ZeroFox Cyber Intelligence Daily Brief - August 1, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cyber Espionage Group XDSpy Targets Companies in Russia and Moldova
- Several Small Indian Banks Offline Due to Ransomware Attack
- Ransomware Attack Cuts off Blood Supply to More than 200 Hospitals
Cyber Espionage Group XDSpy Targets Companies in Russia and Moldova
Source: https://thehackernews.com/2024/07/cyber-espionage-group-xdspy-targets.html
What happened: Companies in Russia and Moldova were targeted by a cyber espionage group, XDSpy, through a phishing campaign. The group used spear-phishing emails to deploy the XDDown malware, which then installed additional plugins to collect system information, monitor drives, exfiltrate files, and capture passwords.
Why it matters: The cyber espionage group has been observed targeting Eastern European and Balkan organizations since 2011. Over the past year, XDSpy has targeted Russian organizations using a C#-based dropper called UTask, which downloads a core executable that retrieves additional payloads from a command-and-control (C2) server. XDSpy's use of advanced techniques like DLL side-loading and its focus on sensitive government and corporate data emphasize the group's capability and persistence. The ability to deploy various plugins for system information and password gathering underscores the potential for significant data breaches and operational disruption.
Several Small Indian Banks Offline Due to Ransomware Attack
What happened: A ransomware attack reportedly affected the payment systems of about 300 small Indian banks, forcing them to shut down temporarily. The targeted company, C-Edge Technologies, is a banking technology solutions provider catering to the affected banks.
Why it matters: Even though the ransomware attack targeted small banks in the country, impacting only about 0.5 percent of India's payment system volumes, the effects on impacted customers can be significant. In such attacks, customers likely lose access to their accounts, face difficulties completing transactions, and experience delays in payroll deposits or bill payments. It can lead to financial distress, especially for those living paycheck to paycheck. Additionally, personal data might be compromised, increasing the risk of identity theft and fraud. Moreover, if the adversary successfully encrypts the exfiltrated data, it can use sensitive information, including personally identifiable information (PII), for further malicious attacks, like spear phishing, extortion, and financial scams. In June, the Reserve Bank of India (RBI), the Indian central bank, published an advisory regarding the cybersecurity of banks across the country because of the increased risk of cyber threats to the Indian banking sector. “Banks should immediately put in place a cyber-security policy elucidating the strategy containing an appropriate approach to combat cyber threats given the level of complexity of business and acceptable levels of risk, duly approved by their Board,” it said.
Ransomware Attack Cuts off Blood Supply to More than 200 Hospitals
Source: https://theregister.com/2024/07/31/ransomware_blood_supply_hospital/
What happened: OneBlood, a non-profit blood donation service, confirmed a ransomware attack that has forced the service to operate at a reduced capacity. Investigations have not concluded if any data was accessed or stolen, but a spokesperson confirmed that one of the fallouts of this attack could mean that OneBlood’s inventory availability is affected.
Why it matters: The attack, according to an official notification, has affected the service’s “software systems” causing it to rely on manual processes. OneBlood services around 250 hospitals. Switching to manual processes takes significantly longer to undertake and may also hinder many hospital’s capabilities in fulfilling emergency requirements. Although emergency procedures are in place, cyberattacks on healthcare facilities take on an added edge as essential patient services like blood donations may place lives at risk.
DEEP AND DARK WEB INTELLIGENCE
Telegram user “unidentified”: Pro-Russian hacktivist group named "unidentified" claimed to have carried out a cyberattack against New York City. The threat actor stated that this attack should be considered a warning to all NATO countries.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-7332: A critical vulnerability (CVSS score: 9.8) has been identified in the TOTOLINK CP450 version 4.1.0cu.747_B20191224. This vulnerability affects an unspecified section of the file /web_cste/cgi-bin/product[.]ini within the Telnet Service component. Exploiting this flaw can lead to the use of a hard-coded password, and the attack can be launched remotely.
Affected product: TOTOLINK CP450 version 4.1.0cu.747_B20191224
Tags: DIB, tlp:green