zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 12, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • UK Ministry of Defence Breach Exposes Armed Forces' Data
  • Law Enforcement Agency Revealed LockBitSupp Leader’s Identity
  • Amnesty International Cites Indonesia as a Spyware Hub

UK Ministry of Defence Breach Exposes Armed Forces' Data

Source: https://www.gov.uk/government/speeches/defence-secretary-oral-statement-to-provide-a-defence-personnel-update-07-may-2024?utm_medium=email&utm_campaign=govuk-notifications-topic&utm_source=8257ab59-9aa6-4522-a85f-94c668dbca49

What happened: A recent breach in the UK's Ministry of Defence (MoD) compromised part of the Armed Forces payment network, exposing personal data of active, reserve, and retired personnel. The attack targeted an external system managed by a contractor, separate from the MoD's core network.

Why it matters: Even though the Ministry has clarified that salary payments and pensions for veterans were not affected by the attack, it has also said, “indications that this was the suspected work of a malign actor and we cannot rule out state involvement.” With 270,000 records exposed and possibilities of state involvement, the exposed information is likely to be used in future spearphishing or other cyberattacks.

Law Enforcement Agency Revealed LockBitSupp Leader’s Identity

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/63678

What happened: Law enforcement revived the LockBit leak site that it had seized with notifications hinting towards new information about the group, including the identity of the person running the ransomware operation. On May 7, it revealed the identity of the alleged leader of the ransomware group also known as “LockBitSupp.”

Why it matters: The LockBit takedown operation was a significant blow to the group responsible for approximately 30 percent of all ransomware activities in 2023. Since then, the group has been struggling to regain its foothold in the cybercrime arena. Law enforcement revealing crucial information about the group is likely to curb further disruptive activities. In the past week, LockBit has already claimed almost 60 victims, possibly in retaliation to law enforcement releasing information about the group.

Amnesty International Cites Indonesia as a Spyware Hub

Source: https://www.darkreading.com/cybersecurity-operations/amnesty-international-cites-indonesia-as-spyware-hub

What happened: Amnesty International's recent research highlights Indonesia's emergence as a hub for surveillance tools and suppliers, with evidence indicating the sale and shipment of intrusive spyware and surveillance technologies from countries like Israel, Greece, Singapore, and Malaysia to Indonesia.

Why it matters: Amnesty International has uncovered various malicious domain names and network infrastructures associated with spyware platforms targeting individuals within Indonesia. These domain names often imitate political parties and media outlets, though the specific targets remain ambiguous. Government agencies have employed spyware in the past to monitor journalists. These findings further highlight the country’s weak civil rights protection system.

Tags: DIB, tlp:green