ZeroFox Cyber Intelligence Daily Brief - July 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Threat Actors with Political Motivations Target NATO amid Ongoing Summit
- New Blast-RADIUS Attack Bypasses Widely-Used RADIUS Authentication
- Japan Warns of Attacks Linked to North Korean Kimsuky Hackers
Threat Actors with Political Motivations Target NATO amid Ongoing Summit
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66914
What happened: ZeroFox intelligence has observed threat actor SiegedSec claiming to have breached the NATO Consultation, Command, and Control (C3) portal. Additionally, several other adversaries have been observed forming alliances to target NATO amid the 2024 Washington summit, which began on July 9 and will go on till July 11.
Why it matters: Most of the actors, including hacktivists, targeting NATO are politically motivated. SiegedSec has stated its support for the Palestinian cause to be the motivation behind its attack. In a Telegram post, the group states it was apparently able to access “tens of thousands documents.” The current geopolitical landscape, dotted with wars, is likely to incite more threat actor activity aimed toward disrupting international events and summits. NoName (057), a pro-Russian hacktivist group infamously known for targeting government entities with DDoS attacks, is actively recruiting other adversaries while claiming to continue DDoS attacks on NATO websites. However, since these are hacktivist groups, the attacks are likely to be short-lived and harmless.
New Blast-RADIUS Attack Bypasses Widely-Used RADIUS Authentication
What happened: Blast-RADIUS, an authentication bypass exploit in the widely adopted RADIUS/UDP protocol, allows threat actors to compromise networks and devices using man-in-the-middle MD5 collision attacks. This vulnerability affects numerous networked devices in enterprise and telecommunication networks, where RADIUS is crucial for authentication across various services including DSL, FTTH, Wi-Fi, cellular roaming, and VPNs.
Why it matters: RADIUS (Remote Authentication Dial-In User Service) is integral to numerous critical functions such as network device authentication, DSL/FTTH (Fiber to the Home) connectivity, Wi-Fi security (802.1X), and mobile network roaming (2G/3G/5G). Exploitation of these critical functions poses severe security risks, potentially compromising tens of thousands of networked devices within a single enterprise or telecom network. Blast-RADIUS exploits a new protocol vulnerability (CVE-2024-3596) and an MD5 collision attack. This allows attackers to manipulate RADIUS traffic to gain administrative privileges without the need for brute-force attacks or credential theft, leveraging weaknesses in the MD5 hashing used in RADIUS protocol transactions.
Japan Warns of Attacks Linked to North Korean Kimsuky Hackers
What happened: Japan's Computer Emergency Response Team Coordination Center (JPCERT/CC) is warning about targeted attacks by the North Korean “Kimsuky” threat actors against Japanese organizations. JPCERT/CC emphasizes the importance of vigilance against CHM files, which can contain executable scripts designed to deliver malware, to mitigate these threats and protect organizational security.
Why it matters: Kimsuky, a North Korean advanced persistent threat (APT) group, conducts attacks across the globe to gather intelligence on topics of interest to the North Korean government. The group is known for using social engineering and phishing techniques to gain initial access to networks. They then deploy custom malware to steal data and retain persistence on networks. These attacks typically begin with phishing emails that impersonate security and diplomatic organizations, containing a malicious ZIP attachment. The ZIP file includes an executable disguised as a document file by using many spaces to hide the ".exe" extension, along with two decoy documents. Once executed, the malware can lead to the exfiltration of sensitive data, such as credentials, which can enable further infiltration into the organization's systems and applications.
Tags: DIB, tlp:green