ZeroFox Cyber Intelligence Daily Brief - October 2, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 2, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Police Arrests Suspects Linked to LockBit and Evil Corp Ransomware Gangs
- CISA and International Partners Release Guidance on Principles of OT Cybersecurity for Critical Infrastructure Organizations
- T-Mobile to Pay Millions to Settle with FCC Over Data Breaches
Police Arrests Suspects Linked to LockBit and Evil Corp Ransomware Gangs
What happened: Europol, the UK, and the US have announced coordinated law enforcement actions against LockBit ransomware affiliates. Britain imposed sanctions on 16 members of the Russian cybercrime gang Evil Corp, citing their involvement in operations directed by Russian intelligence against NATO allies. Authorities arrested an alleged LockBit developer at France's request, two individuals in the UK for supporting a LockBit affiliate, and a key administrator of a bulletproof hosting service in Spain, seizing nine servers.
Why it matters: These arrests and server seizures are essential for disrupting LockBit’s operations and prosecuting core members. By arresting key players associated with LockBit and Evil Corp. Authorities are not only disrupting the operations of these cybercriminal groups but also exposing their connections to state-affiliated cyberespionage. The unmasking and the subsequent sanctions against this individual and other Evil Corp members—the leader of Evil Corp—highlight the global efforts to dismantle ransomware networks that pose serious threats to critical infrastructure, businesses, and governments. Moreover, the apprehension of LockBit's members severely weakens the group's ability to continue extorting victims and leaking stolen data, and other destructive cybercrimes.
CISA and International Partners Release Guidance on Principles of OT Cybersecurity for Critical Infrastructure Organizations
What happened: CISA, along with other agencies, released a guide on operational technology cybersecurity. This guidance provides critical information on how to create and maintain a safe, secure operational technology (OT) environment. The guide is intended to aid organizations in identifying how business decisions may adversely impact the cybersecurity of OT and the specific risks associated with those decisions.
Why it matters: Due to the extensive integration of OT in the technical environments of critical infrastructure organizations, and the complex structure of these environments, it can be difficult to identify how business decisions may affect the cyber security of OT, including the specific risks attributed to a decision. Decisions may include introducing new systems, processes, or services to the environment; choosing vendors or products to support the technical environment; and developing business continuity and security-related plans and playbooks. This document is designed to assist organizations make decisions for designing, implementing, and managing OT environments to ensure they are both safe and secure, as well as enable business continuity for critical services.
T-Mobile to Pay Millions to Settle with FCC Over Data Breaches
Source: https://www.securityweek.com/t-mobile-to-pay-millions-to-settle-with-fcc-over-data-breaches/
What happened: The Federal Communications Commission (FCC) announced a multi-million-dollar settlement with T-Mobile due to multiple data breaches that compromised the personal information of millions. FCC revealed that T-Mobile failed to protect customer data, improperly allowed third-party access to customer proprietary network information (CPNI) without consent, and did not engage in adequate security practices.
Why it matters: This settlement addresses T-Mobile's repeated failures to safeguard customer data, resulting in multiple breaches affecting millions. The exposure of sensitive information, including names, addresses, and Social Security numbers (SSNs), significantly increases the risk of identity theft, financial fraud, and privacy violations for customers. To settle the FCC’s investigation, T-Mobile has agreed to invest USD 15.75 million over the next two years to enhance its cybersecurity practices and pay an equal civil penalty. As part of the settlement, T-Mobile must implement a comprehensive information security program, adopt zero-trust architecture, enhance network segmentation, and widely adopt multi-factor authentication (MFA), while also providing regular reports on its cybersecurity measures.
DEEP AND DARK WEB INTELLIGENCE
Threat actor group Server Killers claims DDoS attack | Pro-Russia threat actor group “Server Killers” claimed to have conducted a DDoS attack against multiple airports in Austria.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-45519: This is an SMTP vulnerability exploit script overview. This script checks for vulnerabilities in an SMTP server and, if found, exploits the vulnerability by establishing a reverse shell connection to your machine.
Affected products: Zimbra postjournal service component for email journaling and archiving
Tags: DIB, tlp:green