zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 22, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 22, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Global IT Outages Causing Significant Disruption to Multiple Industries
  • New Linux Variant of Play Ransomware Targeting VMware ESXi Systems
  • UK Arrests Suspected Scattered Spider Hacker Linked to MGM Attack

Global IT Outages Causing Significant Disruption to Multiple Industries

Source: https://www.zerofox.com/advisories/24600/

What happened: The global outage caused by a faulty CrowdStrike update has left millions of devices across the world struggling with daily operations. ZeroFox notes that threat actors may seek to exploit the ongoing outages, including by taking advantage of stretched security infrastructure and performing attacks against targets that may otherwise draw quick attention and be identified. Scammers may also leverage the outage as a lure in social-engineering attacks. Attackers may also target high-profile victims that choose to remove their endpoint detection and response (EDR) suite in response to the outage, thereby leaving them vulnerable.

Why it matters: Threat actors abused this global outage by reportedly exploiting companies via data wipers (masquerading as an update from CrowdStrike) and remote access tools. The absence of a centralized workaround to address the outage prompted affected people to look for solutions online. Such panic-induced searches, as well as phishing emails promising mitigation measures, led victims to malicious websites that attempt to steal user credentials and infect systems.

New Linux Variant of Play Ransomware Targeting VMware ESXi Systems

Source: https://thehackernews.com/2024/07/new-linux-variant-of-play-ransomware.html

What happened: Cybersecurity researchers have identified a new Linux variant of the Play ransomware, known for targeting VMware ESXi environments. While actual infections haven't been observed yet, the variant's command-and-control (C2) server hosts tools used by Play ransomware, indicating potential readiness for deployment.

Why it matters: This development is important as it signifies a strategic shift by cybercriminals towards targeting Linux platforms, potentially expanding their victim base and increasing the likelihood of successful ransom negotiations. The inclusion of familiar tools and tactics suggests that this variant could leverage established methods for intrusion and exploitation, posing heightened risks to organizations relying on Linux-based infrastructure, particularly VMware ESXi environments, due to their critical role in business operations. Further analysis indicates that the Play ransomware group is utilizing services provided by Prolific Puma, which offers an illicit link-shortening service to aid cybercriminals in evading detection while distributing malware. This potential collaboration suggests that Play ransomware actors are actively seeking ways to circumvent security measures with the help of Prolific Puma's infrastructure. Additionally, RansomHub and Eldorado ransomware groups have also been observed deploying a Linux encryptor specifically designed to target VMware ESXi environments during corporate attacks.

UK Arrests Suspected Scattered Spider Hacker Linked to MGM Attack

Source: https://www.bleepingcomputer.com/news/security/uk-arrests-suspected-scattered-spider-hacker-linked-to-mgm-attack/

What happened: The UK police, in coordination with the FBI, have apprehended a 17-year-old in connection with the threat group called Scattered Spider. Law enforcement has also confiscated digital devices to be investigated for further evidence. Researchers observed that the group is not a “cohesive gang” but a collection of threat actors participating in many global cyberattacks, which makes it difficult for law enforcement to zero-in on them.

Why it matters: The threat group known as Scattered Spider uses various social-engineering techniques, especially phishing, push bombing, and SIM-swapping attacks, to obtain credentials, install remote access tools, and/or bypass multi-factor authentication (MFA). The group has been successful in evaded detection on target networks by using living-off-the-land techniques and allowlisted applications to navigate victim networks, as well as frequently modifying its tactics, techniques, and procedures.

DEEP AND DARK WEB INTELLIGENCE

Pro-Russian hacktivist group Autodafe: A pro-Russian hacktivist group Autodafe internet claimed to have carried out a DDoS attack against Florida Board of Nursing, United States.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-6802: It is a critical (CVSS v3.1 score of 9.8) vulnerability found in SourceCodester Computer Laboratory Management System 1.0. The vulnerability affects an unknown function of the file /lms/classes/Master[.]php?f=save_record. It allows for SQL injection through the manipulation of the 'id' argument.

Affected product: SourceCodester Computer Laboratory Management System 1.0

Tags: DIB, tlp:green