ZeroFox Cyber Intelligence Daily Brief - May 31, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 31, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - New One-Time Purchase Ransomware Announced in Dark Web Forum
- BBC Warns Current and Former Employees of Data Breach
- Europol Seizes Over 100 Servers Worldwide in The Largest Botnet Takedown Operation
ZeroFox Intelligence Flash Report - New One-Time Purchase Ransomware Announced in Dark Web Forum
Source: https://www.zerofox.com/advisories/23643/
What happened: Well-regarded threat actor “phant0m” announced a new ransomware tool named “SpiderX” on the English-speaking dark web forum “OnniForums”. The software tool, which quickly gained traction amongst other forum users, is available for a one-time purchase of USD 150.
Why it matters: The announcement of SpiderX contributes to a broader upward trajectory in the number of both English-speaking and one-time purchase ransomware offerings observed in DDW marketplaces. While threat actors leveraging this ransomware almost certainly pose a threat to organizations across regions and industries, they are almost certainly unable to conduct attacks at the frequency or scale of larger ransomware-as-a-service (RaaS) groups.
BBC Warns Current and Former Employees of Data Breach
Source: https://www.bbc.co.uk/mypension/news/240528
What happened: BBC confirmed that it suffered a data breach where personally identifiable information (PII) of some BBC Pension Scheme members were copied. The company also confirmed that its analysts have found no evidence of misuse to the compromised files yet and that its website and its pension scheme portal remain unaffected.
Why it matters: The threat actors have compromised files that contained certain PII but not other data that could cause more “direct” harm to BBC Pension Scheme members, like financial information and passwords. The perpetrators might leverage the stolen information in possible ransom demands or other forms of follow-on attacks.
Europol Seizes Over 100 Servers Worldwide in The Largest Botnet Takedown Operation
What happened: Operation Endgame, an international law enforcement operation, has shut down malware dropper operations, including IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee, and seized over 100 servers associated with these droppers. Authorities have arrested four individuals, while eight fugitives linked to these criminal activities are to be added to Europol's Most Wanted list.
Why it matters: Operation Endgame is the largest operation targeting botnets that play a crucial role in the deployment of ransomware. For example, IcedID, initially labeled a banking trojan, has developed into a tool for aiding other cybercrimes besides financial data theft. Meanwhile, the infamous Pikabot can execute commands and inject payloads from a command-and-control server. The takedown of these malware operations is likely to curb financially motivated cybercrimes.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user StucxTeam: On May 30, pro-Palestine threat actor group StucxTeam claimed to leak a database against Pimpri-Chinchwad Municipal Corporation, India.
VULNERABILITY AND EXPLOIT INTELLIGENCE
- CVE-2024-24919: This vulnerability can potentially allow an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. CISA added this vulnerability in its KEV catalog on May 30.
Affected products: CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
- CVE-2024-1086: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.
Affected products: Linux kernel's netfilter: nf_tables.
Tags: DIB, tlp:green