zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 15, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 15, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Clop Ransomware Discloses Victim List of Cleo Cyberattack
  • International LE Operation Removes Chinese Malware from Thousands of Computers
  • Funksec Ransomware Uses AI to Bypass Security and Infect at Scale

Clop Ransomware Discloses Victim List of Cleo Cyberattack

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/79211

What happened: ZeroFox observed that the Cl0p ransomware group has disclosed 59 victims of the list teased last month. On December 25, 2024, the group warned that it would reveal the names of the organizations if they failed to respond in the next 48 hours.

Why it matters: As ZeroFox predicted as likely in its earlier reporting, the group continued to extort and leak data in the following weeks and months. The disclosure of the victim list came on January 13 and 14, during the "Old New Year" in Russia, according to the Julian calendar which was once followed in the country. Cleo customers should upgrade the affected tools to the latest release versions and continue to follow the guidelines provided by their internal security teams and the software provider to avoid being targeted by Cl0p.

International LE Operation Removes Chinese Malware from Thousands of Computers

Source: https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed

What happened: An international law enforcement operation has successfully removed the "PlugX" malware, used in several campaigns by Chinese state-sponsored group Mustang Panda, from thousands of infected computers.

Why it matters: The Mustang Panda hackers targeted thousands of computer systems, focusing on victims in the United States, European and Asian governments, businesses, and Chinese dissident groups. They deployed a version of PlugX malware to infect, control, and steal information from victim computers. This wide-ranging hack and long-term infection of thousands of Windows-based computers, including many home computers in the United States, is a likely indication of the aggressiveness of Chinese state-sponsored actors to gather strategic intel to give China an advantage over its adversaries.

Funksec Ransomware Uses AI to Bypass Security and Infect at Scale

Source: https://www.bankinfosecurity.com/ai-driven-ransomware-group-strikes-85-victims-a-27291

What happened: Cybersecurity researchers have discovered an AI-driven ransomware group named “Funksec” that compromised over 85 victims globally at the end of last year. This group employed double extortion, combining data theft and encryption, and identified itself with the "Free Palestine" movement.

Why it matters: Funksec’s FunkLocker, a sophisticated ransomware tool with advanced double encryption and the ability to bypass security programs, allowing it to modify critical system files without authorization. It further developed its arsenal by launching a data-sorting service and an "AI platform," which includes tools for malware creation, hacking knowledge sharing, and AI-powered interactions. The latest version of FunkLocker, FunkLocker V1.5, comprises more advanced features that will likely aid the group in evading detection and spreading infection stealthily and rapidly.

DEEP AND DARK WEB INTELLIGENCE

Black Widow group returns: Threat actor group Black Widow has announced its return after a period of inactivity. The group posted a message encouraging other users to engage with it in either communication or an alliance.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-55591: This vulnerability has been undergoing mass exploitation by threat actors looking to breach corporate and enterprise networks. This vulnerability allows a remote attacker to gain super-admin privileges via crafted requests to Node[.]js websocket module. This vulnerability has been patched.

Affected products: For affected products, please refer to this update.

Microsoft January 2025 Patch Tuesday: In this month’s Patch Tuesday updates, Microsoft addressed 159 security vulnerabilities, including eight zero-day flaws, three of which are actively being exploited in attacks. Twelve critical vulnerabilities have been resolved, including flaws related to information disclosure, privilege escalation, and remote code execution.

Affected products: For affected products and versions, please refer to this update.

Tags: DIB, tlp:green