ZeroFox Cyber Intelligence Daily Brief - November 19, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 19, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- DOJ Unseals Charges Against Phobos Ransomware Operator
- U.S. Government Agencies Impersonated in Doc Signing Phishing Scams
- Chinese Hackers Exploit Fortinet VPN Zero-Day to Steal Credentials
DOJ Unseals Charges Against Phobos Ransomware Operator
What happened: The U.S. Department of Justice (DOJ) has unsealed charges against an individual for allegedly administering the sale, distribution, and operation of Phobos ransomware. Phobos ransomware, through its affiliates, targeted more than 1,000 public and private entities in the United States and around the world and extorted ransom payments worth more than USD 16 million.
Why it matters: Large-scale and intricate ransomware operations, like Phobos, aim to exfiltrate data for financial gain and evade detection by consistently adapting new strategies. Since May 2019, authorities have regularly recorded Phobos ransomware incidents impacting state, local, tribal, and territorial (SLTT) governments. The operation hacked large corporations, schools, hospitals, nonprofits, and a federally recognized tribe, and they extorted more than USD 16 million in ransom payments. The charges will set a precedent for potential similar threats, discouraging other threat actors from following Phobos’ suit and strengthening response tactics against such ransomware attacks.
U.S. Government Agencies Impersonated in Doc Signing Phishing Scams
Source: https://hackread.com/us-govt-agencies-impersonate-docusign-phishing-scams/
What happened: Phishing scams involving a document signing software surged by 98 percent in almost one week, targeting businesses with fake document requests impersonating several U.S. state and federal agencies to steal sensitive information. These scams reportedly use legitimate user accounts and APIs to appear authentic, tricking recipients into disclosing data or authorizing fraudulent transactions.
Why it matters: Impersonating government agencies in these phishing schemes make businesses especially vulnerable since employees are more likely to trust government entities without suspicions being raised. Given the scale of this phishing campaign, it is highly likely that the stolen information contains very sensitive data like client information, business dealings, and financial information. In such a campaign, the leak of sensitive information can be exploited in further attacks like blackmail and fraud, likely resulting in financial losses.
Chinese Hackers Exploit Fortinet VPN Zero-Day to Steal Credentials
What happened: Chinese hackers, "BrazenBamboo," exploited a zero-day vulnerability in Fortinet’s FortiClient Windows VPN client, allowing them to dump user credentials from memory after authentication using a custom toolkit, "DeepData." The flaw, reported in July 2024, remains unpatched by Fortinet, with reportedly no CVE assigned.
Why it matters: Exploiting this zero-day vulnerability allows attackers to steal credentials from authenticated users, putting corporate networks and systems at risk. With no patch or CVE from Fortinet, users remain vulnerable as threat actors continue to develop and deploy advanced malware to exploit the bug. Given FortiClient’s widespread use, the vulnerability poses a significant risk to businesses and government entities, potentially exposing sensitive data to politically or financially motivated threat actors.
DEEP AND DARK WEB INTELLIGENCE
Threat actors collaborate to leak data: Threat actor "EnergyWeaponUser," in collaboration with "IntelBroker," claimed to have leaked a database associated with Ford Motor Company, a U.S.-based automobile manufacturer on predominantly English-language dark web forum BreachForums. The actor allegedly exposed 44,000 records, including customer names, physical locations, and bought products.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-0012: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities. CISA has added this along with two more vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Affected products:
- PAN-OS 10.2 versions < 10.2.12-h2
- PAN-OS 11.0 versions < 11.0.6-h1
- PAN-OS 11.1 versions < 11.1.5-h1
- PAN-OS 11.2 versions < 11.2.4-h1
Tags: DIB, tlp:green