zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. to Seek Information on “Hacktivist” Cyber Av3ngers-Led ICS Attack
  • U.S. DoJ Disrupts North Korean Remote IT Worker Fraud Schemes Through Charges and Arrest of Nashville Facilitator
  • Royal Ransomware Actors Rebrand as “BlackSuit,” FBI and CISA Release Update to Advisory

U.S. to Seek Information on “Hacktivist” Cyber Av3ngers-Led ICS Attack

Source: https://www.securityweek.com/us-offering-10-million-reward-for-iranian-ics-hackers/

What happened: The United States is offering USD 10 million as a reward in exchange for information on senior officials of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) accused of attacking industrial control systems (ICS). These officials are supposedly the brains behind Cyber Av3ngers, a threat group that claims to be a hacktivist group.

Why it matters: A Cyber Av3ngers member is allegedly the head of the IRGC-CEC and has previously been involved in various IRGC cyber and intelligence operations. The group is thus believed to be working on behalf of the IRGC, even though it claims to be engaged in hacktivism. Additionally, Cyber Av3ngers declared its pro-Palestinian political stance when it claimed to have conducted cyberattacks leading to mass power outages across Israel. IRGC-CEC has also been attributed to several other malicious cyber activities targeting critical infrastructure and about a dozen U.S. organizations. As tensions in the Middle East grow, more IRGC-CEC cyber operations will likely target entities in the United States as well as in countries that are politically opposed to Iran.

U.S. DoJ Disrupts North Korean Remote IT Worker Fraud Schemes Through Charges and Arrest of Nashville Facilitator

Source: https://www.justice.gov/opa/pr/justice-department-disrupts-north-korean-remote-it-worker-fraud-schemes-through-charges-and

What happened: A U.S. resident was recently arrested by the Department of Justice (DoJ) for orchestrating a scheme to generate revenue for Democratic People’s Republic of Korea’s (DPRK or North Korea) illicit weapons program. This scheme involved using stolen identities to obtain remote IT jobs with American and British companies, where the workers were actually North Korean operatives.

Why it matters: This success would likely encourage further exploitation of global IT labor markets, leading to increased cyber deception, broader identity theft, and financial harm to more businesses worldwide. North Korea has deployed thousands of IT workers to China and Russia to pose as freelance IT professionals for global businesses. This scheme, which funds North Korea's weapons programs, involves creating fake online identities, using false websites, and employing intermediaries to facilitate their activities. This incident reveals how North Korea exploits global IT labor markets to fund its weapons of mass destruction (WMD) programs through cyber deception. North Korea could have significantly accelerated its WMD programs, leveraging illicit funds to enhance its capabilities while bypassing international sanctions.

Royal Ransomware Actors Rebrand as “BlackSuit,” FBI and CISA Release Update to Advisory

Source: https://www.cisa.gov/news-events/alerts/2024/08/07/royal-ransomware-actors-rebrand-blacksuit-fbi-and-cisa-release-update-advisory

What happened: CISA has released #StopRansomware: BlackSuit (Royal) Ransomware advisory that provides network defenders with recent and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IoCs) associated with BlackSuit and legacy Royal activity.

Why it matters: BlackSuit ransomware attacks have spread across numerous critical infrastructure sectors including, but not limited to, commercial facilities, healthcare and public health, government facilities, and critical manufacturing. The threat actor conducts data exfiltration and extortion prior to encryption and then publishes victim data to a leak site if a ransom is not paid. Phishing emails are among the most successful vectors for initial access by BlackSuit threat actors. After gaining access to victims’ networks, BlackSuit actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting the systems.

DEEP AND DARK WEB INTELLIGENCE

  • Threat actor group STUXNET: Pro-Palestine threat actor group STUXNET claimed to have leaked a user database associated with Assurified, a U.S.-based company specializing in commercial real estate risk management. The leaked database contains 101,372 rows of user data, including names, cities, phone numbers, emails, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • Small Business Zero-Day Bugs: Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an attacker to execute arbitrary commands on the underlying operating system or cause a denial of service (DoS) condition.

  • Affected products: All software releases that run on Cisco Small Business SPA300 Series and Cisco Small Business SPA500 Series IP Phone

  • CVE-2024-4304: This bug allows agent processes to read arbitrary files from the Jenkins controller file system by using the ClassLoaderProxy#fetchJar method in the Remoting library.

  • Affected products: Jenkins 2.470 and earlier; LTS 2.452.3 and earlier

Tags: DIB, tlp:green