zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • LockBit Ransomware Group to Unveil Version 4.0 in Early 2025
  • Ukraine Collects Vast War Data Trove to Train AI Models
  • Dark Web Actors Advertise New Automated OSINT Tools

LockBit Ransomware Group to Unveil Version 4.0 in Early 2025

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/77801

What happened: ZeroFox has observed the LockBit ransomware group claiming that it is set to release LockBit 4.0 on February 3, 2025, nearly a year after a global law-enforcement operation disrupted its activities.

Why it matters: As one of the most prominent ransomware groups, LockBit's evolution signals more advanced attack techniques, including enhanced encryption, improved evasion tactics, and potentially more destructive payloads. The launch of LockBit 4.0 is expected to escalate the scale and sophistication of ransomware campaigns, presenting an even greater threat to organizations worldwide. The delay in the release of the new version can be attributed to the August 2024 arrest of Rostislav Panev, a key member of the group.

Ukraine Collects Vast War Data Trove to Train AI Models

Source: https://www.reuters.com/technology/ukraine-collects-vast-war-data-trove-train-ai-models-2024-12-20/

What happened: Ukraine is leveraging two million hours of drone footage to train AI models for battlefield decision-making, enhancing combat tactics and target recognition. This data, collected through systems, is reportedly important for developing AI capable of identifying targets and optimizing weapons use.

Why it matters: Both Ukraine and Russia are deploying AI on the battlefield, with applications ranging from autonomous drones to target identification. Ukraine’s AI-driven systems, such as Avengers, are reportedly identifying thousands of Russian targets regularly, while drone swarms and self-piloting drones are under development. AI technologies are contributing to the development of unmanned systems, cyber warfare, and military training, significantly influencing battlefield dynamics—allowing for faster decision-making, improved situational awareness, and greater operational efficiency, giving militaries a strategic advantage in modern warfare.

Dark Web Actors Advertise New Automated OSINT Tools

Source: https://www.zerofox.com/advisories/28869/

What happened: ZeroFox continues to observe an increased demand for automated Open Source Intelligence (OSINT) tools amongst deep and dark web threat actors. While OSINT tools are commonly utilized for illicit activity in a variety of industries, malicious actors have capitalized on the tools’ advanced data collection capabilities for personal profit and to encourage subsequent illicit activity.

Why it matters: ZeroFox assesses that the deep and dark web market for these tools will continue to increase in the early months of 2025. A newly observed OSINT tool on the dark web offers a range of capabilities that enhance information gathering and analysis for cybercriminals—including search functionality for personally identifiable information (PII), such as email addresses, phone numbers, personal financial information (PFI), and more. Additionally, the tool supports automated metadata extraction for a comprehensive analysis of digital footprints revealing crucial information like online activities, endangering victims’ data and safety.

DEEP AND DARK WEB INTELLIGENCE

Telegram user RipperSec: Pro-Palestine hacktivist group (allegedly operating from Malaysia) “RipperSec” said that they will lower cyberattacks and operations on Australian websites. According to the actor, the operation will not be completely stopped, but it will be reduced since Australia, as claimed by the actor, has continued taking a stand against Israel.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-12727: A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode. Sophos addressed two other critical vulnerabilities in its security update.

Affected products: Sophos Firewall versions older than 21.0 MR1 (21.0.1)

Tags: DIB, tlp:green