zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Australia Arrests Two Russia-Born with Charges of Espionage
  • Platinum Giant Sibanye Hit by Cyberattack, Mining Business Unaffected
  • New Ransomware Groups Ransomcortex and Vanir Group Emerges on the Dark Web

Australia Arrests Two Russia-Born with Charges of Espionage

Source: https://apnews.com/article/australia-espionage-russia-spying-db92e5c5182b82cd815743298ea0dd56

What happened: Australian authorities have arrested two Russian-born people on espionage charges. One of them, an information systems technician in the Australian Army, allegedly tried to access defense material and transmit it to Russian officials. One individual traveled to Russia and asked the other to log into their official account to access defense materials.

Why it matters: Despite no significant compromise being identified, the case highlights the potential risks of cyber espionage from within the defense sector. Incendiary geopolitical situations, like the Russia-Ukraine war in this case, have often invited cyberwarfare and cyberespionage opportunities. Targeting a sensitive system such as the defense ministry could likely compromise national security by leaking sensitive military strategies, exposing classified information, and undermining defense operations. It could lead to weakened defense capabilities, increased vulnerability to attacks, and diminished trust among international allies. Additionally, malicious state-sponsored activities, including disinformation campaigns, could use the stolen information to manipulate political decisions or economic policies.

Platinum Giant Sibanye Hit by Cyberattack, Mining Business Unaffected

Source: https://www.reuters.com/technology/cybersecurity/platinum-giant-sibanye-says-its-system-has-been-hit-cyberattack-2024-07-11/

What happened: Sibanye-Stillwater confirmed that a cyber incident affected its IT systems and caused limited disruption to its global operations; its core processes remain unaffected. The mining company is investigating the incident and is working toward reviving systems after “isolating” them to limit further attacks.

Why it matters: Sibanye-Stillwater is a global mining company of precious metals like platinum, palladium, rhodium, and gold which can be important to critical infrastructure and industries like aerospace and defense, manufacturing, and automobile. Threat actors may view such an operation as a vital repository of data that they can sell on the dark web to entities that would want to fund global hacktivist efforts or hold such data for ransom.

New Ransomware Groups Ransomcortex and Vanir Group Emerges on the Dark Web

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67059

What happened: On July 12, ZeroFox identified two new leak sites called Ransomcortex and Vanir Group in the dark web. Ransomcortex leak site has been observed listing three victims from Brazil and the Vanir Group listed three victims from the United States, Netherlands, and China.

Why it matters: Smaller and emerging ransomware groups pose a heightened threat in the current cybersecurity landscape. Following significant law enforcement (LE) actions that dismantled major ransomware operations like LockBit, larger groups have decreased their attack frequency to evade detection. However, this shift has inadvertently shifted the spotlight to smaller groups, which are now stepping up their activities. These emerging groups are often observed to consist of skilled members who might have previously operated within larger organizations, bringing sophisticated techniques and capabilities to their new ventures. This dynamic makes smaller ransomware groups more active and prolific. These new groups are more agile, less predictable, and driven by the opportunity created by the void left by their larger counterparts.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user IntelBroker: The well-regarded and established threat actor "IntelBroker" claimed to be selling network access to a police department in South Korea for USD 800 on the predominantly English-language dark web forum BreachForums. The access types available for sale reportedly include the administrative portal, user accounts, and the central command panel.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-39929: It is a critical (CVSS score: 9.1/10.0) bug in Exim, a free mail transfer agent, that can let threat actors deliver malicious attachments to a user’s inbox.

Affected products: Versions of Exim through 4.97.1

Tags: DIB, tlp:green