ZeroFox Cyber Intelligence Daily Brief - May 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - NATO Data Leak Shared on Deep Web Forum
- Chinese Espionage Group Targets Africa & Caribbean Govts
- Google Fixes Eighth Actively Exploited Chrome Zero-Day this Year
ZeroFox Intelligence Flash Report - NATO Data Leak Shared on Deep Web Forum
Source: https://cloud.zerofox.com/intelligence/advisories/23605
What happened: On May 19, threat actor “Sumo” announced a data leak pertaining to a NATO school’s e-learning platform on the Russian-speaking deep web forum Cronos.
Why it matters: It is likely that the data breach originated from an SQL injection vulnerability that was privately advertised for sale on Telegram in January 2024. The vulnerability allegedly implicated an unknown NATO entity. It is very likely that the intended use of this data is social engineering and other fraudulent activity, with a likely chance it has already been leveraged in attacks by financially-motivated threat actors.
Chinese Espionage Group Targets Africa & Caribbean Govts
Source: https://thehackernews.com/2024/05/new-frontiers-old-tactics-chinese-cyber.html
What happened: China linked cyber espionage threat actor Sharp Panda now being tracked as Sharp Dragon is now targeting Africa and Caribbean government agencies as well. Sharp Dragon is reportedly delivering the Soul modular malware framework which begins with the deployment of the SoulSearcher loader responsible for downloading, decrypting, and executing the Soul backdoor and its other components. This attack method allows the espionage group to gather more information.
Why it matters: According to reports, Sharp Dragon has so far confined their cyberespionage campaigns to South Asia, but recently it has upgraded their tactics, techniques, and procedures (TTPs) to gather sensitive data from government agencies and organizations in other countries. China threat actors broadening their attack surface and methodologies shows that they are expanding their cyberespionage campaign globally.
Google Fixes Eighth Actively Exploited Chrome Zero-Day this Year
What happened: Google recently issued an emergency security update about the eighth zero-day vulnerability,CVE-2024-5274, detected in its Chrome browser and has been confirmed to be actively exploited in the wild. Google has decided to retain certain information about this vulnerability till a majority of users implement the patch.
Why it matters: Google Chrome has over two billion users worldwide exposing many users to exploitation. Users are especially vulnerable as Google has acknowledged four zero-day vulnerabilities in May. Zero-day vulnerabilities are particularly concerning because they pose an immediate threat to users' security and can lead to successful attacks on victims without any prior warning or time for mitigation.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums New Site: On May 24, ZeroFox observed an update on telegram channel Jacuzzi 2.0 announcing a new onion site for BreachForums. Initially, users were unable to create accounts, while old "personas" (credentials) were not being recognized. However, at the time of reporting, the site seems to be letting in users with correct credentials.
Tags: DIB, tlp:green