zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - First Potential BreachForums Successor Announced
  • Threat Actor Claims to Leak A Criminal Database from the United States
  • Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

ZeroFox Intelligence Flash Report - First Potential BreachForums Successor Announced

Source: https://www.zerofox.com/advisories/23575/

What happened: On May 16, threat actor “USDoD” announced on X (formerly Twitter) their intent to launch a new, open-source data breach forum named Breach Nation.

Why it matters: USDoD stated their intent for Breach Nation to serve as a successor to BreachForums, which was severely disrupted on May 15, by a law enforcement (LE) operation that seized the forum’s [.]st domain, a [.]onion domain, and a Telegram channel. There is a roughly even chance that Breach Nation will become a popular tool for threat actors seeking to discuss techniques, tactics, and procedures (TTPs) related to data breach attacks, publicize results, and sell stolen information. It is likely that, in the coming months, other BreachForums members, moderators, and staff will seek to capitalize upon its disruption by creating and advertising new forums.

Threat Actor Claims to Leak A Criminal Database from the United States

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/64700

What happened: Threat actor USDoD from BreachForum claimed to have leaked a criminal database from the United States with 70 million rows on the predominantly English-language dark web forum, “LeakBase." The database reportedly has information recorded from 2020 to 2024.

Why it matters: The leaked database includes fields like first name, last name, middle name, generation, date of birth, birth state, address, and military services. The exposed sensitive details can be leveraged for targeting individuals in spear phishing attacks, extortion schemes, and blackmail, leading to severe consequences like reputational damage, financial losses, and legal implications.

Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

Source: https://thehackernews.com/2024/05/iranian-mois-linked-hackers-behind.html

What happened: Iran-based threat actor reportedly from the Ministry of Intelligence and Security (MOIS) engaged in wiping attacks against Albania and Israel. The attacks are being tracked under the title “Void Manticore.”

Why it matters: The threat actor has been launching disruptive cyberattacks against Albania since July 2022 using wiper malware such as Cl Wiper and No-Justice (aka LowEraser). After gaining an initial foothold, they deploy web shells, including a customized one called Karma Shell. Karma Shell masquerades as an error page but has capabilities to enumerate directories, create processes, upload files, and manage services. This sophisticated approach underscores the significant threat posed by state-sponsored or politically motivated cyber actors.

DEEP AND DARK WEB INTELLIGENCE

  • Incognito market owner: The owner of "Incognito Market," one of the internet's largest illegal narcotics platforms, has been arrested after enabling global anonymous drug transactions. The individual was arrested at John F. Kennedy Airport on May 18.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-4323: A critical memory corruption vulnerability in Fluent Bit that may result in denial of service conditions, information disclosure, or remote code execution (RCE).

Affected products: Fluent Bit Versions 2.0.7 Through 3.0.3.

  • CVE-2024-27130: A critical vulnerability, CVE-2024-27130, in QNAP devices allows remote code execution due to unsafe 'strcpy' use in the No_Support_ACL function. Exploitation requires a crafted 'name' parameter and a valid 'ssid' from file sharing. This flaw affects media sharing via the share.cgi script. Researchers have unveiled a proof of concept (PoC) exploit for CVE-2024-27130 recently.

Affected products: QNAP QTS

Tags: DIB, tlp:green