zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Treasury Sanctions 12 Kaspersky Executives amid Software Ban
  • CDK Global Outage Reportedly Caused by BlackSuit Ransomware Attack
  • Chinese Hackers Step Up Attacks on Taiwanese Organizations

U.S. Treasury Sanctions 12 Kaspersky Executives amid Software Ban

Source: https://thehackernews.com/2024/06/us-treasury-sanctions-12-kaspersky.html

What happened: The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned twelve senior executives at Kaspersky Lab. The Department of Commerce also banned Kaspersky Lab and its affiliates from providing cybersecurity products in the United States, citing national security risks and ties to Russian intelligence.

Why it matters: The sanctions block all property and interests of designated individuals and entities within the United States or controlled by American people. They also set precedents for foreign institutions engaging in significant transactions with the Russian military-industrial sector, thereby serving as a warning to entities actively facilitating or enabling activities that could compromise national security. Amid ongoing geopolitical tensions, Russia has criticized the U.S. sales ban on Kaspersky software, calling it a typical effort to stifle foreign competition in favor of American products. However, Kaspersky has maintained its stance of not being associated with the Russian government.

CDK Global Outage Reportedly Caused by BlackSuit Ransomware Attack

Source: https://www.bleepingcomputer.com/news/security/cdk-global-outage-caused-by-blacksuit-ransomware-attack/

What happened: BlackSuit ransomware gang has been observed to be behind the recent CDK Global cyber incidents. The company is reportedly in talks with the gang to receive a decryptor and prevent associated data leaks as well. CDK has suffered two cyber incidents last week and was forced to bring some of its systems offline, including its customer support channels leaving clients with limited support options.

Why it matters: After the first breach, CDK Global decided to rapidly restore services after taking them down. Many expressed their concerns that such an action could endanger clients to fresh attacks. These attacks show that a more staggered approach to reviving offline systems may be instrumental in further protecting clients and the company from future attacks. Also, CDK Global is warning clients that non-CDK representatives are now contacting them on CDK’s behalf hoping to gain unauthorized access to systems. CDK is advising its clients to refrain from responding to such requests, as they are likely to be made by bad actors to facilitate follow-on attacks.

Chinese Hackers Step Up Attacks on Taiwanese Organizations

Source: https://apnews.com/article/china-taiwan-hackers-cybersecurity-breach-b8fdd95b2e0f36e368662925368caa58

What happened: A Chinese state-sponsored hacking group, known as RedJuliett, intensified its cyberattacks targeting Taiwanese organizations, particularly in government, education, technology and diplomacy sectors. RedJuliett exploited vulnerabilities in SoftEther VPN software to breach the networks of various institutions, including government agencies in multiple countries, universities, and technology companies.

Why it matters: These cyberattacks underscore the escalating tensions between China and Taiwan, particularly in light of the new Taiwanese administration's perceived stance on independence. The scale and targets of the attacks suggest strategic interference, potentially aimed at gaining political and economic intelligence. RedJulliet, whose hacking patterns are observed to be similar to those of Chinese state-sponsored groups, has been noted attempting cyberattacks against more than 70 Taiwanese organizations. Earlier this month, Palau, one of Taiwan’s remaining diplomatic allies, accused China after it suffered a cyberattack in March with more than 20,000 government documents stolen and later published on the dark web in April.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user Sp1d3r: Threat actor Sp1d3r claimed to have leaked a database associated with Jollibee, a U.S.-based fast food delivery company on the dark web forum, BreachForums. The threat actor claimed to sell 32 million customers’ data including name, address, phone number, email address, hashed passwords, sales orders, and transactions priced at USD 40,000.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Juniper vulnerabilities: Juniper has released patches for multiple vulnerabilities that affect Juniper Secure Analytics (JSA). A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system. These vulnerabilities have been resolved in the 7.5.0 UP8 IF03 version of the application.

Affected products: All versions of Juniper Secure Analytics prior to 7.5.0 UP8 and 7.5.0 UP8 IF02.

Tags: DIB, tlp:green