ZeroFox Cyber Intelligence Daily Brief - December 2, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 2, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Bologna FC Confirms Ransomware Attack
- New Phishing Campaign Uses Corrupted Documents to Bypass Security
- Wanted Russian Hacker Linked to Hive and LockBit Ransomware Operations Arrested
Bologna FC Confirms Ransomware Attack
Source: https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/
What happened: Italian professional football club Bologna Football Club 1909 Spa has confirmed its security systems were recently the subject of a ransomware attack, on a cloud server and in the internal perimeter. RansomHub ransomware group, which has claimed responsibility for the attack, has leaked samples of the allegedly stolen data, including contracts, medical data, information on young players, commercial strategies, and business plans.
Why it matters: The alleged data involved in the leak, for example, medical data and information on specific contracts, is confidential and sensitive. If the leaked information is legit, it is likely to attract unwarranted attention to the owners of the data, subjecting them to different cyber threats—including triple extortion attempts, financial scams, blackmail, and doxxing. Commercial strategies and business plans are likely to interest financially motivated actors, who will likely re-sell such information to interested parties.
New Phishing Campaign Uses Corrupted Documents to Bypass Security
What happened: A new phishing attack exploits popular document editing software's recovery feature by sending corrupted files as email attachments. These files bypass security software and trick users into scanning a QR code that leads to a fake login page designed to steal credentials.
Why it matters: By taking advantage of a legitimate and trusted file recovery function, it evades detection, making it harder for security systems to identify the threat. The phishing emails, disguised as messages from payroll or HR departments, increase the chances of employees opening the attachments. If successful, attackers can steal sensitive login credentials, compromising corporate networks and potentially leading to significant financial and data security risks.
Wanted Russian Hacker Linked to Hive and LockBit Ransomware Operations Arrested
Source: https://thehackernews.com/2024/11/wanted-russian-cybercriminal-linked-to.html
What happened: A Russian cybercriminal linked to the LockBit and the Hive ransomware groups has reportedly been arrested. They have allegedly conducted significant attacks against entities in the United States and global businesses and critical infrastructure. The United States had offered a USD 10 million reward for information leading to their arrest or conviction.
Why it matters: The individual’s operations targeted thousands of victims globally, including critical infrastructure and businesses in the United States and other countries. By targeting their extensive network and exposing the scale of the damage caused, this arrest could help prevent further financial losses and reputational harm from their ransomware campaigns. Additionally, disrupting the individual’s extensive operations can likely lead to fewer attacks, potentially safeguarding critical systems and industries from even more severe disruptions.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Moroccan Black Cyber Army: Pro-Palestine threat actor group Moroccan Black Cyber Army claimed a web defacement attack against NDE Flaw Technologies, India.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-53750: Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows stored XSS.
Affected products: PayPal Responder versions 1.2 and before
Tags: DIB, tlp:green