ZeroFox Cyber Intelligence Daily Brief - May 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Free Piano Phish Targets American University Students, Staff
- 1.3 TB of Data Belonging to Ticketmaster for Sale on BreachForums
- Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package
Free Piano Phish Targets American University Students, Staff
What happened: A large-scale phishing campaign entices recipients with a promise of a free Yamaha baby grand piano, targeting mainly North American university students and faculty, as well as healthcare and food and beverage service providers, amassing over USD 900,000 through fraudulent shipping fees.
Why it matters: The phishing scheme preys on recipients' trust with a seemingly generous offer of a free Yamaha baby grand piano, exploiting urgency and legitimacy to convince victims to pay substantial shipping fees via non-traceable methods. This phishing campaign's success highlights the effectiveness of leveraging unusual lures to deceive recipients and extract significant sums of money. Phishing emails can further target individuals by exploiting their trust in seemingly legitimate sources. This can impact individuals by deceiving them into providing personal information or making financial transactions, leading to identity theft, financial loss, and compromised cybersecurity.
1.3 TB of Data Belonging to Ticketmaster for Sale on BreachForums
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/65158
What happened: On May 28, ZeroFox Intelligence observed threat actor ShinyHunters selling 1.3 TB of data, allegedly belonging to Live Nation Entertainment, the owner of ticket-selling platform Ticketmaster. The BreachForums post claims that the leaked data contains information about 560 million users, including names, addresses, email IDs, phone numbers, and credit card details. The threat actor has priced the database at USD 500,000.
Why it matters: ShinyHunters was one of the two administrators of BreachForums before law enforcement took the dark web marketplace down last week. The alleged Ticketmaster data breach is yet another indication that BreachForums is steadily being revived. Moreover, the leaked data can expose customer data to extortion scams, spear phishing attacks, and malicious actors. Besides, Live Nation Entertainment is facing a lawsuit from the U.S. Department of Justice because of its allegedly anti-competitive business practices and "monopolistic control over the live events industry." TicketMaster is likely to lose more credibility if the investigations prove that threat actors did breach its systems to steal customer data.
Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package
Source: https://thehackernews.com/2024/05/cybercriminals-abuse-stackoverflow-to.html
What happened: Threat actors are sharing a malicious Python package called “pytoileur” in the Python Package Index (PyPI) and propagating it via the Stack Overflow platform. This would allow threat actors to deploy additional payloads and establish persistence on victim devices.
Why it matters: This malicious code is being distributed on the Stack Overflow platform, where novice developers are particularly susceptible to potential global cybercampaigns. Threat actors can potentially steal data from web browsers and carry out cryptocurrency thefts, compromising several targets at one go.
DEEP AND DARK WEB INTELLIGENCE
Telegram user SN_BLACKMETA: On May 28, threat actor group SN_BLACKMETA conducted a distributed denial of service (DDoS) attack against The Internet Archive, a website used for browsing historical web pages, digitized books, music, movies, software, and academic papers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-2452: In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.
Affected products: Eclipse ThreadX NetX Duo before versions 6.4.0.
Tags: DIB, tlp:green