zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 17, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 17, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Access to U.S. Web Hosting Organization Advertised in Deep and Dark Web Forum
  • U.S. FTC Fines Cerebral USD 7 Million for Breach of User Privacy
  • LockBit Strikes Unidentified Organization in West Africa With a New Variant

ZeroFox Intelligence Flash Report - Access to U.S. Web Hosting Organization Advertised in Deep and Dark Web Forum

On April 8, 2024, untested threat actor “synthetic” posted in deep and dark web (DDW) platform RAMP advertising access to a U.S.-based web hosting organization. Threat actor synthetic claims that the buyer will receive administrative access to all hosted web pages, which could number in the hundreds of thousands and belong to hundreds to thousands of separate organizations. The asking price for the initial access was USD 80,000, which is significantly higher than the typical price tag for initial access to an organizational network. This is almost certainly due to the notably high potential financial return for the successful exploitation of such significant access. synthetic is not an active user in RAMP, but the advertisement indicates that sales will take place using the forums escrow service—significantly increasing the credibility of both the sale and the actor.

U.S. FTC Fines Cerebral USD 7 Million for Breach of User Privacy

The U.S. Federal Trade Commission (FTC) announced the mental telehealth company Cerebral to stop using or disclosing personal medical data for advertising purposes. Cerebral has been fined over USD 7 million for reportedly sharing users' sensitive health information and other data with third parties for advertising without consent, and for failing to uphold its easy cancellation policies. The FTC accuses Cerebral of deceptive practices, including burying its data-sharing practices in dense privacy policies and falsely claiming not to share user data without consent.

LockBit Strikes Unidentified Organization in West Africa With a New Variant

According to researchers, LockBit has targeted an unidentified organization in West Africa with a sophisticated attack leveraging a new variant of the LockBit 3.0 builder. Under the disguise of a system administrator, threat actors infect several victim systems with the LockBit 3.0 builder variant. This new variant can generate custom, self-propagating ransomware to disable defense software on target systems, encrypt network shares, and bypass detection by deleting Windows Event Logs. The malware strain can also orchestrate attacks on select systems and corrupt documents or spreadsheets.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-2955: T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
  • CVE-2024-26134: cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format.

BREACHES

Tags: DIB, tlp:green