zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 14, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 14, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FCC Enforcement Bureau Issues First of Its Kind C-CIST Classification for Repeat Robocall Bad Actor
  • Helsinki Education Division Suffers Data Breach
  • INC Ransomware Source Code Selling on Hacking Forums for USD 300,000

FCC Enforcement Bureau Issues First of Its Kind C-CIST Classification for Repeat Robocall Bad Actor

Source: https://docs.fcc.gov/public/attachments/DOC-402506A1.pdf

What happened: The Federal Communications Commission’s (FCC) Enforcement Bureau officially classified a group of entities and individuals as a Consumer Communications Information Services Threat (C-CIST), naming them "Royal Tiger." This designation aims to empower international partners in anti-robocall efforts by providing another means to identify known threats before they reach U.S. networks.

Why it matters: This move by the FCC represents a proactive measure to combat persistent robocall campaigns aimed at defrauding and harming consumers. By designating threat actors like Royal Tiger and providing industry stakeholders with enhanced information, the FCC aims to empower regulatory bodies to take targeted action against repeat offenders, safeguarding consumers from fraudulent activities, and potential financial losses. Additionally, this initiative fosters greater collaboration among international partners and underscores the importance of global cooperation in tackling telecom-related threats.

Helsinki Education Division Suffers Data Breach

Source: https://www.hel.fi/en/news/investigation-into-helsinki-education-division-data-breach-proceeds

What happened: The City of Helsinki is investigating a data breach affecting the Education Division. Threat actors gained access to usernames and email addresses of all city personnel, content on the division’s network drives, and personal IDs and addresses of students, guardians, and personnel from the division.

Why it matters: Even though no personally identifiable information was exposed, the volume of data involved is significant, with some of the documents containing “confidential information or sensitive personal information.” Threat actors are likely to leverage this information for further phishing attacks, scamming attempts, financial extortion, and even blackmail.

INC Ransomware Source Code Selling on Hacking Forums for USD 300,000

Source: https://www.bleepingcomputer.com/news/security/inc-ransomware-source-code-selling-on-hacking-forums-for-300-000/

What happened: A cybercriminal has announced the sale of source code of INC Ransom on hacking forums which includes both Windows and Linux/ESXi versions of INC, at a price of USD 300,000.

Why it matters: Private sales of ransomware source code, as opposed to public leaks, pose a greater threat to organizations worldwide. Without a decryptor available, these sales enable highly motivated threat actors, including newcomers and established groups, to enhance their capabilities with robust and well-tested encryption tools.

DEEP AND DARK WEB INTELLIGENCE

Threat actor group R00TK1T | On May 12, a threat actor group R00TK1T claimed a cyberattack against the Ministry of Supply and Internal Trade, Egypt. The original post can be found on the group's official Telegram channel.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-47610: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.

Affected products: Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62

Tags: DIB, tlp:green