ZeroFox Cyber Intelligence Daily Brief - June 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- RansomHub Recruits Scattered Spider in Its RaaS Collective
- Panera Warns of Employee Data Breach After March Ransomware Attack
- Truist Bank Confirms Breach After Stolen Data Shows up on Hacking Forum
RansomHub Recruits Scattered Spider in Its RaaS Collective
Source: https://www.darkreading.com/threat-intelligence/ransomhub-brings-scattered-spider-into-its-raas-fold
What happened: RansomHub has recruited Scattered Spider, a notorious actor associated with a string of attacks targeting popular casinos last year, into its ranks. The recruitment drive comes as an effort to capitalize on the situation caused by the collapse of the ALPHV/BlackCat ransomware-as-a-service (RaaS) operation, leaving affiliates without owed payments and infrastructure.
Why it matters: After law enforcement took down BlackCat, the standing RaaS groups initiated a recruiting drive for the best affiliates, reflecting a significant shift in the ransomware landscape. RansomHub's success in recruiting top affiliates and posting over 75 victims swiftly sophistication and threat posed by modern RaaS operations is a direct outcome of its attractive offers and affiliate terms. With a skill set comprising social engineering tactics and a wide range of data exfiltration techniques, this new collective is likely to target critical infrastructure and other large influential organizations globally in financially motivated attacks.
Panera Warns of Employee Data Breach After March Ransomware Attack
What happened: Panera Bread experienced a ransomware attack in late March, resulting in the encryption of its virtual machine systems. Besides notifying the employees, the company has also informed the office of California's Attorney General of the data breach, and is currently investigating the incident with external cybersecurity experts.
Why it matters: Panera's ransomware attack highlights the ongoing threat posed by cybercriminals to businesses, potentially disrupting operations and compromising sensitive data. With the stolen data, threat actors can potentially engage in identity theft, fraud, or sell the information on the dark web. Personal information like names and Social Security numbers can be used to open fraudulent accounts, apply for loans, or conduct other criminal activities. Panera is offering affected individuals a one-year membership to credit monitoring, identity detection, and identity theft resolution services.
Truist Bank Confirms Breach After Stolen Data Shows up on Hacking Forum
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/65805
What happened: ZeroFox has observed threat actor "Sp1d3r'' advertising the sale of data relating to Truist Bank on dark web forums. Truist has confirmed that its systems had been breached in an October 2023 cyberattack. This confirmation came after “Sp1d3r'' posted some of the allegedly stolen data, including information of 65,000 employees, for sale on a dark web forum at USD one million.
Why it matters: The exposure of sensitive employee information such as bank transactions with names, account numbers, balances, and IVR funds transfer source code could lead to identity theft, fraud, phishing attacks, and other malicious activities. The compromised banking data poses a severe threat to customer privacy and financial security. Moreover, the exposure of the source code presents opportunities for exploiting vulnerabilities within the bank's systems, potentially leading to further breaches or manipulation of banking operations.
DEEP AND DARK WEB INTELLIGENCE
Threat actor Centrek: On June 13, 2024, threat actor "Centrek" advertised a data breach impacting the U.S.-based company Santander Bank on the predominantly Russian language Dark Web forum "XSS." According to "Centrek" the breached data includes reference data, customer ID, party ID, party name, party type, entailment level, and country of residence. The threat actor claimed the data breach was a part of the Snowflake breach.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-26169: CISA has added CVE-2024-26169 in its Known Exploited Vulnerabilities (KEV) catalog. It is a critical Windows Error Reporting flaw allowing SYSTEM privilege escalation (CVSS score: 7.8). Microsoft released a patch for it in March.
Affected product: Windows Error Reporting Service.
Tags: DIB, tlp:green