ZeroFox Cyber Intelligence Daily Brief - August 23, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 23, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Best Practices for Event Logging and Threat Detection
- U.S. Oilfield Firm Halliburton Hit by Cyberattack
- Karakurt Ransomware Negotiator Arrested and Extradited to the United States
CISA and Partners Release Best Practices for Event Logging and Threat Detection
What happened: The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), CISA, FBI, NSA, and international partners have released Best Practices for Event Logging and Threat Detection. This guide will assist organizations in defining a baseline for event logging to mitigate malicious cyber threats.
Why it matters: The increased prevalence of malicious actors employing living off the land (LOTL) techniques, such as living off the land binaries (LOLBins) and fileless malware, highlights the importance of implementing and maintaining an effective event logging program. CISA encourages public and private sector senior information technology (IT) decision makers, operational technology (OT) operators, network administrators, network operators, and critical infrastructure organizations to review the best practices in the guide and implement recommended actions. These actions can help detect malicious activity, behavioral anomalies, and compromised networks, devices, or accounts.
U.S. Oilfield Firm Halliburton Hit by Cyberattack
What happened: Halliburton has reportedly been targeted in a cyberattack that disrupted some business operations and global networks. Employees are being advised to disconnect from the network as investigations are underway.
Why it matters: At the time of writing, the company has not confirmed if this “issue” is caused by a cyberattack and said that investigations are underway. However, media sources speculate that it could possibly be a ransomware attack. An unnamed person familiar with this incident has affirmed to news sources that a cyberattack is responsible for this compromise. Critical infrastructure has been greatly susceptible to such attacks given the significant connectivity between operational technology and networks. Such operations, since they provide critical services to people, are also observed to give in to ransom demands more so that they can have their operations running immediately.
Karakurt Ransomware Negotiator Arrested and Extradited to the United States
What happened: A Latvian national has been charged in the United States with money laundering, wire fraud, and extortion as a member of the Russian Karakurt ransomware group. The individual, arrested in Georgia in December 2023 and extradited to the United States earlier this month, negotiated ransoms for Karakurt, which extorted U.S. companies by threatening to leak stolen data.
Why it matters: This arrest marks the first apprehension of a Karakurt member. The group is notorious for focusing on data theft and extortion without using encryption tools. Karakurt, which emerged as an extension of the now-dismantled Conti syndicate, claimed to steal data and threatened to auction it off or release it to the public unless they received payment of the demanded ransom. Known ransom demands have ranged from USD 25,000 to USD 13,000,000 in BTC, with payment deadlines typically set to expire within a week of first contact with the victim. The FBI linked the arrested individual to at least six extortion cases. The arrest could pave the way for further takedowns within the Karakurt group, potentially dismantling the broader cybercrime network, disrupting its extortion activities, and preventing additional attacks on U.S. businesses.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user suspect: Threat actor “suspect” has claimed to have leaked a database associated with Flipkart, an India-based e-commerce company on the predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-6079: A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack.
Affected products: Rockwell Automation Emulate3D™
CVE-2024-39776: Avtec Outpost stores sensitive information in an insecure location without proper access controls in place. Successful exploitation of this vulnerability could allow an attacker to gain administrative privileges on the affected devices.
Affected products: Outpost 0810: Versions prior to v5.0.0, Outpost Uploader Utility: Versions prior to v5.0.0
Tags: DIB, tlp:green