zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Patelco Credit Union Hit with Ransomware Attack
  • Threat Actors Hijack Korean ERP Vendor's Update Systems to Deliver Malware
  • Brain Cipher Ransomware Gang Targets Indonesian Ministry of Communications and Informatics

Patelco Credit Union Hit with Ransomware Attack

Source: https://www.patelco.org/securityupdate

What happened: Patelco Credit Union has recently experienced a ransomware attack leading to the shutdown of several banking systems for containment and remediation efforts. The organization has enlisted a third-party cybersecurity firm to aid in investigation and recovery.

Why it matters: The recent ransomware attack on Patelco Credit Union led to the shutdown of essential banking systems such as online banking, mobile apps, and the call center, disrupting customer transactions and services, affecting activities like transfers, direct deposits, and balance inquiries. Such ransomware attacks are typically launched by threat actors who exploit vulnerabilities in security protocols or employ social engineering tactics to gain access to sensitive systems. Financial sectors remain prime targets due to the potential for significant financial gain through ransom demands or data theft.

Threat Actors Hijack Korean ERP Vendor's Update Systems to Deliver Malware

Source: https://www.theregister.com/2024/07/02/korean_erp_backdoor_malware_attack/

What happened: Threat actors have hijacked a Korean enterprise resource planning (ERP) vendor’s systems to push malware instead of updates. The malware is reportedly the Xctdoor backdoor, which is “capable of stealing system information and executing commands from the threat actor.” Users are warned against downloading executable files and clicking on email attachments from unknown sources.

Why it matters: Cybersecurity researchers are reportedly attributing this attack’s tactics to that of the threat group “Andariel” group. The group has been observed targeting ERP systems, which are usually known for their sound security, in the past. ERP systems contain sensitive customer and company data that can potentially provide a threat actor with important information to hold for ransom. However, outdated software, legacy systems, and poor data export practices can introduce weaknesses. In this case, the Xctdoor allows the transmission of basic information like username, computer name, and the malware’s product ID (PID) to a command and control (C&C) server. It can also execute commands received from the server. Additionally, the backdoor supports information theft functions, including screenshot capture, keylogging, clipboard logging, and transmitting drive information.

Brain Cipher Ransomware Gang Targets Indonesian Ministry of Communications and Informatics

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66665

What happened: On July 2, ZeroFox Intelligence observed that the Brain Cipher ransomware group listed Indonesia’s Ministry of Communications and Informatics (also known as Kominfo) as a victim on its leak site.

Why it matters: Within a short time of its emergence, Brain Cipher has claimed attacks on notable Indonesian entities, including a massive data breach into Indonesia's temporary National Data Center that made headlines last month as one of the worst cyberattacks the country has suffered in recent years. Targeting government entities without political motives depicts the group’s efforts to establish its legitimacy as a new group in the cyber underworld. Moreover, such attacks could disrupt crucial government operations, compromise sensitive citizen data, and erode public trust in the government's ability to protect its digital infrastructure.

DEEP AND DARK WEB INTELLIGENCE

  • CyberVolk Launches Ransomware: Threat actor group CyberVolk launched a new ransomware named "CyberVolk Ransomware" with a unique encryption algorithm. The threat actor claims that the ransomware is developed using C/C++, SHA 512/AES encryption and it has the capability of encrypting key strings by RSA 4096 algorithm, AV undetectable, and can encrypt/decrypt files without any servers. According to the group, the victim must pay and obtain the decryption key to decrypt the files.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-31320: Google has issued fixes for vulnerabilities in the Android OS. CVE-2024-31320 is a critical flaw in the Framework component that permits attackers to gain escalated privileges on affected devices.

Affected products: Android versions 12 and 12L.

Tags: DIB, tlp:green