zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 21, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Suspects Behind USD 230 Million Cryptocurrency Theft Arrested in Miami
  • CISA Warns of Actively Exploited Apache HugeGraph-Server Bug
  • Stolen Medical Data from Indian Insurer Sold on Telegram

Suspects Behind USD 230 Million Cryptocurrency Theft Arrested in Miami

Source: https://www.justice.gov/usao-dc/pr/indictment-charges-two-230-million-cryptocurrency-scam

What happened: Two individuals suspected of stealing and laundering over USD 230 million in cryptocurrency using crypto exchanges and mixing services were arrested by the FBI. According to the indictment, since at least August 2024, the individuals and their collaborators engaged in a scheme to steal and launder cryptocurrency. They accessed victims' cryptocurrency accounts through fraudulent means, transferring the stolen funds into their control.

Why it matters: The growing value and popularity of cryptocurrencies have made them prime targets for financially motivated cybercriminals. Numerous cryptocurrency exchanges and services worldwide have experienced breaches, leading to significant financial losses and, in some cases, permanent closures. Cybercriminals employ a range of tactics to steal cryptocurrency, targeting users, exchanges, custodial services, and even underlying networks. Law enforcement activities are critical in combating cryptocurrency-related crimes, as they play a key role in addressing the growing threats posed by cybercriminals in this space. By developing advanced investigative techniques and collaborating across borders, law enforcement agencies can track and dismantle schemes using sophisticated methods, such as those deployed here to launder the stolen money using a combination of crypto mixers and exchanges, "peel chains" and pass-through wallets, and virtual private networks (VPNs).

CISA Warns of Actively Exploited Apache HugeGraph-Server Bug

Source: https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-apache-hugegraph-server-bug/

What happened: CISA has added a critical remote code execution vulnerability, CVE-2024-27348, affecting Apache HugeGraph-Server to its Known Exploited Vulnerabilities (KEV) catalog, noting that active exploitation has been observed. This flaw impacts versions from 1.0.0 up to, but not including, 1.3.0.

Why it matters: The vulnerability poses a significant risk to organizations that rely on Apache HugeGraph-Server, including telecom providers and financial services, which utilize the software for essential operations like fraud detection and risk control. With a CVSS score of 9.8, the flaw allows unauthorized access, potentially leading to severe data breaches and operational disruptions. Given the observed active exploitation and the deadline for mitigation set for October 9, 2024, it is crucial for affected users to upgrade and implement recommended security measures immediately to protect sensitive data and maintain system integrity.

Stolen Medical Data from Indian Insurer Sold on Telegram

Source: https://www.reuters.com/technology/cybersecurity/hacker-uses-telegram-chatbots-leak-data-top-indian-insurer-star-health-2024-09-20/

What happened: Cybersecurity researchers have discovered Telegram bots exposing information, including medical reports from one of the largest health insurers in India, allegedly stolen from 31 million individuals. The data includes sensitive details like names, addresses, medical diagnoses, and ID cards. Despite efforts to remove the bots, new ones have quickly appeared, exposing data from the health insurer.

Why it matters: The breach of a large-scale health insurer exposes the personal data of millions of individuals to potential misuse, from identity theft to fraud. For victims, unaware of their data being compromised, the risks are both immediate and deeply personal, undercutting trust in both digital platforms and healthcare institutions. Besides, the incident also indicates how threat actors leverage Telegram, one of the world’s largest messaging platforms, and weaponize it for illegal activities, such as selling stolen information via chatbots. With its CEO recently arrested in France, Telegram is already under scrutiny for its lax content moderation. Bots facilitating the open sale of sensitive medical data is a further reflection of the moderation policy. Additionally, further investigations are very likely to weed out other such data-disseminating operations thriving so far under the protection Telegram seemingly offered them.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user grep: Threat actor "grep" has claimed to have leaked a database associated with AirFinch, a U.S.-based platform for booking rental accommodations and rental cars, on BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-8963: Ivanti has a critical vulnerability in Ivanti CSA 4.6, which was incidentally addressed in the patch released on 10 September (CSA 4.6 Patch 519). Successful exploitation could allow a remote unauthenticated attacker to access restricted functionality.

  • Affected products: Ivanti Cloud Services Appliance (CSA) version 4.6 (All versions before Patch 519)

Tags: DIB, tlp:green