zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Meet Interlock—The New Ransomware Targeting FreeBSD Servers
  • EmeraldWhale's Massive Git Breach Highlights Config Gaps
  • New Password Hack Attack—Major Platform Users at Risk

Meet Interlock—The New Ransomware Targeting FreeBSD Servers

Source: https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/

What happened: A new ransomware operation called Interlock is targeting organizations worldwide with a custom encryptor designed specifically for FreeBSD servers. One notable victim is Wayne County, Michigan, which experienced a significant cyberattack in early October.

Why it matters: Creating an encryptor to target FreeBSD servers is unusual, as most operations typically focus on more widely used platforms like Linux, especially in environments such as VMware ESXi servers and virtual machines. Interlock’s choice to target FreeBSD is likely due to its use in critical infrastructure, where successful attacks can cause significant disruptions. The newly launched group Interlock has already claimed attacks on six organizations, publicly releasing stolen data after ransoms went unpaid, showcasing a bold approach in its tactics. Previously, the only other known ransomware operation to create FreeBSD encryptors was the now-defunct Hive ransomware group, which was disrupted by the FBI in 2023.

EmeraldWhale's Massive Git Breach Highlights Config Gaps

Source: https://www.darkreading.com/cloud-security/emeraldwhale-massive-git-breach-config-gaps

What happened: Researchers uncovered a large-scale global cyber criminal operation called EmeraldWhale. The attackers stole over 15,000 credentials by exploiting misconfigured AWS S3 buckets and targeting Git repositories. The attackers reportedly cloned over 10,000 private repositories, extracted cloud credentials, and used phishing tactics to obtain additional credentials offering them up for sale on the dark web.

Why it matters: The EmeraldWhale operation shows the risks posed by misconfigured cloud and source code repositories, highlighting how such vulnerabilities can be exploited for large-scale data theft and credential resale. By selling access and target lists on underground markets, the group demonstrates the risk of further breaches across numerous organizations, likely leading to more future attacks and financial losses. The existence of such an operation emphasizes the need for rigorous security practices in managing cloud and code repositories.

New Password Hack Attack—Major Platform Users at Risk

Source: https://www.forbes.com/sites/daveywinder/2024/11/02/new-password-hack-attack-chrome-facebook-netflix-paypal-users-at-risk/

What happened: LastPass, a password manager, is warning users of an ongoing phishing scam campaign where threat actors post fake 5-star reviews on its extension and promote a fraudulent customer support phone number. This number is reportedly part of a broader campaign aimed at gaining remote access to victims' devices by impersonating support services for multiple major brands.

Why it matters: This campaign leverages popular review platforms to gain user trust, posing as legitimate support across multiple brands. By promoting a fake number within highly trusted services like LastPass and major companies, scammers convince users to reveal sensitive information or give them access to their devices, increasing the risk of identity theft, financial loss, and data breaches.The phishing campaign also affects larger platforms where the user base is much more. Given the reach of these scammers in tricking passwords out of unsuspecting users, users are advised to not give out their passwords since no legitimate customer service would require them to do so.

DEEP AND DARK WEB INTELLIGENCE

XSS user kotbit: The untested threat actor "kotbit" advertised a Fortinet VPN access to an unnamed U.S.-based legal services company on predominantly Russian language dark web forum "XSS." According to kotbit, the company generates USD 250 million in revenue. The threat actor did not specify the prices offered and urged relevant sellers to contact them via Tox messenger.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-10443: Synology, a Taiwanese maker of network-attached storage (NAS) appliances, addressed two critical zero-day vulnerabilities recently. Among them, CVE-2024-10443 is a severe zero-click vulnerability found in Synology Photos, which enables remote attackers to execute arbitrary code.

Affected products: Synology Photos 1.7 for DSM 7.2 Synology Photos 1.6 for DSM 7.2

Tags: DIB, tlp:green