zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 22, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 22, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • YouTube Becomes Latest Battlefront for Phishing, Deepfakes
  • Rockwell Automation Encourages Customers to Assess and Secure Public-Internet-Exposed Assets
  • LockBit Claims to Have Stolen Data in London Drugs Ransomware Attack in April

YouTube Becomes Latest Battlefront for Phishing, Deepfakes

Source: https://www.darkreading.com/vulnerabilities-threats/youtube-becomes-latest-frontier-for-phishing-deepfakes

What happened: Cybersecurity researchers have flagged YouTube as a growing platform for malicious activities, with instances of phishing, malware distribution, and fraudulent investment schemes on the rise.

Why it matters: The exploitation of YouTube by malicious actors poses a significant threat, as the platform's immense user base makes it a prime target for spreading scams and disinformation. Researchers have highlighted Lumma stealer and RedLine for their association with these nefarious activities, indicating a concerning trend of exploitation. From compromising large accounts to utilizing deepfake technology, these tactics undermine trust and security on a widely used platform, potentially leading to financial losses and the spread of false information among users. In 2019, initial assessments from the European Commission and the EU's foreign policy and security arm revealed efforts by Russian-affiliated and other non-state actors to erode the EU's credibility via YouTube.

Rockwell Automation Encourages Customers to Assess and Secure Public-Internet-Exposed Assets

Source: https://www.cisa.gov/news-events/alerts/2024/05/21/rockwell-automation-encourages-customers-assess-and-secure-public-internet-exposed-assets

What happened: Rockwell Automation has released guidance for users to remove connectivity on all Industrial Control Systems (ICS) devices connected to the public-facing internet to reduce exposure to unauthorized or malicious cyber activity.

Why it matters: Ongoing global political events witness major cyber incidents that involve nation state threat actors as well as hacktivists. Rockwell Automation’s products are a prime target for geopolitically inclined cyberattacks considering their use in critical infrastructure. Recognizing the gravity of the threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted people about Rockwell’s advisory to generate more awareness.

LockBit Claims to Have Stolen Data in London Drugs Ransomware Attack in April

Source: https://www.bleepingcomputer.com/news/security/lockbit-says-they-stole-data-in-london-drugs-ransomware-attack/

What happened: LockBit has claimed responsibility for a ransomware attack targeting Canadian pharmacy chain London Drugs in April. ZeroFox Intelligence has observed LockBit threatening to release the extorted data after negotiations between the threat actor and the victim company allegedly failed.

Why it matters: Even though LockBit is yet to provide evidence of the files it claims to have stolen, the group has stated that the data is from London Drugs’ corporate head office, some of which may contain employee information. LockBit has been trying to regain its attack tempo after Law Enforcement (LE) took it down in February. Its recent attacks, including the one on London Drugs, are seemingly in retaliation to yet another LE operation that seized LockBit’s leak site and doxxed one of the main operators of the ransomware gang.

DEEP AND DARK WEB INTELLIGENCE

Telegram user SN_BLACKMETA: On May 20, threat actor SN_BLACKMETA claimed to have carried out a cyber attack against Israel Aerospace Industries. The threat actor announced that as part of this attack they have suspended all services, and the disruption of both external and internal networks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-29849: This vulnerability allows an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user.

Affected product: Veeam Backup Enterprise Manager

Tags: DIB, tlp:green