zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • United States Charges a Dual National as Developer of LockBit Ransomware Group
  • 5.6 Million Affected in May Ransomware Attack Targeting Ascension
  • Crypto Mining Malware Infects Rspack npm Packages in Supply Chain Attack

United States Charges a Dual National as Developer of LockBit Ransomware Group

Source: https://www.justice.gov/opa/pr/united-states-charges-dual-russian-and-israeli-national-developer-lockbit-ransomware-group

What happened: A superseding criminal complaint filed in New Jersey charges an individual for their role as a developer in the LockBit ransomware group. The accused was arrested in Israel in August under a U.S. provisional arrest request and is awaiting extradition to the United States.

Why it matters: The charges against the accused come on the heels of an announcement about the release of a new version of LockBit ransomware, LockBit 4.0, set for February 3, 2025. The criminal complaint alleges that the individual played a key role in developing and maintaining the malware infrastructure behind attacks on thousands of victims, likely resulting in compromised sensitive data, service disruptions, and substantial financial and operational losses in critical sectors. By taking action against key members of the group, such as this developer, the U.S. government is making important strides in dismantling a highly destructive cybercrime network.

5.6 Million Affected in May Ransomware Attack Targeting Ascension

Source: https://techcrunch.com/2024/12/20/ransomware-attack-on-health-giant-ascension-hits-5-6-million-patients/

What happened: A May 2024 ransomware attack targeting Ascension, a U.S. healthcare giant, has impacted nearly 5.6 million patients. Ascension says it will begin notifying individuals whose personal information was involved in this incident and providing them with complimentary credit monitoring and identity protection services.

Why it matters: The large number of individuals impacted by the attack is likely to face further cybercrime-related threats, including extortion, blackmail, doxxing, and other malicious attacks. Healthcare organizations are repeatedly targeted in ransomware attacks as threat actors know that hospitals store large amounts of sensitive and valuable patient data. Healthcare organizations are also known to give in more to ransomware demands to protect their patients and restore services immediately.

Crypto Mining Malware Infects Rspack npm Packages in Supply Chain Attack

Source: https://thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html

What happened: A software supply chain attack compromised Rspack npm packages @rspack/core and @rspack/cli, which enabled threat actors to publish harmful versions of the packages with cryptocurrency mining malware. The affected versions of both packages have been unpublished since the discovery, and the latest safe version is 1.1.8.

Why it matters: The compromised packages, @rspack/core and @rspack/cli, record weekly downloads of 300,000 and 145,000, respectively, indicating that these packages are highly popular among businesses and their compromise will likely have a large-scale impact. Moreover, the attack can steal sensitive information, including cloud service credentials, that can likely expose confidential information belonging to firms and individuals to other threat actors.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Holy League: The threat actor group "Holy League" (an alliance formed by the unification of pro-Russian and pro-Palestinian hacktivists) has issued warnings to NATO countries—France, Germany, and more recently Belgium—about future cyberattacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-11349: The AdForest theme for WordPress is vulnerable to an authentication bypass in all versions up to and including 5.1.6. This issue arises because the plugin fails to properly verify a user's identity before authenticating them via the “sb_login_user_with_otp_fun()” function. As a result, unauthenticated attackers can gain access to the site by logging in as any user, including administrators.

Affected products: Versions up to and including 5.1.6

Tags: DIB, tlp:green