ZeroFox Cyber Intelligence Daily Brief - August 31, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 31, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Advisory on RansomHub Ransomware
- Secret Service and FBI Collaboration Places USD 2.5 Million Bounty on information on Prolific Cyber Criminal
- Brain Cipher Claims Attack on Olympic Venue, Promises 300 GB Data Leak
CISA and Partners Release Advisory on RansomHub Ransomware
What happened: CISA and partners have released a joint advisory detailing the indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with RansomHub activity identified through FBI investigations and third-party reporting. RansomHub is a ransomware-as-a-service variant—formerly known as Cyclops and Knight—which has recently attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV.
Why it matters: Since its inception in February 2024, RansomHub has encrypted and exfiltrated data from at least 210 victims representing the water and wastewater, information technology, government services, and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications critical infrastructure sectors. The affiliates leverage a double-extortion model by encrypting systems and exfiltrating data to extort victims. It should be noted that data exfiltration methods depend on the affiliate conducting the network compromise. The ransom note dropped during encryption gives victims three to 90 days to pay the ransom (depending on the affiliate) before the ransomware group publishes their data on the RansomHub Tor data leak site.
Secret Service and FBI Collaboration Places USD 2.5 Million Bounty on information on Prolific Cyber Criminal
Source: https://www.secretservice.gov/investigations/mostwanted/kadariya
What happened: The Secret Service, along with the U.S. Department of State, has announced a reward of up to USD 2.5 million for information instrumental in arresting or convicting a Belarusian national suspected of several cybercrimes. The individual is reportedly involved in a decade-long malvertising scheme that deployed malware via online ads, compromising millions of devices.
Why it matters: This individual is suspected of being involved in a decade-long cybercrime operation that has inflicted widespread harm on millions of unsuspecting users. By deploying the Angler Exploit Kit and other malware through seemingly legitimate online advertisements, the individual and his collaborators have compromised countless devices, leading to financial losses, data breaches, and the unauthorized access and control of personal information. Their malvertising campaigns not only defrauded individuals but also likely contributed to a broader ecosystem of cybercrime, selling access to compromised devices and stolen data on cybercriminal forums.
Brain Cipher Claims Attack on Olympic Venue, Promises 300 GB Data Leak
Source: https://www.theregister.com/2024/08/29/brain_cipher_olympic_attack/
What happened: The Brain Cipher ransomware group has reportedly claimed responsibility for a cyberattack on French national museums that occurred during the Olympic Games. The group announced that they will leak 300 GB of stolen data soon. It was reported at the time that the central computer system, which also oversees data for 40 smaller museums, was targeted but no disruption to the Olympic events occurred. Why it matters: The potential release of 300 GB of data could have serious implications for French national museums at large. This data might contain sensitive information, risking privacy breaches and operational disruptions for these institutions. However, the ransomware group’s leak site is currently down, and the supposed 300 GB of data has not been released at the time of writing. The leak site being down introduces uncertainty, presenting a roughly even chance of potential damage: the data could still be released, or the claims might be a hoax. Contingency plans should be in place for both scenarios—whether dealing with a data breach or fraud — to minimize impact and protect sensitive information.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user HikkI-Chan: The threat actor known as "HikkI-Chan" claimed to have leaked data from the Israel Police on the predominantly English-language dark web forum BreachForums. The actor claimed to have breached Israel police in August 2024. The leaked data reportedly includes ID numbers, first names, last names, genders, phone numbers, email addresses, home addresses, and more. The threat actor did not disclose the source of the breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-8016: The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object.
Affected products: WordPressEvents Calendar Pro plugin
Tags: DIB, tlp:green