OSINT Updates for November 21 , 2024

https://twitter.com/RakeshKrish12/status/1859476613962006541 https://twitter.com/RedPacketSec/status/1859395091539902864 https://twitter.com/RedPacketSec/status/1859388523238895878 https://twitter.com/RedPacketSec/status/1859395097902604390 https://twitter.com/stealthmole_iol/status/1859433837832655260 https://twitter.com/TMRansomMon/status/1859488698724761825 https://twitter.com/TMRansomMon/status/1859485658428932507

‘SteelFox’ Malware Blitz Infects 11K Victims With Bundle of Pain

CategoryDetailsThreat ActorsUnidentified; deploying the SteelFox malware campaign.Campaign OverviewActive since February 2023, SteelFox is a mass-targeting…

CVE-2024-9264: A Critical Vulnerability in Grafana : Vulnerability Analysis and Exploitation

CategoryDetailsThreat ActorsNation-state Actors, Cybercriminals, and Insiders exploiting CVE-2024-9264.Campaign OverviewCVE-2024-9264 enables low-privilege users to execute arbitrary…

FBI says BianLian Based in Russia, Moving from Ransomware Attacks to Extortion

Category Details Threat Actors BianLian Ransomware group, likely based in Russia with Russian affiliates. Campaign…

Phobos Ransomware Indictment Sheds Light on Long-Running, quietly Successful Scheme

Category Details Threat Actors Phobos Ransomware group; key figure: Russian National Evgenii Ptitsyn. Campaign Overview…

Five alleged members of Scattered Spider cybercrime group charged for breaches, theft of $11 million

Category Details Threat Actors Scattered Spider (also referred to as "The Community" or "The Com").…

Sophos MDR blocks and tracks activity from probable Iranian state actor “MuddyWater”

Key Detail Description Threat Actors Iranian threat actor, MuddyWater (TA450). Campaign Overview Phishing campaign using…

ELPACO-Team Ransomware: A New Variant of the MIMIC Ransomware Family

CategoryDetailsThreat Actors ELPACO-Team ransomware identified as part of the Mimic ransomware family, potentially linked to…

Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware

CategoryDetailsThreat ActorsIgnoble Scorpius (formerly Royal ransomware, also tied to Conti)Campaign OverviewIncreased activity from March 2024…

OSINT Updates for November 20 , 2024

https://twitter.com/marktsec46065/status/1858766026982212004 https://twitter.com/Erik_vd_Veen_/status/1858853292732019189 https://twitter.com/cyb_detective/status/1858841433752694862 https://twitter.com/IntlFinanceMag/status/1859051982742581519 https://twitter.com/hackinarticles/status/1859097360770502787 https://twitter.com/Phish_Destroy/status/1859102116654313608 https://twitter.com/DailyRansomware/status/1859058109794144330 https://twitter.com/DailyRansomware/status/1859058068195013096