zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 27, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Dark Web Competition Offers Insight into Threat Actor Focus
  • Bugged Minesweeper Clones Phish Financial Organizations
  • Cencora Notifies Individuals About Data Stolen Earlier this Year

ZeroFox Intelligence Brief - Dark Web Competition Offers Insight into Threat Actor Focus

Source: https://www.zerofox.com/advisories/23610/

What happened: The results of Competition “// XSSware” on Russian-speaking dark web forum “XSS” were announced on April 16. Projects focusing on obfuscation performed well, likely indicating a demand for accessible, free obfuscation tools within the threat actor community.

Why it matters: While the direct impact is very likely limited, the competition and winning projects will likely contribute to increasing efficiency in attack vectors, particularly as the projects are free to access by members of the forum. The top three projects have predominantly been awarded due to their perceived potential rather than their immediate application—with the exception of the first place PowerShell Stealer, which allegedly boasts immediate application. It is very likely that the total prize money of USD 20,000 awarded in the course of Competition “// XSSware” will further fund threat actors in developing their malicious tools.

Bugged Minesweeper Clones Phish Financial Organizations

Source: https://www.bleepingcomputer.com/news/security/hackers-phish-finance-orgs-using-trojanized-minesweeper-clone/

What happened: Hackers are exploiting a Python clone of Microsoft's Minesweeper game to hide malicious scripts targeting financial institutions in Europe and the United States. Ukrainian cybersecurity agencies link these attacks to UAC-0188, which uses this code to install SuperOps RMM software, enabling remote access to compromised systems.

Why it matters: SuperOps RMM allows attackers direct access to sensitive financial systems, including transactional details, personal information, credit card information, and more, which can be used for spear phishing or pig butchering scams. Besides, this is not the first time threat actors have infected malicious codes in seemingly innocuous files. In a campaign researchers discovered in April, threat actor TA558 had targeted over 320 organizations globally via images infected with malicious code to deploy malware tools.

Cencora Notifies Individuals About Data Stolen Earlier this Year

Source: https://www.reuters.com/techology/cybersecurity/cencora-notifies-individuals-about-cyberattack-earlier-this-year-techcrunch-2024-05-24/

What happened: Cencora disclosed a cybersecurity incident earlier this year where data, including personal and sensitive medical information, was stolen from its information systems. The company has notified affected individuals, informing them that their protected health information, such as first names, last names, and prescription details, was compromised

Why it matters: Prolific threat actors like ALPHV (alias BlackCat, and Noberus) often target healthcare services, exfiltrating sensitive data to demand ransom. Cencora confirmed that patient data was stolen but did not observe any sale or misuse of said data at the time of writing. However, it is not clear if any ransomware has been deployed although threat actors in the past have exfiltrated data after gaining access to extort victims without deploying any ransomware. After exfiltrating data, ALPHV BlackCat affiliates reportedly communicate with victims using proxy networks, Tox, email, or encrypted applications. Once communication is established, the threat actors proceed to delete the data from the victim's system.

DEEP AND DARK WEB INTELLIGENCE

Threat actor 303 | On May 24, threat actor 303 leaked internal documents from the United States Palm Beach County government on the predominantly English-language dark web forum, “BreachForums." The threat actor did not disclose the ultimate source of the data breach or how it was exploited.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-5397: Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure.

Tags: DIB, tlp:green