zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • BreachForums Marketplace Seized By Law Enforcement
  • Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions
  • DOJ Indictment Charges Two Brothers For Stealing USD 25 Million in Ethereum Blockchain Attack

BreachForums Marketplace Seized By Law Enforcement

Source: https://www.zerofox.com/advisories/23547/

What happened: On May 15, 2024, the popular English-language deep and dark web (DDW) forum BreachForums was seized by law enforcement agencies in an operation likely coordinated by multiple international law enforcement agencies.

Why this matters: Since mid-2023, BreachForums has been one of the most popular DDW marketplaces hosting discussions surrounding malicious network access and exploitation, as well as the trading of associated goods such as personally identifying information and personal financial information. ZeroFox can neither independently confirm nor deny that a spate of recent posts on the forum advertising the sale of highly sensitive information initiated the law enforcement activity. ZeroFox notes the possibility that the law enforcement operation is ongoing, with the potential for further disruption to occur.

Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions

Source: https://thehackernews.com/2024/05/turla-group-deploys-lunarweb-and.html

What happened: Cyberespionage group Turla is likely behind the LunarWeb and LunarMail backdoors that targeted a European ministry of foreign affairs and its diplomatic missions. Reportedly, the attacker had network access, used stolen credentials, and compromised the server without raising alarms.

Why it matters: Recent Russian cyber operations in Europe have heightened diplomatic tensions, leading to significant diplomatic actions. Germany temporarily recalled its ambassador from Russia due to accusations of cyberattacks targeting critical infrastructure and a major political party. Similarly, the United Kingdom and Czechia summoned their Russian ambassadors to address concerns regarding alleged cyber activities and suspected espionage operations.

DOJ Indictment Charges Two Brothers For Stealing USD 25 Million in Ethereum Blockchain Attack

Source: https://www.coindesk.com/policy/2024/05/15/brothers-accused-of-25m-ethereum-exploit-as-us-reveals-fraud-charges/#:~:text=Two%20brothers%20have%20been%20arrested,an%20indictment%20unsealed%20on%20Wednesday

What happened: The U.S. Department of Justice (DOJ) has arrested two brothers for attacking the Ethereum blockchain and stealing USD 25 million of cryptocurrency. In an indictment released on May 15, the DOJ has charged them with conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

Why it matters: The charges are a first-of-its-kind criminal action from the DOJ associated with the controversial practice of Maximal Extractable Value (MEV), where operators of blockchains—including Ethereum—preview imminent user transactions to earn extra profits. The brothers leveraged a flaw in MEV-boost, the MEV software used by several validators running the Ethereum blockchain. This attests to the statement in the indictment that the presence of MEV in Ethereum’s infrastructure makes the blockchain vulnerable.

DEEP AND DARK WEB INTELLIGENCE

Threat actor group Cyber Army Russia Reborn | On May 15, a pro-Russia threat actor group Cyber Army Russia Reborn conducted a DDoS attack against the European Conference of Postal and Telecommunications Administrations, Denmark.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-4947: CVE-2024-4947 is a type confusion flaw in the V8 JavaScript and WebAssembly engine that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Google is aware that an exploit for CVE-2024-4947 exists in the wild.

Affected products: Google Chrome versions prior to 125.0.6422.60.

Tags: DIB, tlp:green