20 Feb-CyberNEXT-CISO-Daily
20 Feb-CyberNEXT-CISO-Daily
CyberNEXT CISO Daily – February 20, 2024
February 20, 2024
Posted By: Research Team
CyberNEXT CISO Daily
February 20, 2024

 

NEW DEVELOPMENTS

 

8 LockBit Ransomware Gang Domains Seized in Global Operation
Source: Hackread
Law enforcement agencies, including the UK’s National Crime Agency, the US Department of Justice, the FBI, and Europol, have seized known dark web domains operated by the LockBit Ransomware Gang as part of “Operation Cronos.” While there has been no official confirmation or press release, seizure notices are displayed on the websites. The notice indicates ongoing operations under “Operation Cronos,” urging visitors to return for more information on February 20th. Affiliates attempting to log in have encountered messages revealing that law enforcement has taken control of LockBit’s platform and obtained sensitive information, including victim details and stolen data.
Article Link

 

A Ukrainian Raccoon Infostealer Operator Is Awaiting Trial in the US
Source: Security Affairs
A 28-year-old Ukrainian national named Mark Sokolovsky was extradited to the United States from the Netherlands to face charges related to his alleged participation in the Raccoon Infostealer cybercrime operation.  Raccoon is renowned for its user-friendliness; it provides an automatic backend panel, reliable hosting, and round-the-clock customer service in Russian and English. Intending to steal confidential data, the malware targets several programs, such as email clients, popular browsers, and cryptocurrency wallets. Sokolovsky is accused of money laundering, wire fraud, computer fraud, and aggravated identity theft. 
Article Link

 

North Korean Hackers Linked to Defense Sector Supply-Chain Attack
Source: Bleeping Computer
Germany’s Federal Intelligence Agency (BfV) and South Korea’s National Intelligence Service (NIS) have published a joint alert warning about continued cyber-espionage efforts against the global defense sector on behalf of the North Korean regime. The attacks, linked to North Korean groups, including the Lazarus group, intend to steal sensitive military technology information to aid North Korea’s military modernization ambitions. The joint alert focuses on two scenarios: a supply-chain attack and social engineering tactics, including specifics on the attackers’ techniques and procedures (TTPs). Some of the listed mitigation strategies include limiting access to IT service providers, introducing multi-factor authentication (MFA), training staff on cyberattack trends, and following the principle of least privilege.
Article Link

 

Cactus Ransomware Claim to Steal 1.5TB of Schneider Electric Data
Source: Bleeping Computer
The Cactus ransomware group claims to have stolen 1.5 terabytes of data from Schneider Electric’s Sustainability Business division after breaching the company’s network in January. As proof, 25 megabytes of allegedly stolen data, including American citizens’ passport snapshots and non-disclosure agreement scans, were leaked on the dark web. Schneider Electric, a French energy and automation manufacturing multinational, faces extortion from the ransomware group, threatening to release all stolen data if their ransom demands are unmet. The stolen data may include sensitive information about industrial control and automation systems, potentially impacting high-profile customers like Allegiant Travel Company, Clorox, and Walmart. Cactus ransomware, known for double-extortion tactics, breaches corporate networks using various methods, including phishing attacks and exploiting security vulnerabilities.
Article Link

 

Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries
Source: The Hacker News
The Anatsa Android banking trojan, also known as TeaBot or Toddler, has expanded its reach to include Slovakia, Slovenia, and Czechia in a recent campaign observed in November 2023. Despite Google Play’s enhanced security protocols, some droppers in this campaign successfully exploited accessibility service restrictions in Android 13. These droppers, disguised as innocuous apps, facilitate the installation of malware by circumventing Google’s security measures for application permissions management. Anatsa can gain full control over infected devices, steal credentials, and initiate fraudulent transactions. 
Article Link

 

LabHost Employs Phishing-as-a-Service to Steal Banking Credentials
Source: Cyber Security News
The LabHost group has been identified as orchestrating Phishing-as-a-Service (PhaaS) attacks targeting Canadian banks. PhaaS has gained prominence due to its versatility, offering a range of tools and features, including access to stolen corporate branding, monitoring capabilities, and email security bypass techniques. While Frappo previously dominated the PhaaS landscape, its decline in effectiveness paved the way for emerging players like LabHost. LabHost emerged publicly in late 2021, initially offering expensive multi-branded phishing kits targeting Canadian banks. Over time, LabHost expanded its offerings, including a Canadian interbank network kit, resulting in a surge of phishing campaigns from spring to October. Two subscription packages were offered, covering North American and international brands, with a focus on Canadian banks, regional telecom providers, and postal delivery services. LabHost employs tools like “LabRat” for campaign management and monitoring and “LabSend,” a new SMS lure and campaign manager introduced in December.
Article Link

 

Fake Tokens Exploit BRICS Investment Hype
Source: Infosecurity Magazine
Security researchers have uncovered a concerning trend of cryptocurrency counterfeiting targeting Fortune 100 companies with fraudulent tokens–impersonating major brands, government entities, and national fiat currencies. Exploiting investor interest in decentralized finance (DeFi) and cryptocurrency, scammers employ rug pulls and fraudulent initial coin offerings (ICOs) to deceive investors and steal their funds. One notable case involves a counterfeit token named “BRICS,” capitalizing on the investment frenzy surrounding the BRICS intergovernmental organization comprising Brazil, Russia, India, China, and South Africa. Scammers leverage geopolitical narratives and misinformation to promote fake tokens, exploiting the global image of reputable organizations like BRICS.
Article Link

 

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices
Source: The Hacker News
Meta Platforms has taken action against eight surveillance-for-hire companies based in Italy, Spain, and the United Arab Emirates that target iOS, Android, and Windows devices. These companies participated in various criminal actions, including developing spyware capable of collecting sensitive data from devices and carrying out scraping, social engineering, and phishing attacks across several platforms. Meta also announced the eradication of thousands across from Facebook and Instagram, exhibiting “coordinated inauthentic behavior (CIB)” that originated in China, Myanmar, and Ukraine.
Article Link

 

ALPHV Gang Claims It’s the Attacker That Broke Into Prudential Financial, LoanDepot
Source: The Register
The ALPHV/BlackCat ransomware group claims to have executed cyberattacks against Prudential Financial and LoanDepot, calling into question the transparency of the companies’ disclosures about the breaches. Although Prudential Financial stated that the breach occurred on February 4 and was contained the following day, ALPHV alleges ongoing access to the network and active data exfiltration. Similarly, LoanDepot acknowledged a breach in early January but did not confirm ransomware involvement. ALPHV accuses LoanDepot of stalling negotiations after an initial ransom demand of $6 million, claiming that the company ceased communication after seeking more time. While both companies have not reported any data leaks, the situation highlights the ongoing threat of ransomware groups like ALPHV.
Article Link

 


VULNERABILITIES TO WATCH

 

GL-AX1800 Router Security Flaw Let Attackers Execute Remote Code
Source: Cyber Security News
During their evaluation, Hadess security researchers found a major vulnerability in the GL-AX1800 router, CVE-2023-47464. The GL-AX1800 router is a dual-band gadget that offers low-latency gaming, compatibility for many devices, and fast data transfer. The vulnerabilities found include file overwrite vulnerabilities allowing remote code execution (RCE), path traversal vulnerabilities, CSRF attack vulnerability, and uncontrolled file access downloads. It is imperative to address these vulnerabilities promptly to guarantee network device security and shield users from possible dangers. A Proof of Concept (PoC) showcasing the exploitation of the CVE-2023-47464 vulnerability has been made available by Hadess.
Article Link

 

 

RCE Vulnerabilities Fixed in SolarWinds Enterprise Solutions
Source: Help Net Security
SolarWinds has issued updates for Access Rights Manager (ARM) and the Orion Platform, which address several vulnerabilities, including major directory traversal and high-severity deserialization bugs that might result in remote code execution (RCE). The vulnerabilities in ARM v2023.2 have been patched in v2023.2.3. The Orion Platform has been upgraded to version 2024.1, which includes patches for SQL injection vulnerabilities discovered by security researcher Piotr Bazydło.
Article Link

 

Hackers Exploit Critical RCE Flaw in Bricks WordPress Site Builder
Source: Bleeping Computer
Hackers have been found exploiting a critical RCE vulnerability affecting the Bricks Builder Theme, a widely-used WordPress site builder theme with approximately 25,000 active installations. Discovered by researcher ‘snicco’ on February 10 and tracked as CVE-2024-25600, the vulnerability stems from an eval function call within the ‘prepare_query_vars_from_settings’ function. This flaw could enable unauthorized individuals to execute arbitrary PHP code on vulnerable websites. The Patchstack platform for WordPress security vulnerabilities promptly notified the Bricks team, leading to the release of a fix on February 13 with version 1.9.6.1. Although there is no evidence of active exploitation at the time of the fix’s release, users are strongly advised to update to the latest version as soon as possible to mitigate potential risks. 
Article Link

 

SPECIAL REPORTS

 

How to Make Sense of the New SEC Cyber Risk Disclosure Rules
Source: Help Net Security
The Securities and Exchange Commission (SEC) implemented new cybersecurity disclosure rules on December 18, 2023, requiring businesses to enhance transparency regarding cybersecurity incidents. These regulations affect both public companies and private enterprises, necessitating a reevaluation of cybersecurity disclosure practices. Public companies must report material incidents within four business days and disclose incidents on SEC Form 8-K, alongside annual Form 10-K reporting. Private companies within public supply chains must also comply with these rules, as the SEC has demonstrated an intent to hold them accountable as well. Cybersecurity teams must revamp data collection practices for timely incident reporting, involving collaboration between cybersecurity, legal, and investor relations teams. Automation, anomaly detection, and comprehensive forensic analysis are essential for efficient incident reporting and bolstering cybersecurity effectiveness.
Article Link

 

Q&A: The Cybersecurity Training Gap in Industrial Networks
Source: Darkreading
As cyberattacks on industrial control systems (ICS) and operational technology (OT) networks become increasingly frequent, the scarcity of cybersecurity training for critical infrastructure operators poses significant challenges. Irfan Shakeel, VP of Training and Certification Services at OPSWAT, highlights the urgency in protecting industrial networks, particularly OT environments, where legacy systems and a lack of security awareness contribute to vulnerabilities. Despite the abundance of cybersecurity training for IT professionals, OT defenders lack resources, leading to a knowledge gap in securing OT environments. Shakeel emphasizes the importance of providing proper education and training to OT personnel to effectively protect critical infrastructure against evolving cyber threats.
Article Link

 

How Decentralized Identity Is Shaping the Future of Data Protection
Source: Help Net Security
Decentralized identity (DCI) promises enhanced user control and privacy by redistributing identity management responsibilities. Patrick Harding, Chief Architect at Ping Identity, discusses the implications of DCI in cybersecurity, emphasizing its potential to minimize fraud risks and increase privacy. Harding explains the roles of three key parties: issuers, holders, and verifiers. Issuers create verifiable digital credentials containing unique identity attributes, empowering individuals to selectively disclose claims when necessary, thereby enhancing privacy and reducing fraud risks.
Article Link