zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 26, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Key Money Launderer for North Korean Hacking Group Arrested in Argentina
  • Constantly Evolving MoonPeak RAT Linked to North Korean Spying Group
  • Indian Police Arrests Two People in USD 21 Million Mule-Account Scam

Key Money Launderer for North Korean Hacking Group Arrested in Argentina

Source: https://www.bleepingcomputer.com/news/legal/russian-laundering-millions-for-lazarus-hackers-arrested-in-argentina/

What happened: An individual was arrested in Buenos Aires by the Argentine federal police for laundering cryptocurrency linked to North Korean Lazarus hackers. The suspect processed stolen cryptocurrency through a complex network of exchanges and tumblers, converting it into fiat currency.

Why it matters: The arrested individual, who was handling approximately USD 10 million, was using a complex network of transactions, spanning multiple blockchains. They accepted large sums of cryptocurrency payments from various groups, including the notorious Lazarus group, financiers of terrorism, and distributors of child-abuse content. The arrest dismantles a crucial money-laundering operation tied to some of the most significant crypto heists in recent history. However, emerging reports suggest that the Lazarus group is pivoting to using a new crypto tumbler service named YoMix for its laundering operations. On the other hand, the seized assets and electronic devices may lead to further revelations about the global networks supporting major cybercriminal enterprises, potentially leading to more arrests and asset recoveries.

Constantly Evolving MoonPeak RAT Linked to North Korean Spying Group

Source: https://www.darkreading.com/cyberattacks-data-breaches/constantly-evolving-moonpeak-rat-linked-to-north-korean-spying

What happened: A new variant of the open-source XenoRAT malware, dubbed MoonPeak, is being distributed by a North Korean-affiliated threat actor group potentially linked to Kimsuky. This variant incorporates sophisticated techniques and a complex infrastructure, making it challenging to detect.

Why it matters: MoonPeak's development, involving frequent updates and modifications to the original XenoRAT code, complicates detection and defense strategies. Its modifications enhance its ability to evade detection and target specific systems, underscoring the growing sophistication of cyber-espionage tools. The evolving nature of the malware suggests that threat actors might continue refining their tactics to exploit new vulnerabilities or evade advanced security measures, potentially increasing the risk to sensitive information and critical infrastructure. This variant shows significant overlap with the Kimsuky group’s tactics and infrastructure, indicating the continued threat posed by state-backed actors in the cyber domain.

Indian Police Arrests Two People in USD 21 Million Mule-Account Scam

Source: https://www.financialexpress.com/india-news/telangana-cyber-security-bureau-arrests-two-in-rs-175-crore-scam-committed-using-mule-accounts/3591875/

What happened: The Cyber Security Bureau of the Indian state of Telangana arrested two individuals in Hyderabad related to a INR 175 crore (approx USD 21 million) scam involving fraudulent transactions through six bank accounts. The case was filed under the IT Act and BNS (Bharatiya Nyaya Sanhita), following an investigation into complaints on the National Cybercrime Reporting Portal (NCRP).

Why it matters: Cybercriminals exploit mule accounts to execute large-scale financial scams, such as the USD 21 million fraud uncovered by Telangana Cyber Security Bureau. Mule accounts, which are often held by unwitting individuals or compromised accounts, serve as intermediaries to facilitate the transfer and laundering of illicit funds. By using these accounts, threat actors can quickly and covertly move substantial sums of money, making detection and tracing difficult. As these schemes become more sophisticated, the volume of money moved through such accounts has surged, leading to significant financial losses for victims.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user grep: Threat actor grep claimed to have leaked a database associated with Concentración Deportiva de Pichincha, a South America-based sports school on the predominantly English-language dark web forum, BreachForums. The actor noted that Concentración Deportiva de Pichincha suffered a data breach this month that exposed 700k rows of users’ data. The leaked database includes IDs, email addresses, full names, password hashes, addresses, phone numbers, parents PIIs, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-39717: The Versa Director GUI contains an unrestricted upload of dangerous type files vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface.

Affected products:

  • Versa Director GUI versions from 21.2.2 through 21.2.2
  • Versa Director GUI versions from 21.2.3 before 2024-06-21 before 21.2.3 before 2024-06-21,
  • Versa Director GUI versions from 22.1.1 through 22.1.1
  • Versa Director GUI versions from 22.1.2 before 2024-06-21 through 22.1.2 before 2024-06-21
  • Versa Director GUI versions from 22.1.3 before 2024-06-21 through 22.1.3 before 2024-06-21

Tags: DIB, tlp:green