ZeroFox Cyber Intelligence Daily Brief - May 19, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 19, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- BreachForums Marketplace Seized By Law Enforcement
- FCC Enforcement Bureau Issues First of Its Kind C-CIST Classification for Repeat Robocall Bad Actor
- CISA and Partners Release Advisory on Black Basta Ransomware
BreachForums Marketplace Seized By Law Enforcement
Source: https://www.zerofox.com/advisories/23547/
What happened: On May 15, 2024, the popular English-language deep and dark web (DDW) forum BreachForums was seized by law enforcement agencies in an operation likely coordinated by multiple international law enforcement agencies.
Why it matters: Since mid-2023, BreachForums has been one of the most popular DDW marketplaces hosting discussions surrounding malicious network access and exploitation, as well as the trading of associated goods such as personally identifying information and personal financial information. ZeroFox can neither independently confirm nor deny that a spate of recent posts on the forum advertising the sale of highly sensitive information initiated the law enforcement activity. ZeroFox notes the possibility that the law enforcement operation is ongoing, with the potential for further disruption to occur.
FCC Enforcement Bureau Issues First of Its Kind C-CIST Classification for Repeat Robocall Bad Actor
Source: https://docs.fcc.gov/public/attachments/DOC-402506A1.pdf
What happened: The Federal Communications Commission’s (FCC) Enforcement Bureau officially classified a group of entities and individuals as a Consumer Communications Information Services Threat (C-CIST), naming them "Royal Tiger." This designation aims to empower international partners in anti-robocall efforts by providing another means to identify known threats before they reach U.S. networks.
Why it matters: This move by the FCC represents a proactive measure to combat persistent robocall campaigns aimed at defrauding and harming consumers. By designating threat actors like Royal Tiger and providing industry stakeholders with enhanced information, the FCC aims to empower regulatory bodies to take targeted action against repeat offenders, safeguarding consumers from fraudulent activities, and potential financial losses. Additionally, this initiative fosters greater collaboration among international partners and underscores the importance of global cooperation in tackling telecom-related threats.
CISA and Partners Release Advisory on Black Basta Ransomware
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
What happened: A joint cybersecurity advisory on BlackBasta provides organizations tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified through FBI investigations and third-party reporting.
Why it matters: Black Basta ransomware variant actors have encrypted and stolen data from at least 12 out of 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) Sector. Black Basta affiliates have impacted a wide range of businesses and critical infrastructure in North America, Europe, and Australia. As of May 2024, Black Basta affiliates have impacted over 500 organizations globally.
Tags: DIB, tlp:green