zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 25, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 25, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory
  • FBI Highlights Safety Measures to Safeguard U.S. Critical Food Infrastructure
  • 240 GB of Data Stolen from Toyota Allegedly Leaked by Threat Actors

ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory

What happened: The ransomware-as-a-service (RaaS) operation “RansomHub” has almost certainly significantly increased its operational tempo in recent weeks, having conducted more attacks so far in Q3 2024 than in Q1 and Q2 2024 combined. RansomHub was first observed in approximately February 2024 and exhibited a higher tempo of attacks during those initial weeks than is usually observed from new ransomware operations. Why it matters: RansomHub’s activity as a proportion of all ransomware activity observed by ZeroFox is also on a sharp upward trajectory, with the group accounting for approximately 2 percent of all attacks in Q1, 5.1 percent in Q2, and 14.2 percent so far in Q3. There is a likely chance that RansomHub will remain the most prominent ransomware collective for the coming months and continue to attract affiliates. The collective will almost certainly continue to target a highly diverse array of sectors, and the proportion of attacks targeting organizations located in North America will very likely increase.

FBI Highlights Safety Measures to Safeguard U.S. Critical Food Infrastructure

What happened: FBI’s second annual Agriculture Threats Symposium in Omaha, Nebraska, focused on rising cyber threats to the U.S. agriculture sector, including ransomware attacks, intellectual property theft, and bioterrorism, exacerbated by increased digital connectivity in farming operations. Over 400 farmers, cybersecurity experts, and policymakers from 30 states attended the symposium. Why it matters: The FBI is monitoring four major threats to the nation’s agriculture sector, which—like water, power, and transportation—is considered part of the nation’s critical infrastructure. The agriculture sector, integral to national security, is increasingly vulnerable due to its reliance on digital technologies. As foreign adversaries, particularly China, target this critical infrastructure, the potential impact extends beyond farms to the broader economy. Any disruption in the agricultural sector to any degree affects rural life in the country because of the dependency on this critical sector. Examples of imminent cyber threats mentioned in the symposium included ransomware attacks that cripple operations, network hacks that take control of systems, and the theft of seeds worth millions of dollars in intellectual property and research. Additionally, the symposium highlighted the urgency for stronger partnerships between the public and private sectors to bolster cybersecurity defenses.

240 GB of Data Stolen from Toyota Allegedly Leaked by Threat Actors

What happened: Threat actor group ZeroSevenGroup claimed to have conducted a cyberattack against Toyota’s U.S. branch. The breached data included details on Toyota employees, customers, contracts, and financial records. Toyota has confirmed a network breach following the release of 240 GB of stolen data on a hacking forum. Why it matters: This breach exposes a wide range of sensitive information, including contact details, financial records, customer data, employee records, photos, databases, network infrastructure, and emails, potentially impacting numerous individuals and business operations. The attackers also claimed to use the ADRecon tool (extracts extensive information from Active Directory environments) to gather network infrastructure details and credentials, potentially gaining deep insight into Toyota's network and security. This could lead to increased risk of further attacks and misuse of the stolen credentials. Toyota has not yet disclosed when the breach was detected, how the attacker gained access, or the extent of data exposure.

Tags: DIB, tlp:green