zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Advertised Malicious Tool Targets Gmail Accounts
  • FBI Recovers 7,000 LockBit Keys, Urges Ransomware Victims to Reach Out
  • Chinese State-Backed Cyber Espionage Targets Southeast Asian Government

ZeroFox Intelligence Flash Report - Advertised Malicious Tool Targets Gmail Accounts

Source: https://www.zerofox.com/advisories/23677/

What happened: On May 20, 2024, untested actor “Plifal” announced a new malicious tool named Plifal Software on the Russian-speaking dark web forum Exploit. The tool allegedly bypasses Google application programming interfaces (APIs) and policies, enabling threat actors to exploit session cookies and illicitly access Gmail user accounts.

Why it matters: While the advertisement offers no further detail surrounding the capabilities of Plifal Software, illicit access to an individual or business Gmail account can enable a threat actor to conduct a myriad of malicious activities. Software tools targeting widespread and diverse software solutions that are becoming increasingly prominent in the workplace are almost certainly a coveted target for threat actors seeking to gain illicit access and conduct subsequent malicious activity.

FBI Recovers 7,000 LockBit Keys, Urges Ransomware Victims to Reach Out

Source: https://www.bleepingcomputer.com/news/security/fbi-recovers-7-000-lockbit-keys-urges-ransomware-victims-to-reach-out/

What happened: The FBI has obtained over 7,000 decryption keys for LockBit ransomware and is urging past victims to come forward to recover their encrypted data for free. The development is part of the FBI’s LockBit description efforts following an international operation, "Operation Cronos," which dismantled the LockBit infrastructure in February 2024.

Why it matters: LockBit has extorted up to USD 1 billion in ransoms from over 7,000 attacks worldwide. Despite law enforcement efforts, LockBit remains active while targeting victims and leaking stolen data. The FBI's call to action and provision of decryption keys represent crucial steps in combating ransomware and assisting affected organizations in recovering their data without paying the ransom payment.

Chinese State-Backed Cyber Espionage Targets Southeast Asian Government

Source: https://thehackernews.com/2024/06/chinese-state-backed-cyber-espionage.html

What happened: A Chinese state-sponsored cyberespionage operation called Crimson Palace has been observed targeting a high-profile government organization. The threat group reportedly accessed critical IT systems, collected military and technical information, and conducted command-and-control (C2) communications in the interest of furthering state agendas.

Why it matters: China has been at odds against various Southeast Asian countries over territory disputes in the South China Sea. Additionally, the Philippines opened a new coast guard station in its northern islands near Taiwan which China claims as its own territory. The threat group’s active reconnaissance of users of critical IT infrastructure could potentially point toward China gathering intelligence of surrounding territories to further its claims on the South China Sea.

DEEP AND DARK WEB INTELLIGENCE

NoName057(16): On June 3, pro-Russian hacktivist group NoName057(16) claimed to have carried out a DDoS attack against General Dynamics European Land Systems, a Spain-based automotive and arms manufacturing company.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-5179: The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Affected products: The Cowidgets – Elementor Addons plugin versions up to, and including, 1.1.1 via the 'item_style' and 'style' parameters.

CVE-2024-5324: The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

Affected products: Login/Signup Popup plugnin versions 2.7.1 to 2.7.2.

Tags: DIB, tlp:green