ZeroFox Cyber Intelligence Daily Brief - July 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks
- Scattered Spider Weaves in Qilin and RansomHub Ransomware Variants into Attacks
- Email Addresses of 15 Million Trello Users Leaked on Hacking Forum
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks
Source: https://thehackernews.com/2024/07/iranian-hackers-deploy-new-bugsleep.html
What happened: Iran-linked “MuddyWater” has been observed deploying a new backdoor dubbed BugSleep in its recent campaigns. The group conducts phishing campaigns and establishes persistence by deploying a legitimate remote monitoring and management (RMM) software. The use of legitimate software has now been reportedly replaced by a new backdoor, which can help the group evade detection by “blending in with legitimate network traffic.”
Why it matters: According to researchers, attackers using this new strain of malware focus on a wide range of targets globally including Israel and some in Turkey, Saudi Arabia, India, and Portugal. The group has also been observed targeting entities like government organizations, airlines, media outlets, telecommunications, government, and oil industry organizations. The threat group is reportedly shifting its attack tactics to better evade detection since the RMM software they use is legitimate and subject to regular monitoring. These precautions reflect the group’s persistence in its phishing campaigns making future campaigns likely to be more dangerous given their attack sphere and methodologies.
Scattered Spider Weaves in Qilin and RansomHub Ransomware Variants into Attacks
Source: https://www.theregister.com/2024/07/16/scattered_spider_ransom/
What happened: Cybersecurity researchers have observed threat actor group Scattered Spider, known for targeting Las Vegas casinos last year, adopting RansomHub and Qilin ransomware variants.
Why it matters: After law enforcement took down ALPHV/BlackCat, the standing RaaS groups initiated a recruiting drive for the best affiliates, reflecting a significant shift in the ransomware landscape. Last month, RansomHub recruited Scattered Spider into its ranks. As a result, Scattered Spider is actively using RansomHub’s artillery, signifying RansomHub’s growing popularity in the cybercrime landscape. Moreover, this shift underscores the increasing sophistication and effectiveness of these new ransomware families, which are now favored over older variants like ALPHV/BlackCat.
Email Addresses of 15 Million Trello Users Leaked on Hacking Forum
What happened: A threat actor known as "emo" accessed over 15 million Trello (a web-based project management tool owned by Atlassian) account email addresses using an unsecure API in January. By inputting a list of 500 million email addresses into the API, emo identified which emails were associated with Trello accounts and created member profiles for those accounts. These profiles include email addresses, public Trello account details, and users' full names. ZeroFox has observed threat actor emo leaking a database associated with Trello on BreachForums.
Why it matters: This breach exposes sensitive information about Trello users, including their email addresses and full names. While the majority of the data in Trello profiles is typically public, the inclusion of non-public email addresses makes users vulnerable to targeted phishing attacks. Attackers can use this information to craft convincing phishing emails aimed at stealing passwords or other confidential information. Furthermore, the exposure of personal details like full names facilitates doxxing, a practice where malicious actors gather and publish private information about individuals, potentially leading to harassment or further exploitation.
DEEP AND DARK WEB INTELLIGENCE
Exploit user doZKey: The untested threat actor "doZKey" advertised an auction for a database of 2 million records of U.S. doctors on the predominantly Russian language dark web forum Exploit. According to doZKey, the database package contains personal information including NPI numbers, names, addresses, and phone numbers. The starting bid for the database was USD 1,300,000, with a minimum bid of USD 500, and an instant purchase price of USD 5,000.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-39841: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the testServiceExistence function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user.
Affected product: Centreon versions lower than 2.04.24, 22.10.22, 23.04.18, 23.10.12, or 24.04.3
CVE-2024-27298: This vulnerability allows remote attackers to disclose sensitive information on affected installations of Parse Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the literalizeRegexPart function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected products: Parse server 6.5.0 and 7.0.0-alpha.20
Tags: DIB, tlp:green