zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach
  • LockBit & Conti Ransomware Hacker Busted in Ukraine
  • Phone Scammers Impersonating CISA Employees

ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach

Source: https://www.zerofox.com/advisories/23723/

What happened: On June 11, untested threat actor “sp1d3r'' advertised the sale of a notably-large leaked data set in the Russian-speaking dark web forum xss. The breach allegedly contains 65,000 records of data stolen from a U.S.-based financial organization that purportedly include both personal financial information (PFI) and personally identifiable information (PII).

Why it matters: The owner of this stolen data is likely a victim of the ongoing fallout of the alleged breach of cloud-based service provider Snowflake. Since the alleged breach on May 23, 2024, several of Snowflake’s assumed customers’ data have been advertised on deep and dark web (DDW) forums. Sp1d3r is almost certainly synonymous with, or heavily associated with, threat actor “ShinyHunters”, who is very likely responsible for recent attacks against Snowflake customers. In the coming weeks, it is very likely that additional Snowflake customers will be implicated in data breaches, with the stolen information being advertised for sale in DDW forums.

LockBit & Conti Ransomware Hacker Busted in Ukraine

Source: https://www.darkreading.com/cyberattacks-data-breaches/lockbit-and-conti-ransomware-hacker-busted-in-ukraine

What happened: A Ukrainian man was arrested for his role as a freelance developer for the Russian ransomware groups Conti and LockBit. The accused cybercriminal specialized in creating cryptors, used to hide malware from antivirus detection, and had a history of working for these groups in exchange for cryptocurrency.

Why it matters: Cybercriminals like the arrested Ukrainian developer often operate on a freelance basis, leveraging their expertise to develop cryptors and other tools for ransomware groups like Conti and LockBit in exchange for cryptocurrency payments. However, Operation Endgame showcases ongoing efforts by law enforcement to tackle cyber threats, and serves as a deterrent to individuals involved in facilitating such malicious activities. Additionally, this incident sheds light on the role of cryptocurrency in enabling anonymous transactions for illegal activities, prompting further scrutiny of digital currency regulations and enforcement.

Phone Scammers Impersonating CISA Employees

Source: https://www.cisa.gov/news-events/alerts/2024/06/12/phone-scammers-impersonating-cisa-employees

What happened: Cybersecurity and Infrastructure Security Agency (CISA) reports that phone scammers impersonating names and titles of government employees are also targeting CISA employees. CISA notifies Americans that its employees will never request individuals to wire money, cash, cryptocurrency, or use gift cards and will never instruct to keep the discussion secret.

Why it matters: CISA advises Americans to take note of the phone number, hang up immediately, and to validate the contact by calling CISA or reporting it to law enforcement. Successful infiltration into systems with the scammed data can create opportunities for identity theft and fraud, potentially causing financial harm to affected individuals.

DEEP AND DARK WEB INTELLIGENCE

BreachForums: On June 13, ZeroFox observed that both Tor and clearnet sites of BreachForums, a major English-language cybercrime forum, were back operational.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-32896: Google released a major Pixel security update, warning that one patched vulnerability, CVE-2024-32896, has been exploited. This zero-day bug is a high-severity elevation of privilege issue.

Affected product: Pixel Firmware.

CVE-2024-30103: The critical flaw enables attackers to circumvent Outlook's registry-based block lists, facilitating the creation and deployment of harmful DLL files.

Affected products: Microsoft has listed the affected products in this advisory.

Tags: DIB, tlp:green