ZeroFox Cyber Intelligence Daily Brief - April 24, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 24, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief: Ransomware Threat Landscape Continues to Diversify in 2024
- Treasury Designates Iranian Cyber Actors Targeting U.S. Companies and Government Agencies
- North Korean Hackers Target South Korean Defense Industry Entities
ZeroFox Intelligence Brief: Ransomware Threat Landscape Continues to Diversify in 2024
The frequency of ransomware and digital extortion (R&DE) attacks is on an upward trajectory, with the number of observed incidents during Q1 2024 only slightly less than that of the previous quarter, despite Q4 2023 constituting more attacks than any other quarter observed by ZeroFox. So far in 2024, the five most active collectives have been responsible for a continually-decreasing proportion of total R&DE activity. This is indicative of a growing number of highly-active threat groups, many of which are exhibiting an upward trajectory in their attack frequency. Several smaller threat groups, such as DarkVault, DragonForce, MyData, and Red, have displayed high attack tempos, which are historically atypical for newer collectives. It is very likely that such groups are benefitting from the acquisition of experienced affiliates from LockBit and ALPHV. It is likely that the R&DE threat landscape will continue to diversify during the coming months, with an increasing number of threat collectives conducting a growing proportion of total activity.
Treasury Designates Iranian Cyber Actors Targeting U.S. Companies and Government Agencies
The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned two companies and four individuals linked to cyber attacks carried out on behalf of the Iranian Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC). These actors targeted numerous U.S. entities through tactics like spear phishing and malware. The U.S. Justice Department and FBI are unsealing indictments against the four individuals. The IRGC-CEC operates through front companies like Mehrsam Andisheh Saz Nik, concealing its involvement. The sanctions have frozen all U.S.-based assets and interests associated with the designated individuals and entities. OFAC has further stated that it has issued these sanctions “not to punish, but to bring about a positive change in behavior.”
North Korean Hackers Target South Korean Defense Industry Entities
South Korea's National Police Agency has issued a warning stating North Korean hackers are increasingly targeting the nation's defense industry. Notorious North Korean hacking groups Lazarus, Andariel, and Kimsuky have been associated with successful breaches, exploiting vulnerabilities in both primary companies and their subcontractors. These infiltrations, dating back to late 2022, went unnoticed until a recent investigation. Lazarus targeted network connection systems, Andariel seized employee account data for malware installation, while Kimsuky exploited email server weaknesses. The police advise security measures including network segmentation, regular password changes, two-factor authentication, and IP blocking.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user USDoD: Actor Claims to Leak Data From Bureau van Dijk and US Consumer
- BreachForums user IntelBroker: Actor Claims to Leak Source Code for BTC Cash
VULNERABILITIES
- CVE-2024-31032: An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.
- CVE-2024-31081: A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function.
BREACHES
- Combolist: '100k Outlook Mix Uhq.txt' (88,292 Records): Email Address, Password
- Combolist: '6k Edu Target Combolist.txt' (5,944 Records): Email Address, Password
Tags: DIB, tlp:green