXPLOITS
- CVE-2021-31181: Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2020-24186: A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
BREACHES
- Combolist: 'netf.txt' (14,634 Records): Email Address, Password
- Combolist: '12koutlook.txt' (12,054 Records): Email Address, Password
Tags: DIB, tlp:green