zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 19, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackers
  • Europol Takes Down Criminal Communication Platform Ghost
  • Vanilla Tempest Hackers Hit Healthcare with INC Ransomware

U.S. Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackers

Source: https://www.justice.gov/usao-wdpa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state

What happened: The U.S. Department of Justice (DOJ) announced the successful disruption of a botnet comprising over 200,000 consumer devices, which were infected by state-sponsored hackers from the People’s Republic of China, operating through a company known as Integrity Technology Group. The operation targeted various devices, including small-office/home-office (SOHO) routers, internet protocol (IP) cameras, digital video recorders (DVRs), and network-attached storage (NAS) devices, allowing the hackers to conduct malicious cyber activities disguised as normal internet traffic.

Why it matters: This disruption reveals the ongoing threat from state-sponsored cyber actors, particularly from China, who exploit consumer devices for large-scale malicious activities. The malware linked thousands of infected devices into a botnet controlled by Integrity Technology Group, enabling harmful actions disguised as normal internet traffic. If successful, these attacks could allow hackers to launch attacks on other networks or steal sensitive information, leading to compromised personal data and degraded device performance. The FBI conducted a court-authorized operation that took control of the hackers' infrastructure and issued disabling commands to the malware, despite a failed DDoS attack aimed at disrupting these efforts. By disrupting the botnet, law enforcement not only reduced immediate risks but also demonstrated international cooperation among cybersecurity agencies. The advisory on Integrity Technology Group's tactics aims to improve global awareness and defense against similar threats, emphasizing the importance of cybersecurity for personal and national protection.

Europol Takes Down Criminal Communication Platform Ghost

Source: https://www.europol.europa.eu/media-press/newsroom/news/global-coalition-takes-down-new-criminal-communication-platform

What happened: Europol, Australian Federal Police (AFP), and global law enforcement agencies have shut down Ghost, an encrypted communication platform used by criminal networks worldwide, and arrested an individual accused of creating and managing the platform. Ghost enabled large-scale drug trafficking, money laundering, and violent crimes.

Why it matters: The AFP infiltrated Ghost and tampered with regular software updates sent by the administrator, effectively planting malware that allowed it to access and monitor the content on the devices in Australia. Information from this led to raids across four Australian states, resulting in 38 arrests, seizure of weapons, and prevention of drug distribution. The operation, named "Kraken," revealed that criminals, including organized crime groups, were using Ghost to coordinate serious illegal activities like importing drugs and ordering murders. Cyber threat actors and other malicious criminals often leverage seemingly secure and encrypted channels, like the one Ghost provided, to communicate and coordinate illegal activities without fear of detection. The dismantling of Ghost is, therefore, a major blow to organized crime, operating on a global scale.

Vanilla Tempest Hackers Hit Healthcare with INC Ransomware

Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-vanilla-tempest-hackers-hit-healthcare-with-inc-ransomware/

What happened: Researchers have identified that the threat group Vanilla Tempest deployed INC ransomware for the first time in an attack targeting the U.S. healthcare sector. This attack disrupted the healthcare provider's IT and phone systems, leading to a loss of access to critical patient information databases. In response, the healthcare system was forced to reschedule appointments and non-emergent procedures to mitigate further risks.

Why it matters: INC ransomware’s use in high-profile attacks highlights the growing danger of ransomware-as-a-service (RaaS) operations. The availability of ransomware source code for sale on dark web forums means more cybercriminals can potentially access these powerful tools, increasing the frequency and severity of attacks. The targeting of critical sectors such as healthcare, education, and manufacturing by threat actors like Vanilla Tempest poses a direct threat to national security. Cyberattacks on healthcare impact both patient safety and the functioning of vital services. Although the threat actor has not made any ransom demands that are publicly known at the time of writing, ransomware attacks have significant financial repercussions. The disruption of services can cost millions in lost revenue as healthcare institutions are often forced to give in to these demands to have their systems running to treat patients that are often reliant on digital devices and digital services like electronic health records.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user Sorb: Threat actor "Sorb" claimed to have leaked a database associated with Bharat Petroleum Corporation on predominantly English-language dark web forum BreachForums. Allegedly, the leaked database contains 148 million rows of personal data, including phone numbers, names, delivery addresses, payment information, and order lists.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-45409: GitLab released security updates for this critical SAML authentication bypass vulnerability, affecting self-managed GitLab CE and EE, caused by issues in OmniAuth-SAML and Ruby-SAML libraries.

  • Affected products: GitLab versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, and 16.11.10

Tags: DIB, tlp:green