zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Law Enforcement Disrupts Dispossessor’s Ransomware Operations
  • South Korea Says North Korea Hackers Stole Spy Plane Technical Data
  • CERT-UA: Hackers Posing as SSU Distribute Malware Among Government Bodies in Ukraine

Law Enforcement Disrupts Dispossessor’s Ransomware Operations

Source: https://www.fbi.gov/contact-us/field-offices/cleveland/news/international-investigation-leads-to-shutdown-of-ransomware-group

What happened: A law-enforcement operation has disrupted operations of ransomware group Dispossessor (alias Radar) by dismantling three U.S. servers, three United Kingdom servers, 18 German servers, eight U.S.-based criminal domains, and one German-based criminal domain.

Why it matters: Dispossessor developed into an impactful operation targeting small-to-mid-sized businesses and organizations from the production, development, education, healthcare, financial services, and transportation sectors. Investigations revealed 43 companies as victims of Dispossessor, from countries including Argentina, Australia, Belgium, Brazil, Honduras, India, Canada, Croatia, Peru, Poland, the United Kingdom, the United Arab Emirates, and Germany. By taking down servers and domains across multiple countries, authorities have shut down the Dispossessor operations, potentially preventing further attacks and protecting sensitive data. Ransomware has become one of the greatest cyber threats to the digital world, with alarming statistics. Ransomware attacks have also been known to have tangible effects, including shutting down crucial systems. The recent takedowns of infamous ransomware groups LockBit and Blackcat, besides Dispossessor, indicate dedicated efforts to combat this threat.

South Korea Says North Korea Hackers Stole Spy Plane Technical Data

Source: https://www.bleepingcomputer.com/news/security/south-korea-says-dprk-hackers-stole-spy-plane-technical-data/

What happened: South Korea’s People Power Party (PPP) has called for additional security measures to strengthen national security after reports of North Korea stealing key information about certain spy planes. Reportedly, a South Korean defense contractor that produces manuals for military equipment including the two spy planes was hacked, endangering details about technology, upgrades, operation capabilities, and other data.

Why it matters: The PPP has called for a revision of existing criminal law to include foreign countries in the application of its espionage laws. The leaks of South Korea’s military secrets puts the country in a weak position in its defense against other entities while North Korea may have a greater advantage on the battlefield. It is worth noting that in the past South Korea observed several breaches into defense companies allegedly conducted by North Korea-linked threat actors like Lazarus, Andariel, and Kimsuky. South Korea’s companies have been under threat at least since 2022, according to South Korea’s National Police Agency. These breaches have reportedly occurred thanks to weak network protection as well as inadequate security precautions like reusing passwords, making it vital for South Korea to invest in mechanisms to not only better track suspicious cyber activities but also anticipate and identify DPRK’s cyberattacks as they happen.

CERT-UA: Hackers Posing as SSU Distribute Malware Among Government Bodies in Ukraine

Source: https://cip.gov.ua/en/news/khakeri-rozpovsyudzhuyut-shkidlive-programne-zabezpechennya-nibito-vid-imeni-sbu

What happened: The Computer Emergency Response Team of Ukraine (CERT-UA) reported a widespread phishing campaign where attackers, masquerading as the Security Service of Ukraine (SSU), sent emails with a malicious link to download a file named "Documents[.]zip." This link triggers a process that finally installs ANONVNC malware, granting unauthorized access to the victim's computer.

Why it matters: This incident reveals a burgeoning trend of attackers masquerading as law enforcement officials and distributing malware via phishing emails to infiltrate government networks. With over 100 affected computers in the abovementioned campaign, including those in central and local government bodies, the ANONVNC malware allows stealthy, unauthorized access to sensitive systems. Given the sophisticated nature of this breach, it raises concerns that foreign actors could be involved, potentially aiming to undermine Ukraine’s security and destabilize its governmental functions. In April, CERT-UA revealed that the Russian hacker group Sandworm targeted approximately 20 critical infrastructure facilities in Ukraine. CERT-UA has advised all concerned parties to stay vigilant and promptly report any suspicious activity to them.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user IntelBroker: Well-regarded and established threat actor IntelBroker claimed to have leaked a database associated with the U.S. Bank on the predominantly English-language dark web forum BreachForums. The threat actor alleged that Kukun, a U.S.-based data and analytics company, suffered a data breach this month that led to the exposure of user information belonging to U.S. Bank. The compromised data includes usernames, first names, last names, email addresses, phone numbers, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-7589: As a result of calling functions that are not async-signal-safe in the privileged sshd(8) context, a race condition exists that a determined attacker may be able to exploit to allow an unauthenticated remote code execution as root.

  • Affected products: All supported versions of FreeBSD

  • CVE-2024-6768: When subjected to an improper validation of specified quantities within input data, this vulnerability will trigger a function known as KeBugCheckEx and result in the blue screen of death.

  • Affected products: Common Log File System (CLFS) driver

Tags: DIB, tlp:green