zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 23, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • New SafePay Ransomware Group Targets UK Firm Microlise, Disrupting Key Clients
  • FBI Issues Warning About Racist Text Messages
  • PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries

New SafePay Ransomware Group Targets UK Firm Microlise, Disrupting Key Clients

Source: https://www.theregister.com/2024/11/22/safepay_microlise/

What happened: The SafePay ransomware group targeted UK telematics company Microlise, stealing 1.2 TB of data. After demanding payment within 24 hours, they leaked data following the company's failure to comply.

Why it matters: The attack crippled essential services for Microlise’s clients like DHL and Serco, including vehicle tracking and prison transport systems. These disruptions highlight the dangerous impact of ransomware on critical infrastructure, where delayed or compromised systems can directly affect public safety and logistics. SafePay's methods, including exploiting valid credentials and disabling security tools, is a likely indication of a sophisticated operation that targets networks relied upon by large public and private sector entities.

FBI Issues Warning About Racist Text Messages

Source: https://www.cisa.gov/news-events/alerts/2024/11/21/cisa-releases-insights-red-team-assessment-us-critical-infrastructure-sector-organization

What happened: CISA recently released Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a U.S. Critical Infrastructure Sector Organization in coordination with the assessed organization. The advisory contains key findings from the assessment to provide recommendations to network defenders and software manufacturers for improving their organizations’ and customers’ cybersecurity posture.

Why it matters: Within this assessment, the red team gained initial access through a web shell left from a third party’s previous security assessment. The red team proceeded to move through the demilitarized zone (DMZ) and into the network to fully compromise the organization’s domain and several sensitive business system (SBS) targets. The assessed organization discovered evidence of the red team’s initial activity but failed to act promptly regarding the malicious network traffic through its DMZ or challenge much of the red team’s presence in the organization’s Windows environment.

PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries

Source: https://thehackernews.com/2024/11/pypi-attack-chatgpt-claude.html

What happened: Cybersecurity researchers discovered two malicious packages on the Python Package Index (PyPI) repository that mimicked well-known artificial intelligence (AI) models such as OpenAI ChatGPT and Anthropic Claude. These packages were designed to deliver an infostealer called JarkaStealer, which is designed to steal sensitive information from users.

Why it matters: By impersonating trusted AI models, attackers can deceive users into installing malware, putting both personal and organizational data at risk. The malicious packages, disguised as legitimate AI tools, were downloaded thousands of times, potentially infecting numerous systems with JarkaStealer. This malware is designed to steal sensitive information, such as login credentials and personal data, which can potentially result in financial loss, identity theft, and further cyberattacks.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user IntelBroker: Well-regarded and established threat actor "IntelBroker" has claimed to have leaked a database associated with MicMonster, a Finland-based company that provides text-to-speech services on predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CISA releases seven ICS advisories: CISA has released seven Industrial Control Systems (ICS) advisories on November 21, 2024. Successful exploitation of these vulnerabilities could allow threat actors to execute arbitrary commands, retrieve password hashes or cause a denial-of-service condition, tamper with memory on affected devices, and more.

  • Affected product: For the affected products, please refer to CISA’s alert.

Tags: DIB, tlp:green