ZeroFox Cyber Intelligence Daily Brief - April 19, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 19, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Lengthy Indian Elections Present Cyber and Physical Threats
- Researchers Mark the Beginning of Russian Influence Campaigns Targeting U.S. Elections
- CISA and Partners Release Advisory on Akira Ransomware
ZeroFox Intelligence Brief - Lengthy Indian Elections Present Cyber and Physical Threats
India will hold a national parliamentary election from April 19 to June 1, with results expected on June 4. Prime Minister Narendra Modi is heavily favored to win a rare third term at the head of the Bharatiya Janata Party. In the cyber realm, the election has been marked by the use of online influence campaigns and generative artificial intelligence (AI) to spur support for certain candidates. High tensions between India and its major neighbors, China and Pakistan, will likely play out through online influence campaigns, election-related hacktivism, and cyber infiltration rather than through direct physical conflict. At the same time, insurgents in both the Jammu and Kashmir territory and India’s forested central belt could seek to stage small-scale attacks on electoral infrastructure.
Researchers Mark the Beginning of Russian Influence Campaigns Targeting U.S. Elections
Recent findings have revealed that Russian online campaigns targeting the upcoming U.S. presidential election have commenced, although at a slower pace than previous cycles. Researchers have highlighted Russia-linked accounts disseminating divisive content, including criticizing the United States’ support for Ukraine in its war with Russia. The most active campaign is reportedly associated with Russia's Presidential Administration. Additionally, another campaign focuses on spreading disinformation across multiple languages, often initiated by purported whistleblowers or citizen journalists on video platforms. Several media outlets and websites then amplify this content.
CISA and Partners Release Advisory on Akira Ransomware
The U.S. Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and other agencies released a joint cybersecurity advisory to disseminate known Akira ransomware indicators of compromise (IOC) and tactics, techniques and procedures (TTP). FBI investigations show that Akira ransomware has impacted a wide range of businesses and critical infrastructure entities in North America, Europe, and Australia since 2023. As of January 1, 2024, the ransomware group has impacted over 250 organizations and claimed more than USD 40 million in ransomware proceeds. The FBI, CISA, and others encourage organizations to undertake security mitigations like implementing a recovery plan, segmenting networks, and filtering network traffic to reduce the likelihood and impact of ransomware incidents.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- INC RANSOM user INC RANSOM: Delano Joint Union High School Distric
- Telegram user 66SLAVS: Actor Claims to Leak Data From National Energy Research Scientific Computing Center
VULNERABILITIES
- CVE-2024-3600: The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.
- CVE-2024-3731: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
EXPLOITS
- CVE-2023-49294: Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the
live_dangerouslyis not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue. - CVE-2023-6019: A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
BREACHES
- Combolist: 'emailsp.txt' (209,733 Records): Email Address, Password
- Combolist: 'baza_part10.txt' (19,866 Records): Email Address, Password
Tags: DIB, tlp:green