ZeroFox Cyber Intelligence Daily Brief - July 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Europol Urges Lawmakers to Address Encryption Hurdles in SMS Home Routing
- Euro 2024 Faces Cyber Threats, Including Attempted Denial-of-Service Attacks
- New Eldorado Ransomware Targets VMware ESXi VMs
Europol Urges Lawmakers to Address Encryption Hurdles in SMS Home Routing
Source: https://www.theregister.com/2024/07/05/europol_home_routing_complaint/
What happened: Europol has released a position paper expressing concerns over SMS home routing technology, which uses service-level encryption that hinders law enforcement's ability to intercept unencrypted data from suspects using foreign SIM cards. Telecommunication companies often use this privacy-enhancing technology (PET) to provide seamless mobile services to customers traveling abroad.
Why it matters: SMS home routing with privacy-enhancing technology and service-level encryption protects the user's messages from interception and unauthorized access, ensuring privacy and security. At the same time, it complicates the ability to intercept and monitor SMS messages for investigative purposes. Europol claims that PET-enabled home routing poses roadblocks while accessing unencrypted communications of suspects, as data is processed through the user's home network. Hence, investigations become complex when a crime is committed in a foreign country, as local authorities cannot easily obtain unencrypted data from the suspect's home network.
Euro 2024 Faces Cyber Threats, Including Attempted Denial-of-Service Attacks
What happened: Cybersecurity researchers have encountered threat actors selling credentials belonging to Union of European Football Associations (UEFA) customers on dark web forums. Russian actors are suspected of conducting denial-of-service attacks during online broadcast of Poland's Group D opener against Estonia.
Why it matters: Threat actors selling UEFA customer credentials on dark web forums are likely looking to profit from exploiting sensitive information. Such data can also encourage other malicious actors to engage in phishing attacks, identity theft scams, and extortion. Meanwhile, Russian actors targeting the tournament are likely aligned with the political motives of their sponsor state because the UEFA has barred Russia from Euro 2024 amid the ongoing Russia-Ukraine war. State-sponsored activity will likely persist in the upcoming international events, including the Paris Olympics.
New Eldorado Ransomware Targets VMware ESXi VMs
What happened: Eldorado ransomware group has been observed targeting both Windows and Linux systems, including VMware ESXi hypervisors, using ChaCha20 and RSA encryption, appending ".00000001" to encrypted files, and leaving "HOW_RETURN_YOUR_DATA.TXT" ransom notes on the compromised systems. It encrypts network shares via SMB, deletes shadow copies, and self-deletes to evade detection. On June 7, ZeroFox identified Eldorado’s new leak site.
Why it matters: Eldorado's use of strong encryption algorithms and RSA for key management highlights the increasing sophistication of ransomware techniques, posing severe threats to organizations across multiple critical sectors. Its deliberate targeting of VMware ESXi environments underscores the ransomware's adaptation to enterprise infrastructures, potentially causing widespread operational disruptions and data loss. Furthermore, RansomHub, a ransomware-as-a-service (RaaS) operation was also observed utilizing a Linux encryptor tailored for encrypting VMware ESXi environments in corporate attacks. Threat actors target VMware ESXi environments due to their prevalence in corporate infrastructures, aiming to maximize impact and ransom yield. This specialized focus disrupts critical operations, demanding significant recovery efforts and potentially substantial financial losses for affected organizations.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user IntelBroker: Well-regarded and established threat actor IntelBroker claimed to have leaked access to ANRA Technologies, a U.S.-based drone software platform provider, on dark web forum BreachForums. The threat actor did not disclose the ultimate source of the data breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-0986: This vulnerability found in Issabel PBX 4.0.0 has been rated with a CVSS score of 9.8. This issue affects some unknown processing of the file /index[.]php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument command leads to os command injection. The attack can also be initiated remotely.
Affected products: Issabel PBX 4.0.0.
CVE-2024-37903: Starting in Mastodon version 2.6.0 and before versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining access to the contents of a post not intended for them. Versions 4.1.18 and 4.2.10 contain a patch for this issue.
Affected products: Versions >= 2.6.0.
Tags: DIB, tlp:green