zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 22, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 22, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Mirai Botnet Variants Used in Global Attacks Targeting IoT Devices and More
  • Cryptocurrency Financial Services Firm Pleads Guilty to Market Manipulation and Wire Fraud
  • Four Million Insecure Internet Hosts and Tunneling Protocols Found

Mirai Botnet Variants Used in Global Attacks Targeting IoT Devices and More

Source: https://www.darkreading.com/cyberattacks-data-breaches/mirai-botnet-spinoffs-global-wave-ddos-attacks

What happened: Two separate variants of the Mirai botnet are behind a global wave of distributed denial-of-services (DDoS) attacks. The Murdoc Botnet exploits vulnerabilities in certain devices, while the other strain combines Mirai and Bashlite variants to exploit internet of things (IoT) flaws and weak credentials, targeting organizations worldwide.

Why it matters: The campaigns are reportedly impacting businesses worldwide where over 1,300 active IPs are involved since 2024, while researchers have identified more than 100 command-and-control servers facilitating the attack operations. Although this campaign involves two separate strains of Mirai being deployed, it likely indicates a large-scale operation behind these sustained attacks intended to cause severe operational disruptions globally.

Cryptocurrency Financial Services Firm Pleads Guilty to Market Manipulation and Wire Fraud

Source: https://www.justice.gov/usao-ma/pr/cryptocurrency-financial-services-firm-agrees-plead-guilty-charges-related

What happened: A financial services firm known in the cryptocurrency industry as a “market maker,” has agreed to resolve criminal charges relating to its fraudulent manipulation of cryptocurrency trading volume. The charges against the firm followed an undercover law enforcement operation targeting cryptocurrency “wash trading,” sham trading activity intended to attract investors.

Why it matters: The firm has admitted that it agreed to provide market-making services for the NexFundAI token, including “wash trading,” to fraudulently attract investors to purchase the token. Wash trading misleads investors and erodes trust in the market by distorting market prices and volumes, creating an illusion of demand or liquidity. Malicious actors could use wash trading to influence the market to confer unfair advantages upon themselves, causing financial losses for uninformed participants.

Four Million Insecure Internet Hosts and Tunneling Protocols Found

Source: https://thehackernews.com/2025/01/unsecured-tunneling-protocols-expose-42.html

What happened: Compromised internet hosts—including VPN servers and private routers—are likely a result of vulnerabilities in multiple tunneling protocols to affect multiple countries like China, France, and the United States. Tunneling protocols allow hosts (internet connected devices with an IP address) to communicate from one network to another, which can be hijacked to allow threat actors to gain access to networks anonymously.

Why it matters: Researchers have discovered more than 4 million compromised hosts potentially allowing threat actors to target networks with attacks like denial of service attacks (DoS). The vulnerabilities especially arise as some tunneling protocols do not reportedly authenticate and encrypt traffic with adequate security measures like internet protocol security. These vulnerabilities can likely allow attackers to intercept traffic, overload systems through DoS attacks, and gain remote access to sensitive information.

DEEP AND DARK WEB INTELLIGENCE

Xss user b0nd: Untested threat actor "b0nd" has advertised source code of a RAT (remote access trojan) malware strain on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-47100: The web interface of devices with this bug is vulnerable to cross-site request forgery (CSRF) attacks. This could allow an unauthenticated attacker to change the CPU mode by tricking a legitimate and authenticated user with sufficient permissions on the target CPU to click on a malicious link. This vulnerability is one of the three to be listed recently by CISA as a part of its Industrial Control Systems (ICS) advisories.

Affected products: The affected products and platforms are listed in this advisory.

Tags: DIB, tlp:green