ZeroFox Cyber Intelligence Daily Brief - April 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Temporary BreachForums Disruption Claimed by Hacking Group
- Kapeka Backdoor Spotted in Eastern Europe
- Threat Actor Claims to Leak Data From Ministry of Defense Israel in Dark Web
ZeroFox Intelligence Flash Report - Temporary BreachForums Disruption Claimed by Hacking Group
On April 15, 2024, threat actor “R00TK1T”—in alleged coordination with the “CyberArmyofRussia”—claimed to have taken down BreachForums’ surface web domain. R00TK1T also alluded that it would imminently publish information related to the forum’s users. R00TK1T’s involvement was quickly disputed by “Baphomet,” BreachForum’s moderator, who instead blamed “the five eyes network, and various other large nations.” Baphomet also announced the resumption of the forum on a new [.]st top level domain (TLD). As of the time of writing, this site is fully functional. BreachForum’s short downtime and R00TK1T’s failure to publish subsequent information as had been threatened indicates there is an unlikely chance R00TK1T was involved. There is a roughly even chance that the events were initiated by law enforcement (LE) entities as Baphomet claimed. Prior to the disruption, a well-regarded threat actor advertised a data breach composed of allegedly sensitive information, which had a high chance of spurring LE scrutiny.
Kapeka Backdoor Spotted in Eastern Europe
Kapeka backdoor, a previously undocumented malware strain linked to Russian threat group Sandworm, is targeting East European Countries including Estonia and Ukraine. Kapeka is a flexible backdoor that can be deployed for early-stage reconnaissance and long-term access to compromised systems. Kapeka is reported to use a dropper that installs and activates a backdoor on the victim's machine before removing itself. The backdoor then gathers information about the system and user, sending this data to the threat actor for further actions or updates to the backdoor's configuration.
Threat Actor Claims to Leak Data From Ministry of Defense Israel in Dark Web
Threat actor APExploits claimed to have leaked a database associated with the Ministry of Defense Israel on the dark web forum “BreachForums." The threat actor claimed to have breached the data in January 2023. Information such as date of birth, email addresses, genders, groups, status gender data, phone numbers, names, projects, and more were leaked. Meanwhile, Israeli Defense Forces are preparing for cyberattacks against Iran in response to April 14 aerial drone and missile attack.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RAMP user ghost_rider: Network access to Israeli Ministry of Foreign Affairs
- RAMP user ghost_rider: Data breach impacting Israeli Mossad mail server
VULNERABILITIES
- CVE-2024-31497: In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures.
- CVE-2024-24680: An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
EXPLOITS
- CVE-2021-36393: In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
- CVE-2024-23897: Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
BREACHES
- Combolist: '100k Food UhQ (2).txt' (95,811 Records): Email Address, Password
- Combolist: '100k Combo Twitter Good (1).txt' (93,077 Records): Email Address, Password
Tags: DIB, tlp:green