ZeroFox Cyber Intelligence Daily Brief - November 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Akira Ransomware Racks Up over 30 Victims in a Single Day
- U.S. Senate Panel Holds Hearing on Suspected Chinese Hacking Incidents
- Botnet Fueling Residential Proxies Disrupted in Cybercrime Crackdown
Akira Ransomware Racks Up over 30 Victims in a Single Day
Source: https://www.darkreading.com/cyberattacks-data-breaches/akira-ransomware-30-victims-single-day
What happened: The Akira ransomware group updated its data-leak website on November 13-14, revealing more than 30 new victims. This marks the highest single-day total for the group since it began operating in March 2023. The group uses a ransomware-as-a-service (RaaS) model, stealing sensitive data before encrypting it and demanding a ransom.
Why it matters: This surge in attacks shows a significant escalation in Akira's operations, especially as they surpass their total number of victims for 2023 within just a few months.The latest victims span various industries and countries, with around 25 U.S.-based targets, along with others from Canada, Europe, and more. The growing frequency of these attacks suggests that the group is becoming more effective in its operations, posing an increasing threat to global cybersecurity.
U.S. Senate Panel Holds Hearing on Suspected Chinese Hacking Incidents
What happened: A U.S. Senate Judiciary subcommittee held a hearing to address Chinese hacking incidents, including a recent Salt Typhoon cyberattack on American telecom firms. Lawmakers highlighted cybersecurity risks to U.S. infrastructure and national security, noting the targeting of phones belonging to political figures like Donald Trump and JD Vance by Salt Typhoon. The hearing addressed the growing threat posed by Chinese-linked cyberattacks on critical systems.
Why it matters: The recent hearing addressed several threats posed by China-linked entities and current China-affiliated activities. The threats posed by Chinese cyber actors targeting U.S. institutions raise serious national security concerns. These attacks compromise sensitive communications as seen in the Salt Typhoon attack targeting prominent U.S. figures. The risks also extend beyond hacking, as economic ties between China and American companies, like Tesla and Apple, create vulnerabilities that the country can reportedly manipulate to likely advance its geopolitical goals.
Botnet Fueling Residential Proxies Disrupted in Cybercrime Crackdown
What happened: The Ngioweb botnet, which powers most of the 35,000 proxies in the NSOCKS proxy service, is being disrupted as traffic is currently being blocked to its networks. NSOCKS reportedly has been routing traffic through over 180 command-and-control (C2) nodes to mask user identities.
Why it matters: Ngioweb botnet has been exploited for a range of malicious activities, including espionage by nation-state hackers and cybercrime such as DDoS amplification, phishing, and credential stuffing. Its proxies hide malware traffic and target devices with outdated vulnerabilities, posing a persistent threat to cybersecurity. The ongoing takedown is an essential step in mitigating these risks, although some command-and-control nodes remain active.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Hunt3r Kill3rs: Pro-Palestine threat actor group Hunt3r Kill3rs called for Muslim hackers, human rights organizations, and activists all around the world to "unite again" under the operation #OpIsrael and start a campaign against Israel. The actor urges them to share the "truth about the situation in Israel."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-44308: Apple has addressed two zero-day vulnerabilities in its advisory. One of the flaws (CVE-2024-44308) allows threat actors to achieve remote code execution through maliciously crafted web content.
Affected products: macOS Sequoia JavaScriptCore
CVE-2024-10924: The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).
Affected products: Wordpress Really Simple Security (Free, Pro, and Pro Multisite) plugins versions 9.0.0 to 9.1.1.1
Tags: DIB, tlp:green