ZeroFox Cyber Intelligence Daily Brief - June 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Exploit TikTok Zero-Day to Break into CNN Servers
- Data Breach at Australian Rare Earth Mining and Exploration Company
- New V3B Phishing Kit Targets Customers of 54 European Banks
Hackers Exploit TikTok Zero-Day to Break into CNN Servers
What happened: Threat actors exploited a TikTok zero-day bug to hijack high-profile accounts, including celebrities and companies, and plant malicious code on CNN’s official page. The now-patched flaw in the social media platform’s direct message feature allowed hackers to compromise accounts merely by having the target open a malicious message.
Why it matters: The White House has had TikTok on its radar recently, calling for its ban in the United States on national security grounds. In the run-up to the upcoming U.S. presidential elections, hackers are likely to conduct more such nuisance and disruptions in legitimate news sources to spread misinformation. Additionally, threat actors are likely to use information extorted from the hijacked high-profile accounts to target account holders in malicious attacks like phishing, extortion, and blackmail.
Data Breach at Australian Rare Earth Mining and Exploration Company
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/65410
What happened: On June 4, 2024, ZeroFox observed an update on the BianLian ransomware leak site targeting Northern Minerals, an Australia-based mining company focused on the development of heavy rare earths projects. The breach included operational, shareholder, financial, and employee data.
Why it matters: Recently, China’s Ministry of State Security (MSS) warned of possible threats to its rare earths industry where threat actors aimed to steal state secrets. MSS stressed that some foreign enterprises had directed their operations in China to use their commercial activities as a cover to gather intelligence and internal data on the country’s rare-earth industry chain to steal commercial secrets and national secrets. It is possible that BianLian has similar motives of selling the breached operational details, Australian and foreign projects' documents, and research and development data to foreign actors looking to reduce their dependency on other countries for rare earth materials in its semiconductors, electrical vehicles, and weapons.
New V3B Phishing Kit Targets Customers of 54 European Banks
What happened: Threat actors are advertising a new phishing kit, V3B, on Telegram, targeting customers of 54 major financial institutions across Europe. Priced between USD 130 and USD 450 per month, it boasts advanced features like obfuscation, localization, OTP/TAN/2FA support, live chat with victims, and evasion mechanisms.
Why it matters: The emergence of V3B represents a significant advancement in phishing-as-a-service (PhaaS) platforms, offering sophisticated tools to facilitate cybercrime. Phishing kits like V3B can be utilized not only to harvest banking credentials and credit card details but also to facilitate broader follow-on cyberattacks. Moreover, the real-time interaction capability via the admin panel allows for customized phishing attempts, such as obtaining one-time passwords (OTPs), enhancing the kit's effectiveness in evading detection and perpetrating cybercrime. Its ability to evade detection by anti-phishing measures heightens the risk of successful phishing attacks, potentially leading to substantial financial losses and compromised personal information.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user 303: On June 3, threat actor 303 claimed to sell unauthorized shell access belonging to Chunghwa Telecom, an Taiwan-based telecommunications company on the predominantly English-language dark web forum, “BreachForums."
VULNERABILITY AND EXPLOIT INTELLIGENCE
Zyxel vulnerabilities: Zyxel has released patches addressing command injection and remote code execution vulnerabilities in two NAS products that have reached end-of-vulnerability-support. Users are advised to install them for optimal protection.
Affected products: Versions V5.21(AAZF.16)C0 and earlier, and versions V5.21(ABAG.13)C0 and earlier
Tags: DIB, tlp:green