zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI, CISA, NSA, and US and International Partners Release Advisory on Russian Military Cyber Actors Targeting US and Global Critical Infrastructure
  • Sponsored Online Ads Phish Lowe’s Employees
  • Fake OnlyFans Checker Tool Infects Hackers with Lummac Stealer Malware

FBI, CISA, NSA, and US and International Partners Release Advisory on Russian Military Cyber Actors Targeting US and Global Critical Infrastructure

Source: https://www.cisa.gov/news-events/alerts/2024/09/05/fbi-cisa-nsa-and-us-and-international-partners-release-advisory-russian-military-cyber-actors

What happened: The Federal Bureau of Investigation (FBI)—in partnership with CISA, and other partners—released a joint cybersecurity advisory about Russian military cyber actors targeting U.S. and global critical infrastructure. This advisory provides overlapping cybersecurity industry cyber threat intelligence, tactics, techniques, and procedures (TTPs) and indicators of compromise (IoC) associated with Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) cyber actors, both during and succeeding their deployment of the WhisperGate malware against Ukraine.

Why it matters: The advisory assesses that the cyber actors have been responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as 2022. To mitigate such malicious cyber activity, organizations should prioritize routine system updates and remediate known exploited vulnerabilities, segment networks to prevent the spread of malicious activity, enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially for webmail, virtual private networks (VPNs), and accounts that access critical systems.

Sponsored Online Ads Phish Lowe’s Employees

Source: https://www.darkreading.com/threat-intelligence/malvertising-campaign-phish-lowes-employees

What happened: A phishing campaign targeted Lowe’s employees through malicious websites—promoted via digital ads sponsored via a popular web browser—mimicking their internal portal. Fake websites, appearing as some of the top search results, re-directed employees to fake login pages that stole their account numbers, passwords, and answers to security questions. The phishing sites used AI-generated templates to avoid detection, complicating efforts to remove them.

Why it matters: The malvertising operation exploits user trust in search engines, especially through sponsored ads, to steal credentials from unsuspecting employees. AI-generated sites, which mimic authentic websites, not only lured employees into thinking those were legitimate sites but also bypassed traditional detection methods used by search engines. Once the attackers accessed an employee’s account, they stole personal data, which they are likely to use to commit identity theft or manipulate company resources. Malicious actors are also likely to target victims with spear phishing, further extortion attacks, and blackmail. Additionally, they might abuse access to employee accounts and systems to install malware, leading to far-reaching repercussions like ransomware infections.

Fake OnlyFans Checker Tool Infects Hackers with Lummac Stealer Malware

Source: https://hackread.com/onlyfans-checker-tool-hackers-lummac-stealer-malware/

What happened: Cybersecurity experts have observed a malicious campaign involving the Lummac Stealer, a malware disguised as an OnlyFans "Checker" tool, targeting hackers. The campaign lures cybercriminals into downloading the Checker tool, which can reportedly be used to exploit OnlyFans accounts. The tool can infect systems with Lummac Stealer, also known as LummaC2.

Why it matters: Lummac Stealer malware disguised as an OnlyFans "Checker" tool is significant due to the rising popularity of OnlyFans accounts as targets for cybercriminals. Threat actors often aim to hijack these accounts to steal fan payments, extort content creators, or leak private photos. Checker tools are commonly used by hackers to validate stolen login credentials for platforms like OnlyFans, helping them identify active accounts for exploitation. Lummac Stealer’s advanced capabilities, including the ability to bypass two-factor authentication, steal cryptocurrency wallets, and retrieve expired session tokens, make it a highly dangerous tool. Its ability to target sensitive data such as passwords, cookies, and credit card details stored in browsers adds to the potential damage it can cause. This incident not only reveals the risks involved in illicit cyber activities but also shows that malware, such as this one, is becoming increasingly sophisticated and harder to sidestep.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user HikkI-Chan: Threat actor HikkI-Chan claimed to be selling a database associated with Fleet Management, a UAE-based transport management solution on the predominantly English-language dark web forum, “BreachForums." Allegedly, the leaked database contains 25,000 user records that include user ID, customer ID, first name, last name, email address, password (hashed and plain text), verification status, country code, and more. The threat actor claimed to have breached the data in September, 2024. The threat actors did not disclose the ultimate source of the data breach or how it was exploited.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-40711: This vulnerability is a critical (CVSS v3.1 score: 9.8) remote code execution (RCE) vulnerability on Veeam Backup & Replication (VBR) that can be exploited without authentication.

Affected products: Veeam Backup & Replication 12.1.2.172 and all earlier versions of the 12 branch

Tags: DIB, tlp:green