ZeroFox Cyber Intelligence Daily Brief - May 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw
- Muddling Meerkat Hackers Manipulate DNS Using China’s Great Firewall
- Hôpital de Cannes - Simone Veil in France Refuses to Pay Ransom to LockBit
Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw
Source: https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html
What happened: Cybersecurity researchers have uncovered a targeted operation aimed at Ukraine, utilizing a seven-year-old vulnerability in Microsoft Office to distribute Cobalt Strike on compromised systems. The attack begins with a PowerPoint slideshow file named signal-2023-12-20-160512.ppsx, which researchers suggest may have been shared via the Signal instant messaging app. This file is reported to be an old U.S. Army instruction manual for mine clearing blades (MCB) for tanks.
Why this matters: This vulnerability with a CVSS score of 7.8, which has been patched in 2017, enables attackers to execute arbitrary actions by tricking victims into opening a malicious file. This highlights the need for organizations/individuals to promptly patch the vulnerabilities to safeguard against evolving cyber threats and protect systems from exploitation.
Muddling Meerkat Hackers Manipulate DNS Using China’s Great Firewall
Source: https://thehackernews.com/2024/04/china-linked-muddling-meerkat-hijacks.html
What happened: Threat actor dubbed Muddling Meerkat has been manipulating domain name systems (DNS) to probe global networks. The threat actor is suspected to be a Chinese nation-state hacker whose techniques involve injecting fake responses through China's Great Firewall (GFW) after manipulating mail exchange (MX).
Why it matters: The threat actor’s ability to bypass China’s GFW and manipulate DNS has implications to the nation’s internet censorship system using sophisticated capabilities. However, a report suggests that the threat actor does not aim for disruption but for testing other networks to plan for future attacks instead.
Hôpital de Cannes - Simone Veil in France Refuses to Pay Ransom to LockBit
What happened: French hospital Hôpital de Cannes - Simone Veil (CHC-SV) has refused to pay the ransom that the LockBit 3.0 ransomware gang demanded. ZeroFox intelligence has observed an update on LockBit 3.0’s leak site targeting CHC-SV.
Why it matters: Ransomware groups have been increasingly targeting the healthcare industry, with a recent major one being the attack on Change Healthcare, where the two groups demanded ransoms from the victim company. The consequences of CHC-SV refusing to pay LockBit 3.0’s ransom demands remain unclear. After LockBit’s takedown in February, the group has been unable to conduct any majorly significant attacks.
Tags: DIB, tlp:green