ZeroFox Cyber Intelligence Daily Brief - April 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 26, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - New Ransomware-as-a-Service Operation Claims Innovative Features
- FBI Issues Warning Against Unregistered Cryptocurrency Money Transmitting Services
- North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures
ZeroFox Intelligence Flash Report - New Ransomware-as-a-Service Operation Claims Innovative Features
On April 19, positive-reputation threat actor “Bezzle” announced a new ransomware-as-a-service (RaaS) operation named “Apos” in the Russian-speaking deep and dark (DDW) community RAMP. Bezzle proclaims Apos is the “fastest” and “most technically advanced” product on the market. Apos purportedly has many software features typically only observed amongst the more advanced RaaS offerings. The service also includes highly uncommon capabilities, which is very likely indicative of an attempt to separate the Apos service from its competition and appeal to potential affiliates. RaaS offerings are very likely to become increasingly competitive during 2024, with collectives offering affiliates more software features, better technical support and digital infrastructure, higher payouts, and loyalty incentives.
FBI Issues Warning Against Unregistered Cryptocurrency Money Transmitting Services
The FBI has warned Americans against using cryptocurrency money transmitting services that are not registered as Money Services Businesses (MSB) according to U.S. federal law and do not adhere to anti-money laundering requirements. This announcement comes after the U.S. Department of Justice charged the founders of Samourai Cryptomixer for laundering over USD 100 million from criminal enterprises. The FBI has advised users to verify the registration of a money-transmitting service with FinCEN, be wary of services not requesting KYC information, avoid services promoting illegal activities, and verify the service’s legality despite their presence on the app store.
North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures
The Lazarus Group has been using fake job offers as bait to distribute a new remote access trojan called Kaolin RAT in a campaign known as Operation Dream Job. This campaign has been ongoing for some time and involves the use of social media and instant messaging platforms to deliver malware. The Kaolin RAT not only functions as a standard RAT but also has the ability to alter file timestamps and load DLL binaries from a command-and-control server. The Lazarus Group employs advanced techniques to ensure persistence and evade detection by security software.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user UserSec: Actor Claims Preparing Goals For New Cyber Attack Campaign
- BreachForums user 888: Actor Claims to Leak Data From El Carnicero
VULNERABILITIES
- CVE-2024-31755: cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
- CVE-2023-47252: An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering.
EXPLOITS
- CVE-2024-28741: Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.
- CVE-2024-27612: Numbas editor before 7.3 mishandles editing of themes and extensions.
BREACHES
- Combolist: '120k Fresh HQ Combolist Email-Pass [Netflix,Minecraft,Uplay,Steam,Hulu,spotify].txt' (119,959 Records): Email Address, Password
- Combolist: 'PREMIUM Accounts.txt' (527 Records): Email Address, Password
Tags: DIB, tlp:green