ZeroFox Cyber Intelligence Daily Brief - July 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- A Cyberattack on the Alabama Education Department Exposed Student and Employee Data
- Threat Actor Claims to Leak Bar Codes for Taylor Swift’s ERAS Tours
- New Golang-Based Zergeca Botnet Capable of Powerful DDoS Attacks
A Cyberattack on the Alabama Education Department Exposed Student and Employee Data
What happened: Alabama State Department of Education faced a recent hacking attempt, which was halted while the attack was ongoing. The superintendent of the department stated that some student and employee data was breached during the incident, and a contractor is investigating the extent of the compromise.
Why it matters: Threat actors can exploit compromised student and employee data for various malicious activities, including identity theft, phishing scams targeting individuals within the affected organization, and potentially selling the data on the dark web for financial gain. The stolen information can also be used to perpetrate further cyber attacks or to impersonate individuals for fraudulent purposes such as accessing financial accounts or applying for loans. Fortunately, sensitive employee banking details were not stored on state servers, minimizing that risk. Authorities believe the hackers' objective was to encrypt data and demand ransom, leading to an ongoing federal investigation into the incident involving suspected foreign hackers.
Threat Actor Claims to Leak Bar Codes for Taylor Swift’s ERAS Tours
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66835
What happened: Threat actor group Sp1d3rHunters has leaked 170,000 allegedly valid barcodes for Taylor Swift's ERAS Tour events online. The group claims that these barcodes can be used for entry at concerts in Miami, New Orleans, and Indianapolis and has demanded USD 2 million from Ticketmaster, threatening to release more sensitive data if the company does not meet the ransom demands.
Why it matters: The leaked barcodes might be acquired by other bad actors that are likely to grab the attention of fans who were unable to get tickets and entrap them in illegal schemes. Therefore, the data breach could not only lead to financial losses, but also result in unauthorized venue access, overcrowded events, and subject the attendees to substantial physical threats of stampedes. Besides, such behavior will likely encourage other threat actors to follow suit for other highly-anticipated events. The threat to release 30 million more event barcodes and 680 million users' information, including major sporting events and concerts, highlights the severity of the situation. Previous breaches involving Ticketmaster's parent company, Live Nation, and the substantial ransom demands reflect
New Golang-Based Zergeca Botnet Capable of Powerful DDoS Attacks
Source: https://thehackernews.com/2024/07/new-golang-based-zergeca-botnet-capable.html
What happened: Cybersecurity researchers have discovered a new botnet called Zergeca, which is capable of conducting distributed denial-of-service (DDoS) attacks. According to researchers, the malware is actively being developed and updated to support new commands.
Why it matters: Zergeca supports six different attack methods and has additional capabilities such as proxying, scanning, self-upgrading, persistence, file transfer, reverse shell, and collecting sensitive device information. It is notable for using DNS-over-HTTPS (DoH) for DNS resolution of its Command and Control (C2) server and employing a lesser-known library called Smux for C2 communications. Additionally, it can establish persistence by adding a system service, implementing proxying, removing competing miner and backdoor malware to gain exclusive control over certain devices, and handling the main botnet functionality.
DEEP AND DARK WEB INTELLIGENCE
Telegram user “Altoufan Team”: Threat actor group Altoufan Team claimed to have carried out a cyberattack against various government websites from the United Arab Emirates (UAE) , including the Ministry of Community Development and Sharjah Economic Development Department. The threat actor allegedly leaked a sample database that contains 240 thousand documents acquired from Sharjah Economic Development Department.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-5716: It is a vulnerability affecting the password reset mechanism, allowing an attacker to bypass authentication. This security flaw occurs due to the absence of limitations on the number of password reset attempts. Exploiting this issue involves sending numerous password reset requests until the correct reset code is brute-forced. With the correct reset code in hand, the attacker can then reset the admin's password, thereby obtaining unauthorized administrative access to the system.
Affected product: Logsign Unified SecOps Platform
Tags: DIB, tlp:green