ZeroFox Cyber Intelligence Daily Brief - March 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Financial Scams Circulate as U.S. Tax Season Nears End
- CISA and Partners Release Fact Sheet on PRC-Sponsored Volt Typhoon Cyber Activity
- Federal Trade Commission Warns of Scammers Pretending to Be Agency Staff
ZeroFox Intelligence Flash Report: Financial Scams Circulate as U.S. Tax Season Nears End
As the end of the U.S. tax season nears, ZeroFox Intelligence has observed an increase in tax fraud-related activity taking place in the deep and dark web (DDW). On March 9 a highly-regarded Russian-speaking threat actor known as “MagaClub” posted in DDW forum xss, claiming they are able to supply two types of illegitimate IRS tax documents—the U.S. Individual Income Tax Return (1040) and the Wage and Tax Statement (W2)—for a cost of USD 20 per form. The actor claimed to also be selling completed credit reports with scores over 700 (considered high) for USD 30 each. The tax documents and the credit reports are sold fully populated with illicitly obtained PII and use the forum’s escrow service. It is very likely that the forms sold by MagaClub are purchased primarily by malicious actors intending to file fraudulent tax returns in the name of the victim.
CISA and Partners Release Fact Sheet on PRC-Sponsored Volt Typhoon Cyber Activity
CISA, NSA, the FBI, and other U.S. government and international partners have released a fact sheet providing an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” The authoring agencies have urged leaders to empower cybersecurity teams to make informed resourcing decisions to better detect and defend against Volt Typhoon and other malicious cyber activity. The guidance lists key cybersecurity practices such as ensuring logging, including access and security, is turned on for applications and systems and logs are stored in a central system. Robust logging is necessary for detecting and mitigating living off the land. Organizations should also fortify their supply chains and have an incident response plan.
Federal Trade Commission Warns of Scammers Pretending to Be Agency Staff
The Federal Trade Commission (FTC) is warning the public about scammers pretending to be affiliated with the agency to steal consumers’ money. The agency will never ask consumers to move their money, send them to a Bitcoin ATM, demand cash withdrawals, threaten to arrest or deport them or promise a prize. Scammers may use the names of real employees, offer free money from government grants, or claim that a family member is in trouble, and needs money. It is important to learn the signs of a scam and report it immediately. FTC has released an advisory to help the public identify and avoid imposter scams, including those involving business and government impersonators.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Killnet 2.0: Actor Announces Their Own Botnet
- BreachForums user IntelBroker: Actor Claims to Leak Data From PyLC Insurance
VULNERABILITIES
- CVE-2024-2615: Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.
- CVE-2024-28303: Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.
EXPLOITS
- CVE-2021-26551: An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.
- CVE-2020-35734: Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitrary user's data (username, displayed name, etc.).
BREACHES
- Combolist: '118K .MIX COMBO MAIL ACCESS.txt' (111,745 Records): Email Address, Password
- Combolist: 'emailsp.txt' (49,610 Records): Email Address, Password
Tags: DIB, tlp:green