ZeroFox Cyber Intelligence Daily Brief - June 7, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 7, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- "Vermin” Attacks the Defense Forces of Ukraine
- Los Angeles Unified School District Investigates Data Theft Claims
- U.S. Government Attempts to Recover a Trade Union’s Funds Stolen Via Business Email Compromise
“Vermin” Attacks the Defense Forces of Ukraine
Source: https://cert.gov.ua/article/6279600
What happened: Threat actor group “Vermin” was observed targeting Ukraine’s defense forces according to the country’s Computer Emergency Response Team (CERT-UAP) and Cyber Security Center of the Armed Forces of Ukraine (CCB). The threat group reportedly deployed the SPECTR malware to steal data.
Why it matters: Authorities suspect that the Vermin threat group is from temporary Russia occupied Luhansk and was last seen in 2022. The suspected reemergence of this group raises a likely chance that other old time notorious groups may emerge to aid Russia’s hybrid war efforts.
Los Angeles Unified School District Investigates Data Theft Claims
What happened: The Los Angeles Unified School District (LAUSD) officials are investigating claims made by a threat actor stating that they're selling stolen databases containing records of millions of students and thousands of teachers. Meanwhile, ZeroFox has observed threat actor Satanic claiming to sell data belonging to LAUSD on the predominantly English-language dark web forum, “BreachForums."
Why it matters: This incident raises significant concerns about the security of sensitive personal data within educational institutions, affecting not only students but also teachers and staff. The threat actor offered CSV files on a hacking forum, allegedly containing over 11 GB of data, including sensitive personal information. If verified, the breach could have serious implications for the affected individuals, including identity theft and privacy violations. Additionally, it underscores the ongoing threat posed by cybercriminals targeting valuable data repositories.
U.S. Government Attempts to Recover a Trade Union’s Funds Stolen Via Business Email Compromise
Source: https://www.theregister.com/2024/06/06/union_bec_scam/
What happened: The U.S. Department of Justice is seeking to recover over USD 5 million stolen from a Massachusetts trade union by business email compromise scammers, who funneled the funds into accounts in China, Singapore, Hong Kong, and Nigeria.
Why it matters: Business Email Compromise (BEC) is highly likely to remain a pertinent threat to organizations across industries as threat actors continue to capitalize upon established techniques, high success rates, and constantly increasing financial payoffs. A ZeroFox brief released in April noted a sharp rise in BEC attacks due to their high success rates and lucrative returns. Several high-profile BEC attacks have been observed this year, including a campaign targeting Western states with promises of substantial profits. Another campaign involved a BEC-specialized hacker group impersonating several U.S. government agencies to reportedly steal corporate credentials, infiltrate mailboxes, and conduct follow-on business email compromise (BEC) activity.
DEEP AND DARK WEB INTELLIGENCE
- Threat actor b1nary01: Threat actor b1nary01 claimed to have leaked a database from Facebook on the predominantly English-language dark web forum, “BreachForums." The threat actor did not disclose the ultimate source of the data breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
- CVE-2018-20062: Fixed in December 2018, CVE-2018-20062, a critical vulnerability, allows remote attackers to execute arbitrary PHP code by manipulating the filter parameter. Chinese threat actors are exploiting this bug to install a persistent web shell named Dama.
Affected products: NoneCMS 1.3.
- CVE-2019-9082: Addressed in February 2019, this high severity remote command execution vulnerability affects Open Source BMS 1.1.1, posing significant security risks. Chinese threat actors are exploiting this bug to install a persistent web shell named Dama Affected products: ThinkPHP 3.2.4 and older.
Tags: DIB, tlp:green