zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • New ICS Malware “FrostyGoop” Targeting Critical Infrastructure
  • U.S. Government IT Services Provider Suffers Data Breach
  • BreachForums v1 Database Leak Reveals Threat Actor Information

New ICS Malware “FrostyGoop” Targeting Critical Infrastructure

Source: https://thehackernews.com/2024/07/new-ics-malware-frostygoop-targeting.html

What happened: An energy company in Lviv, Ukraine, experienced a disruptive cyberattack early this year, utilizing a new type of Industrial Control Systems (ICS)-focused malware dubbed “FrostyGoop.” This malware is notable for being the first to employ Modbus TCP communications to target operational technology (OT) networks. It interacts with ENCO controllers via TCP port 502 exposed to the internet. FrostyGoop can manipulate ICS devices by reading and writing to their registers, affecting inputs, outputs, and configuration data.

Why it matters: The discovery of FrostyGoop marks the emergence of the ninth known ICS-focused malware, underscoring a growing threat landscape targeting critical infrastructure worldwide. By leveraging Modbus TCP, a widely used protocol in industrial environments, FrostyGoop malware poses a direct risk to the reliability and safety of ICS networks. Its ability to manipulate ICS devices remotely underscores the potential for severe operational disruptions, as seen in Lviv where heating services to over 600 apartment buildings were disrupted for nearly two days. Furthermore, FrostyGoop's attribution to an unknown threat actor highlights the evolving landscape of cyber threats, where sophisticated tools like this can be deployed with strategic intent but without clear identification.

U.S. Government IT Services Provider Suffers Data Breach

Source: https://www.bloomberg.com/news/articles/2024-07-23/hackers-leak-documents-from-pentagon-it-services-provider-leidos

What happened: Leidos Holdings Inc., one of the largest IT services providers of at least three U.S. government entities, has suffered a breach in which actors stole some internal documents.

Why it matters: A Leidos spokesperson has reportedly confirmed that the leaked data was from “a previous incident affecting a third-party vendor” and did not impact Leidos’ network or any sensitive customer data. However, Leidos has seen a dip of almost four percent in its shares since, signaling an erosion of shareholder trust and some reputational damage. Moreover, the leaked documents will likely tempt malicious threat actors and state-sponsored actors to abuse the data in attacks with far-reaching impacts, potentially affecting national security and sensitive operations. Besides, such attacks also lay a blueprint for adversaries to infiltrate critical infrastructure or government networks via third-party vendors for cyberespionage, persistent campaigns, and data exfiltration.

BreachForums v1 Database Leak Reveals Threat Actor Information

Source: https://www.bleepingcomputer.com/news/security/breachforums-v1-database-leak-is-an-opsec-test-for-hackers/

What happened: The complete database of the BreachForums v1 hacking forum has reportedly been released on Telegram, exposing a vast amount of data. This includes members' information, private messages, cryptocurrency addresses, and every post made on the forum. Although the database had been shared with sources previously, it was not publicly released until recently.

Why it matters: This leak has proven to be of some value as researchers have additional details about various threat actors which they can use to profile them to connect them to respective cybercrimes conducted. The leak also revealed private messages between threat actors discussing operational details. This leak reportedly started with the Life360 Breach where the threat actor “emo” claimed to leak a database allegedly leaking personal information of over half a million users of Life360, a family safety and location-sharing app on the dark web. Researchers observed that the leaked data included all the forum data, including passwords, private messages, and cryptocurrency wallets.

DEEP AND DARK WEB INTELLIGENCE

Telegram user “NetSycho”: Threat actor group NetSycho claimed to have leaked a database associated with the National Institute of Health Sciences and Technology, India. The leaked database includes name, email, phone number, and more. The threat actor claimed to have access to both the internal network and device data.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-5602: Successful exploitation of this vulnerability could allow a local attacker to execute arbitrary code. The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. User interaction is required to exploit the vulnerability in that the user must open a malicious nitrace file. CISA has also added three other Industrial Control Systems (ICS) advisories on July 23, 2024.

Affected product: All versions of I/O TRACE

CVE-2024-5983: A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file bookPerPub.php. The manipulation of the argument pubid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268459.

Affected product: itsourcecode Online Bookstore 1.0

Tags: DIB, tlp:green