ZeroFox Cyber Intelligence Daily Brief - November 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 30, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Actively Deploying Zyxel Firewall Flaw To Deploy Ransomware
- Threat Actor Advertises New Crypter Service on Dark Web
- Phishing-as-a-Service "Rockstar 2FA" Targets Popular App Users
Hackers Actively Deploying Zyxel Firewall Flaw To Deploy Ransomware
Source: https://cybersecuritynews.com/hackers-actively-deploying-zyxel-firewall-flaw/
What happened: Cybersecurity experts have discovered that attackers are exploiting a directory traversal vulnerability (CVE-2024-11667) in Zyxel firewalls to deploy Helldown ransomware. This flaw affects Zyxel ZLD firmware versions 5.00 through 5.38, allowing unauthorized file uploads and downloads via crafted URLs.
Why it matters: This vulnerability enables attackers to gain unauthorized access to sensitive network systems, making it possible for them to deploy ransomware or conduct further malicious activities. Given the widespread use of Zyxel firewalls in various organizations, this flaw poses a serious security risk. Zyxel has responded by issuing security updates to patch the vulnerability, urging all users to immediately upgrade to the latest version to prevent potential breaches.
Threat Actor Advertises New Crypter Service on Dark Web
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/76444
What happened: Threat actor "DarkMatter" has advertised a crypter service dubbed "DarkMatter" on predominantly Russian-language dark web forum xss. The service offers features, including unique stubs, anti-sandbox protection, and bypassing operating system defender systems.
Why it matters: A crypter service is software designed to encrypt and obfuscate files, often to protect executable files or malicious software like viruses, trojans, and ransomware. DarkMatter’s features are likely to help it evade antivirus detection and enable malicious software to operate unnoticed. The anti-sandbox protection is likely to aid in detecting isolated environments and the ability to bind malware to legitimate software can likely enable attackers to lure users into executing harmful programs, increasing the chances of infection.
Phishing-as-a-Service "Rockstar 2FA" Targets Popular App Users
Source: https://thehackernews.com/2024/11/phishing-as-service-rockstar-2fa.html
What happened: Malicious email campaigns dubbed Rockstar 2FA is a phishing-as-a-service (PhaaS) toolkit which aims to steal credentials from a widely used application. The toolkit reportedly allows threat actors to use features like two-factor authentication (2FA) bypass, antibot protection, Telegram bot integration, and more.
Why it matters: The phishing kit is advertised and priced at a relatively nominal price, allowing actors of likely lower skill sets also to leverage its capabilities to steal credentials from a wide user base. The sophistication of this toolkit allows actors to convincingly disguise malicious links as legitimate websites. In the past, scammers have been successful in stealing personal and financial information.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user 888: Well-regarded threat actor "888" claimed to have leaked a database associated with eMedals, a Canada-based online store that provides antique and auction items, on predominantly English-language dark web forum BreachForums. The actor allegedly compromised the personal information of around 65,000 rows of user data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-11482: This vulnerability allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Affected product: ESM version 11.6.1
Tags: DIB, tlp:green