ZeroFox Cyber Intelligence Daily Brief - December 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 26, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- After Exploiting Cleo’s File Transfer Platforms Cl0p Ransomware Claims 66 Victims
- Iranian APT Charming Kitten Deploys C++ Variant of BellaCiao Variant
- Dark Web Facial ID Farm Warning—Hackers Build Identity Fraud Database
After Exploiting Cleo’s File Transfer Platforms Cl0p Ransomware Claims 66 Victims
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/78125
What happened: ZeroFox intelligence has observed Russia-based criminal ransomware collective Cl0p claiming responsibility for exploiting alleged zero-day vulnerabilities in Cleo file transfer tools to target 66 organizations in data theft attacks. The group has warned that it will publicize the names of the organizations if they fail to respond within 48 hours of the initial post.
Why it matters: The initial victim list likely marks the beginning of a campaign to extort and leak data in the coming weeks and months. While ZeroFox has observed Cl0p removing three of the 66 victims—likely because negotiation talks have commenced—it will likely reveal names of victims that fail to meet its demands, or even expose exfiltrated files, which will interest other financially motivated adversarial threat actors. Cleo customers should upgrade the affected tools to the latest release versions and continue to follow the guidelines provided by their internal security teams and the software provider to avoid being targeted by Cl0p.
Iranian APT Charming Kitten Deploys C++ Variant of BellaCiao Variant
Source: https://thehackernews.com/2024/12/irans-charming-kitten-deploys-bellacpp.html
What happened: Charming Kitten (also known as APT35, CALANQUE, CharmingCypress, and ITG18), affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been deploying the C++ variant of a known malware strain called BellaCiao.
Why it matters: The malware variant can intrude into networks, maintain stealthy persistence, and create secure tunnels for hidden communication using domains linked to known attackers. Charming Kitten weaponizes these capabilities to bypass standard security solutions and exploit security flaws in publicly accessible and widely used applications in a wide range of cyberattacks.
Dark Web Facial ID Farm Warning—Hackers Build Identity Fraud Database
What happened: A dark web criminal group has been uncovered collecting genuine identity documents along with matching facial ID images. This operation was designed to bypass Know Your Customer (KYC) verification processes, which are used to prevent identity fraud in banking and financial institutions.
Why it matters: The criminal group used authentic identity documents paired with corresponding facial biometric data, making it more difficult to identify the perpetrators through conventional security checks. Unlike previous incidents where stolen biometric data was scraped from breached databases, the group appears to have acquired the information directly from users. This poses a significant risk to banks, financial institutions, and any organization that relies on KYC and biometric authentication systems, potentially leading to a rise in identity fraud and other related crimes.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user miyako: On December 25, 2024, ZeroFox observed threat actor “miyako,” associated with HELLCAT ransomware group, claiming to have breached the Sistem Informasi Pengelolaan Keuangan Daerah (Regional Financial Management Information System) managed by Badan Pendapatan, Indonesia, on BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-45387: An SQL injection vulnerability in Traffic Ops in Apache Traffic Control allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2.
Affected product: Traffic Ops in Apache Traffic Control versions 8.0.1 and lower, and versions 8.0.0 and higher
Tags: DIB, tlp:green