ZeroFox Cyber Intelligence Daily Brief - June 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian APT Midnight Blizzard Targets French Diplomats in Persistent Cyberattacks
- Oyster Backdoor Spreading via Trojanized Popular Software Downloads
- Threat Actor Allegedly Continues Cyberattack Against Schneider Electric
Russian APT Midnight Blizzard Targets French Diplomats in Persistent Cyberattacks
Source: https://www.darkreading.com/remote-workforce/russia-midnight-blizzard-french-diplomats
What happened: Russia-backed advanced persistent threat group Midnight Blizzard (alias APT29, BlueBravo, Cloaked Ursa, Cozy Bear, and The Dukes) has been targeting French diplomatic entities since at least 2021. CERT-FR has warned that this group is actively trying to exfiltrate strategic intelligence through phishing campaigns using compromised email accounts.
Why it matters: In the campaign, dubbed "Diplomatic Orbiter," Midnight Blizzard engages in phishing attacks on diplomatic institutions, embassies, and consulates using forged documents to lure diplomatic staff into its traps. After gaining initial access, the adversary deploys custom first-stage loaders to execute public tools like Cobalt Strike or Brute Ratel C4 to primarily infiltrate the victim's network, maintain access, and steal data. Even though many of their attacks have failed, the focus on French diplomatic entities spell a very likely direct extrapolation of the geopolitical tensions between Russia and France into the cyber landscape. Moreover, with the upcoming Paris Olympics, ZeroFox assesses more Russia-nexus actors will try to target French infrastructure, especially the sports ministry, to disrupt the international event.
Oyster Backdoor Spreading via Trojanized Popular Software Downloads
Source: https://thehackernews.com/2024/06/oyster-backdoor-spreading-via.html
What happened: Security researchers have observed threat actors conducting a malvertising (malicious advertising) campaign to propagate a backdoor called Oyster (Broomstick/CleanUpLoader). The backdoor is spread via a malicious campaign that targets victims attempting to download popular web browsers and communication applications. The downloaded payload can steal system information and facilitate remote code execution.
Why it matters: The evasion tactics used in the campaign involve actually installing the legitimate software tool (in addition to the backdoor) so that victims do not suspect foul play. This discovery comes at a time when a similar phishing campaign, relating to the new phishing-as-a-service (PhaaS) ONNX Store, is targeting installers of popular software tools using PDF attachments. Much like the Oyster backdoor campaign, threat actors lure users to phishing pages that mimic the legitimate websites. To protect against sophisticated phishing attacks, administrators can block PDF and HTML attachments from unverified sources, block access to HTTPS websites with untrusted or expired certificates, and set up additional hardware-based security measures for high-risk, privileged accounts to limit future phishing attempts.
Threat Actor Allegedly Continues Cyberattack Against Schneider Electric
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66127
What happened: Threat actor group Hunt3r Kill3rs claimed to have breached Schneider Electric systems in Germany, the United States, and Turkey, supposedly gaining access to configurations of PowerLogic ION7650 meters, PowerLogic EGX100, and U.motion Builder. The group advertised a zero-day exploit related to Schneider's PowerLogic ION7650 systems for sale at USD 40,000 and requested interested parties to reach out via Telegram.
Why it matters: The infiltration of critical data within Schneider Electric systems has significant repercussions for the supply chains of energy and infrastructure sectors. Compromising such systems can disrupt supply chains, affecting operations, reliability, and potentially cascading impacts across interconnected networks and services. The sale of a zero-day exploit highlights a thriving underground market where cybercriminals can purchase tools to exploit vulnerabilities in industrial control systems, thus increasing the likelihood of future attacks.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user SN_Blackmeta: Threat actor group SN_Blackmeta has claimed to have conducted a cyberattack against KeyBank, a U.S.-based retail banking company. The actor stated the attack was conducted for two hours, allegedly disabling all account services including digital wallet, prepaid mastercard transactions, and money transfers between accounts.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-28995: Threat actors have been observed actively exploiting this SolarWinds Serv-U path-traversal vulnerability, using publicly available proof-of-concept (PoC) exploits.
Affected products: SolarWinds Serv-U FTP Server 15.4, SolarWinds Serv-U Gateway 15.4, SolarWinds Serv-U MFT Server 15.4, and SolarWinds Serv-U File Server 15.4.2.126 and earlier.
Tags: DIB, tlp:green