zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Dark Web Competition Offers Insight into Threat Actor Focus
  • Pakistani Hackers Target Indian Critical Infrastructure
  • 1.3 TB of Data Belonging to TicketMaster for Sale on BreachForums

ZeroFox Intelligence Brief - Dark Web Competition Offers Insight into Threat Actor Focus

Source: https://www.zerofox.com/advisories/23610/

What happened: The results of Competition “// XSSware” on Russian-speaking dark web forum “XSS” were announced on April 16. Projects focusing on obfuscation performed well, likely indicating a demand for accessible, free obfuscation tools within the threat actor community.

Why it matters: While the direct impact is very likely limited, the competition and winning projects will likely contribute to increasing efficiency in attack vectors, particularly as the projects are free to access by members of the forum. The top three projects have predominantly been awarded due to their perceived potential rather than their immediate application—with the exception of the first place PowerShell Stealer, which allegedly boasts immediate application. It is very likely that the total prize money of USD 20,000 awarded in the course of Competition “// XSSware” will further fund threat actors in developing their malicious tools.

Pakistani Hackers Target Indian Critical Infrastructure

Source: https://thehackernews.com/2024/05/pakistan-linked-hackers-deploy-python.html

What happened: Cybersecurity researchers have discovered Pakistani APT group Transparent Tribe targeting the Indian government, defense, and aerospace sectors in a spear phishing campaign with cross-platform malware written in Python, Golang, and Rust.

Why it matters: Transparent Tribe is persistently targeting critical sectors vital to India's national security. The group's evolving tactics include cross-platform programming, open-source tools, and web services. Its actions and targets align with escalating India-Pakistan geopolitical tensions, suggesting a strategic motive. Threats from malicious cyber actors, such as Transparent Tribes, will likely persist and heighten amid the ongoing Indian general elections.

1.3 TB of Data Belonging to TicketMaster for Sale on BreachForums

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/65158

What happened: On May 28, ZeroFox Intelligence observed threat actor ShinyHunters selling 1.3 TB of data, allegedly belonging to Live Nation Entertainment, the owner of ticket-selling platform Ticketmaster. The BreachForums post claims that the leaked data contains information about 560 million users, including names, addresses, email IDs, phone numbers, and credit card details. The threat actor has priced the database at USD 500,000.

Why it matters: ShinyHunters was one of the two administrators of BreachForums before Law Enforcement took the dark web marketplace down last week. The alleged Ticketmaster data breach is yet another indication that BreachForums is steadily being revived. Moreover, the leaked data can expose customer data to extortion scams, spear phishing attacks, and malicious actors. Besides, Live Nation Entertainment is facing a lawsuit from the U.S. Department of Justice because of its allegedly anti-competitive business practices and "monopolistic control over the live events industry." TicketMaster is likely to lose more credibility if the investigations prove that threat actors did breach its systems to steal customer data.

Tags: DIB, tlp:green