ZeroFox Cyber Intelligence Daily Brief - September 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CosmicBeetle Ransomware Gang Utilizes RansomHub Malware in Recent Attacks
- Chinese APT Deploys Malware on APAC Government Entities via USB Devices
- Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia
CosmicBeetle Ransomware Gang Utilizes RansomHub Malware in Recent Attacks
What happened: Recent activities of the NoName ransomware gang (also known as CosmicBeetle) suggest a possible affiliation with RansomHub. In a recent attack, the group leveraged RansomHub’s EDR killer to disable security measures on a compromised machine—following a failed deployment of ScRansom (a Delphi-based file-encrypting malware). Shortly after, the group executed RansomHub’s ransomware on the same system.
Why it matters: The evolution of the NoName gang's toolset reflects a strategic move to enhance effectiveness and reputation in the ransomware landscape. The use of RansomHub's EDR killer tool, combined with the adoption of new tactics, demonstrates their adaptability and determination to overcome security defenses. The potential affiliation with RansomHub and the ongoing development of ScRansom indicate that NoName continues to be a significant and evolving threat to businesses. The RansomHub ransomware group has been known to target critical infrastructure worldwide. The potential affiliation between NoName and RansomHub could enhance their combined capabilities, resulting in more severe and disruptive attacks on organizations. This partnership might lead to significant disruptions in essential services and considerable financial damage.
Chinese APT Deploys Malware on APAC Government Entities via USB Devices
Source: https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack
What happened: A state-sponsored Chinese advanced persistent threat (APT) group, Mustang Panda (Earth Preta, HoneyMyte, Bronze President, and Red Lich), has resumed operations, distributing new self-propagating malware via USB drives and spear-phishing campaigns to target government entities in the Asia-Pacific (APAC) region. The group delivers tools for system control and data theft, deploying the HIUPAN worm to spread PUBLOAD malware and multistage downloaders for further compromise.
Why it matters: Using self-propagating malware via USB drives and evolving spear-phishing tactics makes these attacks harder to detect, giving attackers the advantage of rapid infiltration and data exfiltration. Moreover, the group's collaboration with other actors hints at a larger, coordinated espionage effort. Besides, compromising key government sectors—including the military, police, foreign affairs, and other government organizations— reflects the allure of sensitive, confidential information for adversarial states. Chinese-state-sponsored actors, like Mustang Panda, have a very likely political motivation behind conducting such intel-gathering operations, aiding Chinese geopolitical strategies. The group also targeted Taiwanese, Malaysian, and Vietnamese government entities in February this year in a backdoor distribution campaign, further suggesting the political motivations of the group. Such increasingly sophisticated and persistent state-sponsored cyberattacks are likely designed to bolster influence and gain a strategic upper hand over rival states.
Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia
Source: https://thehackernews.com/2024/09/experts-identify-3-chinese-linked.html
What happened: The Crimson Palace espionage campaign, linked to China, has expanded its operations across Southeast Asia, targeting more government organizations in the region. This cluster of state-sponsored intrusion sets involves three threat activity clusters, using compromised public service and organizational networks to deliver malware and tools disguised as trusted access points.
Why it matters: The Crimson Palace campaign is observed to involve targeting entities with multi-cluster attacks, which allows Chinese state-sponsored actors to infiltrate and remain undetected in sensitive government systems. This method enables attackers to infiltrate sensitive government systems undetected, increasing the reach and impact of their espionage activities while deepening their hold in Southeast Asian nations. By using compromised organizational networks as command and control (C2) relay points and leveraging tools, attackers can stage longer and more covert operations. This allows the threat actors to steal sensitive government data, manipulate public service networks, and have a likely influence on geopolitical outcomes in Southeast Asian nations where these operations are focused. The potential for long-term access and data exfiltration poses significant national security risks for the targeted countries.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user Grep: Threat actor group Grep claimed to be selling a database associated with Capgemini, a France-based information technology company, on the predominantly English-language dark web forum BreachForums. Allegedly, Capgemini suffered a data breach this month that exposed 20 GB of data, including database information, source code, private keys, credentials, employee data, T-Mobile's virtual machine logs, and more. The threat actor claimed to have accessed additional data but chose to exfiltrate only large files, company confidential information, and Terraform data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-29847: It is a security vulnerability (CVSS score 10) affecting Ivanti EPM versions prior to 2022 SU6 or the September 2024 update. This flaw arises from the deserialization of untrusted data in the agent portal, enabling a remote unauthenticated attacker to execute arbitrary code remotely. This critical vulnerability has been patched.
Affected products: Ivanti Endpoint Manager versions 2024, and 2022 SU5 and earlier
CVE-2024-38226: In this month’s Patch Tuesday updates, Microsoft addressed 79 vulnerabilities, but attackers are already actively exploiting four of them. Among these is CVE-2024-38226, a zero-day security bypass affecting Microsoft Publisher. This vulnerability allows an attacker with authenticated access to circumvent Microsoft Office macros designed to block untrusted and malicious files.
Affected products: The affected products and versions have been listed by Microsoft in this security update.
Tags: DIB, tlp:green