ZeroFox Cyber Intelligence Daily Brief - August 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Malicious Stealer Log Marketplace Advertised for Sale
- Threat Actor Targets Iranian Entities in Politically Motivated Attacks
- New CMoon USB Worm Targets Russians in Data Theft Attacks
ZeroFox Intelligence Flash Report - Malicious Stealer Log Marketplace Advertised for Sale
Source: https://www.zerofox.com/advisories/25125/
What happened: On July 30, 2024, user “2Easy.Shop” (which is almost certainly synonymous with the official handle of the malicious marketplace 2EasyShop) announced in a deep and dark web (DDW) forum that the stealer log marketplace is available for purchase.
Why it matters: 2EasyShop—described by the poster as a “ready-made, configured, highly profitable business”—is a DDW marketplace that specializes in advertising and selling stealer logs, which are compilations of information that have been stolen from devices and networks infected with malware. Given the very likely growing demand among various types of cyber threat actors for the information contained within stealer logs, it is likely that a sale will take place. If the auction fails, there is a roughly even chance that the site will remain closed until a sale occurs. A successful deal at the asking price would very likely reinvigorate 2EasyShop, resulting in more reliable service, an increased supply of logs, and higher volume of sales that almost certainly pose a threat to individuals and organizations.
Threat Actor Targets Iranian Entities in Politically Motivated Attacks
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/68100
What happened: Threat actor group Anonymous KSA claimed to have compromised the Iranian Foreign Ministry's service distributor and Iran's military and civil aviation data. The leaked data allegedly includes IP addresses, names, and personnel movements.
Why it matters: Anonymous KSA cited the attack on the Iranian entities as a “response to the negative Iranian position towards the assassination of Haniyeh from within Iran.” The leaked data will likely attract the attention of more actors with the same political motivations to target affected individuals in malicious attacks. It can also incite politically opposed threat actors to retaliate. Anonymous KSA group has previously targeted several entities in Saudi Arabia, driven by its political inclination towards the pro-Palestinian cause. Tensions between Israel and Iran have further escalated since the deaths of Hamas’ political chief Ismail Haniyeh and a senior Hezbollah official, Fuad Shukr, amid the ongoing Israel-Hamas war. These conflicts continue to have repercussions in the cyber world, with various politically inclined actors declaring their support for either side and conducting attacks to further their agenda.
New CMoon USB Worm Targets Russians in Data Theft Attacks
What happened: A new worm is reportedly being distributed in Russia, which can steal account credentials and other data. This worm is a type of malware dubbed CMoon, which was reportedly introduced via a compromised gas supply company website. This worm can load additional payloads, capture screenshots, and launch DDoS attacks.
Why it matters: Researchers have not yet observed evidence of this malware being distributed anywhere else, which indicates that the perpetrator may have been targeting only specific Russian users who click on the website and try to download its documents. The document links contained malicious executables that started the infection chain. The company has been notified and the download links and files have been taken down; however, researchers suspect the malware to have self-propagating capabilities that can allow it to continue infecting other devices. The worm disguises itself in an infected device by impersonating a file to avoid detection and begins exfiltrating any data it finds when USB drives are connected.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user “GlorySec”: Threat actor group GlorySec claims to have attacked Partido Comunista de Venezuela (Communist Party of Venezuela). The group also warned: "If the account is taken back or rolled back we will leak it and hit your accounts harder, will even delete them."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-4885: This critical (CVSS score: 9.8) unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold lets unauthorized attackers execute commands with the privileges of the 'iisapppool\nmconsole' user. Threat actors are trying to exploit this fixed bug.
Affected products: Progress WhatsUp Gold versions released before 2023.1.3
Tags: DIB, tlp:green