ZeroFox Cyber Intelligence Daily Brief Dec 10 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 10, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Ransomware Attack Targets Leading U.S. Medical Device Maker
- Black Basta Ransomware Adds Email Bombing and QR Codes to Its Arsenal
- Ukraine’s Military Companies Baited with Doctored Emails
Ransomware Attack Targets Leading U.S. Medical Device Maker
What happened: Artivion, a leading manufacturer of heart surgery medical devices based in the United States, has confirmed that a late November ransomware attack disrupted its operations, forcing it to take some systems offline. The company has further stated that the incident has had no impact on “overall financial condition or results of operations.”
Why it matters: Artivion has confirmed that the incident involved encryption of some files, which the threat actors are likely to use in further extortion attacks, or even specifically target individuals whose information could be included in the encrypted files. The healthcare industry has large repositories of sensitive information that actors can leverage for financial gain, making it a lucrative target for ransomware attacks. ZeroFox has detected around 480 ransomware and digital extortion victims in the healthcare sector in the past year, indicating that the sector has been facing recurring ransomware attacks.
Black Basta Ransomware Adds Email Bombing and QR Codes to Its Arsenal
Source: https://thehackernews.com/2024/12/black-basta-ransomware-evolves-with.html
What happened: The Black Basta ransomware group has adopted new social engineering tactics, including email bombing and impersonation, to target victims. It employs remote access tools like AnyDesk and malicious QR codes to deploy payloads such as Zbot and DarkGate for credential harvesting and further attacks.
Why it matters: Black Basta’s new methods blend social engineering with custom malware and will likely facilitate environment, reconnaissance, credential theft, and VPN exploitation. The group disguises itself as support personnel or IT staff of the targeted organization and tricks users into its email bombing tactic to install legitimate remote access software, later used to deliver additional payloads, including a custom credential harvesting program. Such evolutionary tactics are likely to complicate detection and response efforts.
Ukraine’s Military Companies Baited with Doctored Emails
What happened: Ukraine’s CERT-UA confirmed that hacking group UNC4221 targeted defense and military companies with phishing emails from a Ukrainian business organization. The campaign aimed to compromise employees of Ukraine’s defense contractors and forces. This group is suspected to be linked to Russia and has been observed targeting messaging services, like Telegram and Whatsapp, and military systems like Kropyva.
Why it matters: This hacking group targeted Ukraine's critical infrastructure with phishing emails disguised as invitations to a legitimate conference hosted by the Ukrainian League of Industrialists and Entrepreneurs (ULIE). The attack aimed to deceive recipients and compromise sensitive systems. What makes this phishing campaign particularly dangerous is that it exploits a legitimate event and trusted organization to appear credible, increasing the likelihood of employees opening the emails. By targeting defense and military companies, the attackers likely aim to compromise sensitive systems and steal critical data, likely impacting national security.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user miyako: Well-regarded threat actor "miyako" advertised network access with root rights to an unnamed U.S.-based manufacturing company on predominantly English language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-54143: Openwrt/asu is an image-on-demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.
Affected product: Versions before openwrt asu 920c8a1
Tags: DIB, tlp:green