ZeroFox Cyber Intelligence Daily Brief - December 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Cl0p Claims Responsibility for Zero-Day Exploitation
- CISA Issues Directive to Better Secure Cloud Services
- “Bitter” Cyberspies Target Defense Orgs with New MiyaRAT Malware
ZeroFox Intelligence Flash Report: Cl0p Claims Responsibility for Zero-Day Exploitation
Source: https://www.zerofox.com/advisories/28797/
What happened: ZeroFox analyzes the ransomware group Cl0p reportedly claiming responsibility for a recent spate of data theft attacks that targeted organizations using Cleo managed file transfer (MFT) software solutions.
Why it matters: There is a likely chance that Cl0p is responsible, as claimed, for the recent exploitation of vulnerabilities CVE-2024-50623 and CVE-2024-55956—particularly given the collective’s propensity for targeting organizations that offer MFT services. If Cl0p’s claims are legitimate, there is a roughly even chance that additional organizations will be compromised in the coming weeks before they are named on the victim leak site to apply additional extortion pressure. The extent of the compromise and the number of victim organizations will be heavily dependent on Cl0p’s ability to conduct widespread exploitation activities before effective security patches are implemented.
CISA Issues Directive to Better Secure Cloud Services
What happened: CISA issued Binding Operational Directive (BOD) 25-01, Implementing Secure Practices for Cloud Services to safeguard federal information and information systems. This Directive requires federal civilian agencies to identify specific cloud tenants, implement assessment tools, and align cloud environments to CISA’s Secure Cloud Business Applications (SCuBA) secure configuration baselines.
Why it matters: Maintaining secure configuration baselines is critical in the dynamic cybersecurity landscape, where vendor changes, software updates, and evolving security best practices shape the threat environment. As vendors frequently release new updates and patches to address vulnerabilities, security configurations must also adjust. Outdated security configurations expose systems to exploits that can be easily mitigated by recommended and mandatory security configurations.
“Bitter” Cyberspies Target Defense Orgs with New MiyaRAT Malware
What happened: A cyberespionage group named “Bitter” targeted defense organizations in Turkey using a new malware, MiyaRAT, alongside the previously used WmRAT. The attack was initiated through a malicious email, luring victims with a fake foreign investment project, which triggered the deployment of the malware.
Why it matters: Bitter is a long-running South Asian cyberespionage group, active since 2013, with a history of targeting government and critical organizations in Asia. By deploying both MiyaRAT and WmRAT, the threat group gains advanced capabilities like data exfiltration, remote control, and system monitoring, posing serious risks to sensitive military and defense data. Additionally, reports indicate that MiyaRAT is likely reserved for critical sectors, deployed infrequently to maximize its impact, making it a highly effective tool for targeted, strategic cyberattacks.
DEEP AND DARK WEB INTELLIGENCE
XSS user Sudogreen: Untested threat actor "Sudogreen" advertised Fortinet VPN access to an unnamed Canadian Legal Services company on predominantly Russian language dark web forum XSS. The actor charged USD 3,000 for the access.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-53677: This recently patched critical vulnerability in Apache Struts 2 is being actively exploited, with publicly available proof-of-concept (POC) exploits targeting vulnerable devices. The flaw stems from the software's file upload logic, which is vulnerable to path traversal attacks, allowing the upload of malicious files that could lead to remote code execution. Users are recommended to upgrade to version 6.4.0.
Affected products: Apache Struts from 2.0.0 before 6.4.0
Tags: DIB, tlp:green