zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Security Company Denies Being Hacked by Pro-Palestinian Threat Actors
  • Venezuelan Government Web Domain Access for Sale on Dark Web
  • Tech Giant Nidec Confirms Data Breach Following Ransomware Attack

Security Company Denies Being Hacked by Pro-Palestinian Threat Actors

Source: https://www.darkreading.com/cyberattacks-data-breaches/eset-wiper-attack-targets-israel

What happened: Security firm ESET denied reports that hackers compromised its systems to target Israeli customers with wiper malware, confirming that only its partner, Comsecure, was affected. A malicious email campaign, blocked within ten minutes, impersonated ESET with a fake security warning and malware-laced ZIP attachment.

Why it matters: Even though the hackers could not breach the ESET platform, they leveraged its partner network, abused anti-spoofing defenses, and mimicked official channels to distribute malware. The malware distributed resembles tactics used by politically motivated Handala group, known for attacking Israeli organizations following the Israel-Hamas conflict. The campaign’s sophistication, bypassing email authentication protocols, reveals security gaps in vendor relationships that hackers will likely target to further their agenda during geopolitical crises.

Venezuelan Government Web Domain Access for Sale on Dark Web

Source: https://dailydarkweb.net/venezuelan-government-web-domain-access-for-sale-on-dark-web/

What happened: A cybercriminal is attempting to sell initial access to a Venezuelan governmental web domain in the agriculture sector, including a webshell and command-and-control capabilities, for USD 20,000. The transaction is being facilitated through secure channels like Tor and includes escrow services via XSS.

Why it matters: The offer of initial access to a Venezuelan governmental web domain in the agriculture sector poses serious risks, including potential data breaches, manipulation of agricultural policies, disruption of food supply chains, and attacks on critical infrastructure. Threat actors could exploit this access to create significant economic destabilization and incite public unrest in an already vulnerable nation.

Tech Giant Nidec Confirms Data Breach Following Ransomware Attack

Source: https://www.bleepingcomputer.com/news/security/tech-giant-nidec-confirms-data-breach-following-ransomware-attack/

What happened: Nidec Corporation confirmed that hackers behind a ransomware attack earlier this year stole and leaked confidential data on the dark web after the company reportedly did not meet their demands. The attackers gained access by using valid VPN credentials from a Nidec employee. Although Nidec has not named the perpetrators responsible for this attack, ZeroFox observed threat actors 8Base and Everest claim to leak the company’s data on their leak sites.

Why it matters: The threat actors reportedly leaked over 50,000 files from Nidec, including business contracts, procurement policies, and internal documents. While the attack did not encrypt files, the stolen data could be exploited in targeted phishing campaigns or other malicious activities. Employees, contractors, and business partners can likely face targeted phishing attacks, financial fraud, or reputational damage due to the stolen information. It is also likely that this leaked data can provide other threat actors with information to conduct further breaches and phishing attacks. Malicious actors might abuse access to employee accounts and systems to install malware and infiltrate other sensitive data.

DEEP AND DARK WEB INTELLIGENCE

Data leaked from Indonesian Power Company: A threat actor claims to have leaked a database with 4 million records from PT Haleyora Power, an Indonesian power company, exposing sensitive employee data, including IDs, contracts, and banking information.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-37383: CVE-2024-37383 is a vulnerability in the Roundcube Webmail email client and is a stored XSS vulnerability which can allow attackers to execute avaScript code on the user's page.

Affected products: Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7

CVE-2024-44000: Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.

Affected products: LiteSpeed Cache: from n/a before 6.5.0.1.

Tags: DIB, tlp:green