ZeroFox Cyber Intelligence Daily Brief - December 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 27, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hacker Charged for Extorting USD 3.2M in Bitcoin After Breaching 300,000 Accounts
- North Korean Hackers Deploy “OtterCookie” Malware to Backdoor Developers
- Botnets Are Exploiting D-Link Devices to Gain Complete Remote Control
Hacker Charged for Extorting USD 3.2M in Bitcoin After Breaching 300,000 Accounts
Source: https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html
What happened: An individual has been charged in the United States for allegedly hacking into a New Jersey-based company’s network in March 2020, stealing confidential data from about 300,000 customers. The accused then extorted the company, demanding a payment of 300 bitcoin (approx. USD 3.2 million) to prevent the release or sale of the stolen data.
Why it matters: The hacker exploited vulnerabilities in the company's network, affecting a large number of customers and violating their privacy. If the accused had successfully released or sold the stolen data, it likely would have led to widespread identity theft, financial fraud, and significant harm to the affected customers. The use of cryptocurrency, in this case Bitcoin, complicates the investigation and enforcement process, as it allows the accused to potentially hide their identity and evade traditional financial tracking systems.
North Korean Hackers Deploy “OtterCookie” Malware to Backdoor Developers
What happened: North Korean threat actors are deploying OtterCookie, a new malware strain, in the Contagious Interview campaign, which targets software developers with fake job interviews to deliver malware to their systems.
Why it matters: OtterCookie can perform reconnaissance and exfiltrate data—including sensitive information like clipboard data, cryptocurrency wallet keys, documents, and images. With these capabilities, the malware is likely to expose confidential data to threat actors, who might leverage it in financially or even politically motivated attacks. Moreover, adding new malware strains and diversifying infection tactics within the Contagious Interview is a likely indication of the threat actors constantly experimenting and adapting the operation to conduct more targeted attacks.
Botnets Are Exploiting D-Link Devices to Gain Complete Remote Control
Source: https://cybersecuritynews.com/d-link-routers-under-attack/
What happened: Researchers have connected a surge in cyberattacks leveraging legacy bugs in D-Link routers to two botnets, FICORA and CAPSAICIN. Even though patches for many of the exploited bugs are available, several unpatched devices are still at risk of such attacks..
Why it matters: The two botnets exploit vulnerabilities in the Home Network Administration Protocol (HNAP) interface of the D-Link routers, which enables threat actors to take complete remote control over the devices and execute malicious commands. The FICORA botnet can also launch distributed denial-of-service (DDoS) attacks. The use of unpatched legacy devices is likely to enable cybercriminals to deliver malware in scalable operations.
DEEP AND DARK WEB INTELLIGENCE
- New alliance of hacktivists on Telegram: Pro-Russian hacktivist group "NoName057(16)" announced an alliance with pro-Palentine group "LulzSec Muslims".
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-52046: This vulnerability allows attackers to exploit the deserialization process by sending specially crafted malicious serialized data, potentially leading to remote code execution (RCE) attacks.
Affected product: MINA versions 2.0 through 2.0.26, 2.1 through 2.1.9, and 2.2 through 2.2.3
Tags: DIB, tlp:green