ZeroFox Cyber Intelligence Daily Brief - November 21, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 21, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory
- Five Charged in Nationwide Phishing Scam Targeting Several U.S. Companies
- China's 'Liminal Panda' APT Attacks Telcos, Steals Phone Data
CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory
What happened: CISA, the FBI, and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released updates to #StopRansomware: BianLian Ransomware Group on observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) attributed to data extortion group, BianLian.
Why it matters: BianLian is likely based in Russia, with Russia-based affiliates, and has affected organizations in multiple U.S. critical infrastructure sectors since June 2022. The group gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega.
Five Charged in Nationwide Phishing Scam Targeting Several U.S. Companies
What happened: Law enforcement unsealed criminal charges against five defendants for allegedly engaging in a nationwide phishing scam to steal non-public company data and hack into virtual currency accounts to steal millions of dollars in cryptocurrency. The accused targeted employees of companies with phishing text messages and then used the harvested employee credentials to access data and financial accounts.
Why it matters: The defendants reportedly sent mass text messages—with links to phishing pages disguised as legitimate websites—pretending to be from the victim company or a contracted information technology or business services supplier of the victim company. Unsuspecting employees landed on the phishing websites, eventually providing confidential information, including account login credentials. They even authenticated their identities using a two-factor authentication request sent to their mobile phones. The case highlights how threat actors can bypass usually robust security measures, like two-factor authentication, by taking advantage of a user's anxiety to cause financial and psychological damage.
China's "Liminal Panda" APT Attacks Telcos, Steals Phone Data
Source: https://www.darkreading.com/threat-intelligence/china-liminal-panda-telcos-phone-data
What happened: A newly identified threat actor, Liminal Panda, has reportedly been spying on mobile networks in Asia and Africa for over four years. The group exploits outdated telecommunication systems to collect call records, text messages, and sensitive data on large groups or specific individuals.
Why it matters: The group's command-and-control (C2) infrastructure mimics the Global System for Mobile Communications (GSM), a widely used mobile communication standard, to covertly exfiltrate data. By exploiting outdated systems in telecom networks, it gathers call logs, text records, and other sensitive identifying information for surveillance and intelligence purposes. These attacks undermine personal privacy, facilitate espionage, and expose critical vulnerabilities in global telecommunications infrastructure, particularly in regions relying on legacy systems.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user Hunt3r Kill3rs: Pro-Palestine (and an ally of many pro-Russia groups) threat actor group Hunt3r Kill3r announced retaliation on the United States for allegedly deciding to “expand” the ongoing Ukraine-Russia war. According to the actor, America will face the consequences of this “big mistake.”
VULNERABILITY AND EXPLOIT INTELLIGENCE
Ubuntu Needrestart Local Privilege Escalation Bugs: Researchers have discovered a few vulnerabilities, which allow a local attacker to gain root privileges, in the needrestart package (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, and CVE-2024-11003) and a related issue in libmodule-scandeps-perl (CVE-2024-10224). Updates for the needrestart and libmodule-scandeps-perl packages for all Ubuntu releases are available.
Affected product: Debian, Ubuntu and other Linux distributions
Tags: DIB, tlp:green