zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 17, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 17, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - LockBit Update: What Comes Next for the Extortion Collective?
  • MediSecure Data Breach: Cyber Security Chief Says No Current Prescriptions Affected
  • Kimsuky Group Delivers Malware via Facebook in New Social Engineering Campaign

ZeroFox Intelligence Brief - LockBit Update: What Comes Next for the Extortion Collective?

Source: https://www.zerofox.com/advisories/23544/

What happened: Increased pressure on LockBit’s leadership following recent law enforcement (LE) activity is likely to make the extortion operation more volatile and unpredictable in the short term and may have negative consequences for extortion victims.

Why it matters: LockBit’s inability to maintain stable infrastructure will likely be perceived by many threat actors as evidence that LockBit’s operation is on a declining trajectory and is indicative of its leadership focusing on brand restoration rather than operational efficacy. Should barriers persist and hinder LockBit’s ability to restore its reputation—as well as continued degradation in operational output—the likelihood that leadership will seek to close down LockBit’s operation will increase. R&DE operations of this nature have a history of ceasing activity via exit scams conducted by the operations’ leadership teams.

MediSecure Data Breach: Cyber Security Chief Says No Current Prescriptions Affected

Source: https://www.theguardian.com/australia-news/article/2024/may/17/medisecure-data-breach-australia-healthcare-prescriptions-impact

What happened: MediSecure shut down its operations due to a ransomware attack originating from a third-party vendor. Personal and health information of individuals has been compromised, with the extent of the breach still unclear. The Australian Federal Police is investigating the incident.

Why it matters: The MediSecure cyberattack underscores the critical importance of cybersecurity in safeguarding personal and health information, particularly within the healthcare sector. With the increasing frequency of ransomware attacks and data breaches targeting healthcare organizations, this breach highlights systemic vulnerabilities that could compromise patient privacy and care quality, potentially endanger lives by impeding access to critical health information and causing systemic disruptions in medical services.

Kimsuky Group Delivers Malware via Facebook in New Social Engineering Campaign

Source: https://thehackernews.com/2024/05/north-korean-hackers-exploit-facebook.html

What happened: Threat researchers have attributed North Korean state-backed Kimsuky hackers to a new social engineering campaign using fake Facebook accounts to deliver malware via Messenger. Disguised as North Korean human rights officials, the group reportedly targets activists in anti-North Korea and human rights fields.

Why it matters: Kimsuky is known for constantly upgrading its techniques and cyber-armory to conduct cyberattacks with great stealth and precision. In its latest campaign, the threat group departed from the typical email-based methods instead of using Facebook Messenger, seemingly targeting entities in South Korea and Japan. Besides, the nature of the targets in the campaign reflects the political motivations of the North Korean government. In 2023, Kimsuky was also associated with an intelligence gathering operation, where it targeted think tanks, academia, the media, and experts on North Korean affairs.

DEEP AND DARK WEB INTELLIGENCE

Threat Actor GhostSec: Threat actor group GhostSec, previously involved in financially motivated cybercrimes, announced its departure from the cybercrime and ransomware scene and has returned to its original focus on hacktivism.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-20326: A vulnerability in the ConfD CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.

Affected product: ConfD software

Tags: DIB, tlp:green