zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 27, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining
  • North Korean Hacker Indicted for Cyberattacks on U.S. Health Care, NASA, and Military
  • BreachForums Actor Claims to Leak Data Associated with Mexican Political Parties

Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining

Source: https://thehackernews.com/2024/07/ongoing-cyberattack-targets-exposed.html

What happened: Cybersecurity researchers have identified a campaign, named SeleniumGreed, targeting misconfigured and exposed Selenium Grid services to illegally mine cryptocurrency. This campaign exploits older versions of Selenium (3.141.59 and prior), which allow full interaction with the underlying machine.

Why it matters: Selenium Grid, used for running WebDriver scripts on remote machines, can be vulnerable when exposed to the internet. Misconfigurations can allow attackers to exploit these services for unauthorized access, including file manipulation and remote command execution. The exploitation of such vulnerabilities for cryptocurrency mining not only compromises system performance but also risks further unauthorized access and data breaches. Recently, threat actors have been observed to increasingly target cryptocurrency mining operations, seeking to exploit and hijack computing power for illicit gains. To protect against such attacks, organizations should use external and vulnerability scanners to identify exposure within the cloud environment, implement runtime detection for real-time threat response, and apply network security controls like firewalls to restrict access.

North Korean Hacker Indicted for Cyberattacks on U.S. Health Care, NASA, and Military

Source: https://apnews.com/article/north-korea-hacker-military-intelligence-hospitals-b3153dc0ad16652a80a9263856d63444

What happened: A North Korean military intelligence operative has been indicted for hacking into American healthcare providers, NASA, U.S. military bases, and international entities. The individual laundered stolen money through a Chinese bank to fund further cyberattacks on global defense, technology, and government entities. The hacks disrupted patient treatment and compromised sensitive information.

Why it matters: The adversary’s efforts disrupted healthcare services and compromised sensitive information across multiple U.S. states and international entities. The indictment may lead to sanctions that could deter future ransom-based cyberattacks, especially on vital services like hospitals. However, the attacks, driven by North Korea’s need to fund military and nuclear ambitions amidst international sanctions, indicate that such politically motivated attacks pose a significant risk to the American critical infrastructure. Additionally, experts warn that North Korea might shift to more cryptocurrency theft, maintaining the cybersecurity threat. The involvement of a Chinese bank and victims in allied countries adds geopolitical complexity to the issue.

BreachForums Actor Claims to Leak Data Associated with Mexican Political Parties

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67628

What happened: ZeroFox intelligence has observed threat actor USDoD claiming to leak a dataset associated with two Mexican Political Parties on BreachForums.

Why it matters: USDoD has been making headlines for its supposed CrowdStrike breach, where the adversary leaked some of the company’s private information on hackers it monitors. USDoD has also previously disclosed a database allegedly containing 70 million rows of information, derived from a U.S. criminal database. The latest leak of the political parties’s data allegedly includes full names, voter IDs, addresses, and dates of birth. The exposed sensitive details can be leveraged for targeting individuals in spear phishing attacks, extortion schemes, and blackmail, leading to severe consequences like reputational damage, financial losses, and legal implications. Moreover, it is likely to attract the attention of politically motivated actors who wish to cause harm or draw attention to their agenda via influence campaigns and cyberattacks targeting the exposed parties. Mexican elections have a recent history of utilizing disinformation campaigns to manipulate public opinion. Notably, during this year’s general elections, the Electoral Institute reported a total of 441 cyberattacks.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user "Hana": Threat actor "Hana" claimed to have leaked data associated with Koninklijke Nederlandse Akademie van Wetenschappen (KNAW), a Netherlands-based educational institution, on the predominantly English-language dark web forum BreachForums. The threat actor claimed that Koninklijke Nederlandse Akademie van Wetenschappen had a data breach in July 2024, exposing 37,523 user records. The leaked data includes UID, full name, address, email, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-38164: An improper access control vulnerability (CVSS score: 9.6) in GroupMe allows an unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.

Affected product: GroupMe

Tags: DIB, tlp:green