zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 20, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russia Conducted Mass Cyberattack on Ukraine's State Registries, Deputy PM Says
  • UAC-0125 Distributes Malware Disguised as Army+ App
  • Juniper Warns of Mirai Botnet Targeting Session Smart Routers

Russia Conducted Mass Cyberattack on Ukraine's State Registries, Deputy PM Says

Source: https://www.reuters.com/technology/cybersecurity/russia-conducted-mass-cyber-attack-ukraines-state-registries-deputy-pm-says-2024-12-19/

What happened: Russia launched a large-scale cyberattack on Ukraine's state registries, leading to a temporary suspension of services that store critical information such as births, deaths, marriages, and property ownership.

Why it matters: The cyberattack has temporarily halted access to essential records, affecting both citizens and government operations. While some services are expected to resume within two weeks, the disruption can likely cause delays and confusion in various sectors reliant on these registries. The registries are essential for maintaining public records and ensuring the functioning of civil services. Disrupting these systems can potentially create significant challenges in managing legal and civic processes, such as property transfers and vital statistics.

UAC-0125 Distributes Malware Disguised as Army+ App

Source: https://thehackernews.com/2024/12/uac-0125-abuses-cloudflare-workers-to.html

What happened: A cyberattack, attributed to the threat group UAC-0125 (linked to the Russian GRU), is targeting Ukrainian military personnel. The attackers are reportedly using a popular web service to host fake versions of a legitimate mobile app, Army+, to distribute malware.

Why it matters: Army+ is an application that aims to make it easier for Military personnel in Ukraine to efficiently undertake tasks digitally. This incident likely increases the risks of data breaches and remote system compromises, as users may trust the source due to its association with a legitimate service. Since this application manages military resources, it is likely that the Russia-linked Unit 74455 aims to exfiltrate essential information from Ukraine to influence the ongoing Russia-Ukrain war.

Juniper Warns of Mirai Botnet Targeting Session Smart Routers

Source: https://www.bleepingcomputer.com/news/security/juniper-warns-of-mirai-botnet-targeting-session-smart-routers/

What happened: Juniper Networks is warning customers about the Mirai malware strain infecting Session Smart routers due to the use of default credentials. The strain reportedly gains access through default logins, enabling remote command execution and launching DDoS attacks.

Why it matters: The Mirai malware campaign is particularly dangerous because of the exploitation of default credentials, which can likely expose devices to DDoS attacks and remote command execution. According to Juniper's advisory, using weak security practices, such as default passwords, can lead to device compromises. Compromised devices can disrupt services and be leveraged for further malicious actions if not properly secured.

DEEP AND DARK WEB INTELLIGENCE

Exploit/RAMP user faheem: Untested threat actor "faheem" advertised an auction for network access with domain administrator rights to an unnamed U.S.-based defense technology company on predominantly Russian language dark web forums Exploit and RAMP.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-34990: A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows an attacker to execute unauthorized code or commands via specially crafted web requests.

Affected products: Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4

Tags: DIB, tlp:green