zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Treasury Sanctions Individuals Behind Infamous 911 S5 Botnet
  • Russian Indicted for Selling Access to U.S. Corporate Networks
  • BreachForums Returns Just Weeks After FBI-Led Takedown

U.S. Treasury Sanctions Individuals Behind Infamous 911 S5 Botnet

Source: https://home.treasury.gov/news/press-releases/jy2375

What happened: The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned three individuals and three Thai companies for their association with the malicious botnet tied to the residential proxy service known as 911 S5.

Why it matters: The 911 S5 botnet compromised 19 million computers, enabling fraudsters to steal billions from the U.S. COVID-19 relief funds through thousands of counterfeit applications. Some of the IP addresses the botnet compromised were also involved in a series of bomb threats through the United States in April 2022. Additionally, cybercriminals used the 911 S5 botnet to disguise their digital activities, to make it seem like the crimes originated from the victim’s computer instead of their own. This tactic effectively shifted blame and hindered law enforcement efforts.

Russian Indicted for Selling Access to U.S. Corporate Networks

Source: https://www.bleepingcomputer.com/news/security/russian-indicted-for-selling-access-to-us-corporate-networks/

What happened: A Russian national, operating under aliases "FlankerWWH" and "Flanker," has been indicted in the United States for wire and computer fraud. The indicted individual allegedly acted as an initial access broker (IAB), breaching corporate networks and selling access on Russian-language cybercrime forums. The threat actor was known for using brute-forcing tactics exposed Remote Desktop Protocol (RDP) services.

Why it matters: The indictment of the Russian national highlights the pervasive threat of IABs in cybercrime ecosystems. By selling network access, these actors enable other threat actors to conduct various malicious activities, such as data theft or ransomware attacks, and facilitate a marketplace for cybercriminals to exploit vulnerabilities. This amplifies the scale and complexity of cyber threats, as multiple actors can exploit compromised networks, causing significant financial and reputational damage to targeted organizations.

BreachForums Returns Just Weeks After FBI-Led Takedown

Source: https://www.theregister.com/2024/05/28/breachforums_back_online/

What happened: BreachForums makes its reappearance on the clearweb after law enforcement took its dark web presence down. ZeroFox observed that BreachForums is now operational on the clearnet with a new URL (breachforums[.]st).

Why it matters: After the takedown of BreachForums in the dark web, experts reported the possibility of unidentified backup servers and domains that can be accessed. There might also be previously unidentified individuals with administrative or technical access who can resume operations after any seizure or takedown. Takedowns of this scale cause major operational hurdles to underground cyber crimes, which is likely to deter further disruptive activities for a short while. Although law enforcement activities are effective in the short-term, the current BreachForums takedown does not guarantee any permanent seizure as seen in 2022.

DEEP AND DARK WEB INTELLIGENCE

Hacktivist group Indonesian Anon Black Flag | Hacktivist group Indonesian Anon Black Flag announced attack against entities in India, under its ongoing operation #OpIndia. The group claims the motive of the attack to be PM Narendra Modi’s speech that allegedly terms Indian Muslims “infiltrators” and to cause disruption in India elections.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-23108: An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM allows an attacker to execute unauthorized code or commands via crafted API requests.

Affected products: Fortinet FortiSIEM version 7.1.0 through 7.1.1; 7.0.0 through 7.0.2; 6.7.0 through 6.7.8; 6.6.0 through 6.6.3; 6.5.0 through 6.5.2; 6.4.0 through 6.4.2.

CVE-2024-5433: The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression can lead to a path traversal vulnerability. This command combined with a specially crafted expression allows anonymous, unauthenticated access (allowed by default) by an attacker to files and directories outside of the webserver root directory they should be restricted to.

Affected products: Campbell Scientific CSI Web Server Versions 1.6 and prior; RTMC Pro Version 5.0 and prior.

Tags: DIB, tlp:green