Threat Intelligence Bulletin: 05/19/2023 - 05/25/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 05/19/2023 - 05/25/2023
ZeroFox Daily Intelligence Briefs:
ZeroFox Daily Intelligence Brief - May 25, 2023
Brief Highlights
- China State-Sponsored Cyber Actor Evades Detection with Stealth Techniques
- Barracuda Discloses Zero-Day Bug in Email Security Gateway Appliance
- GitLab Strongly Recommends Patching Max Severity Flaw
- CVE-2022-30256
- CVE-2023-2732
- CVE-2023-31861
- CVE-2012-0391
- CVE-2023-2732
- CVE-2009-0658
- Credit Card Data Breach: 2023-5-24
Report: https://zerofox.com/advisories/20679
ZeroFox Daily Intelligence Brief - May 24, 2023
Brief Highlights
- U.S. Treasury Department Imposes Fresh Sanctions to Combat North Korea’s Illicit Revenue
- Arms Maker Rheinmetall Confirms BlackBasta Ransomware Attack
- GoldenJackal: New Threat Group Targeting Middle Eastern and South Asian Governments
- CVE-2023-30763
- CVE-2023-29242
- CVE-2023-31922
- CVE-2019-9596
- Credit Card Data Breach: 2023-5-23
- April Logs Botnet Breach
- BreachForums: 1.6KK_VIP_GOLD Combolist
Report: https://zerofox.com/advisories/20666
ZeroFox Daily Intelligence Brief - May 23, 2023
Brief Highlights
- ZeroFox Intelligence Brief: An Overview of 5G and Potential Vulnerabilities: A ZeroFox Intelligence Brief
- Indonesian Cybercriminals Exploit AWS for Crypto Mining Operations
- CVE-2023-2844
- CVE-2023-28409
- CVE-2023-28413
- Credit Card Data Breach: 2023-5-22
Report: https://zerofox.com/advisories/20655
ZeroFox Daily Intelligence Brief - May 22, 2023
Brief Highlights
- Notorious Cyber Gang Returns for New Wave of Financially Motivated Attacks
- Luxottica Confirms 2021 Data Breach After Information of 70 Million Customers Leaks Online
- CISA: Samsung ASLR Bypass Bug Actively Exploited by Threat Actors
- CVE-2021-31239
- CVE-2023-2726
- CVE-2023-2721
- Credit Card Data Breach: 2023-5-21
Report: https://zerofox.com/advisories/20641
ZeroFox Daily Intelligence Brief - May 19, 2023
Brief Highlights
- Six-Year-Old Bug Weaponized by Notorious Cryptojacker 8220 Gang
- Security Bugs Revealed in Parental Control App Downloaded over Five Million Times
- KeePass Flaw Allows Retrieval of Master Password Through Memory Dumps
- CVE-2023-1729
- CVE-2023-24805
- CVE-2023-2704
- CVE-2016-0189
- CVE-2011-4642
- Credit Card Data Breach: 2023-5-18
- XIII_LOGS.zip
Report: https://zerofox.com/advisories/20607
Breach Disclosures:
Breach Disclosure: uk_5m
Summary
A combolist breach package titled “uk_5m" exposed 4,995,149 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20640
Breach Disclosure: Le Petit Béret
Summary
An alleged data breach at Le Petit Béret – a U.S.-based an online influencer network that claims to help users monetize social media usage – exposed 20,250 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20629
Breach Disclosure: usa_vegan
Summary
A combolist breach package titled “usa_vegan" exposed 18,948 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20628
Breach Disclosure: Shopper Plus
Summary
An alleged data breach at Shopper Plus – a Canada-based online retail company – exposed 878,030 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20627
Breach Disclosure: usa_sextoy
Summary
A combolist breach package titled “usa_sextoy" exposed 12,063 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20626
Breach Disclosure: Classmates
Summary
An alleged data breach at Classmates – a U.S.-based social networking service site – exposed 2,341,101 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20625
Breach Disclosure: office365_dump
Summary
A combolist breach package titled “office365_dump" exposed 148,338 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20624
Breach Disclosure: Germany_100k
Summary
A combolist breach package titled “Germany_100k" exposed 99,964 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20623
Breach Disclosure: usa_dump_combo
Summary
A combolist breach package titled “usa_dump_combo" exposed 7,315,842 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20622
Breach Disclosure: usa_home
Summary
A combolist breach package titled “usa home" exposed 17,308 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20621
Breach Disclosure: 5M_Dump
Summary
A combolist breach package titled “5 Million Email" exposed 5,000,000 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20620
Breach Disclosure: canada_b2b
Summary
A combolist breach package titled “canada_b2b" exposed 3,001 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20619
Breach Disclosure: LovePlanet
Summary
An alleged data breach at LovePlanet – a Ukraine-based online dating site – exposed 19,284,401 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20618
Breach Disclosure: usa_actorDB
Summary
A combolist breach package titled “usa_actorDB" exposed 32,700 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20617
Breach Disclosure: Tele2
Summary
An alleged data breach at Tele2 – a Russia-based mobile network operator providing services– exposed 5,678,238 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20616
Breach Disclosure: Office of Civil Defense Philippines
Summary
An alleged data breach at Office of Civil Defense Philippines – a Philippines-based defense organization – exposed 377 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20615
Breach Disclosure: 500K_US
Summary
A combolist breach package titled “500K_US" exposed 99,146 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20614
Breach Disclosure: Paid Leaf
Summary
An alleged data breach at Paid Leaf – a U.S.-based an online influencer network that claims to help users monetize social media usage – exposed 67,472 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20612
Breach Disclosure: Randizzon
Summary
An alleged data breach at Randizzon – a Hungary-based dating site – exposed 1,592,553 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20611
Breach Disclosure: CoinTracker
Summary
An alleged data breach at CoinTracker – a U.S.-based web-3.0 financial service – exposed 1,557,147 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20610
Breach Disclosure: 4.4M_USA
Summary
A combolist breach package titled “4.4M_USA" exposed 4,468,872 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20609
Breach Disclosure: Tuprode
Summary
An alleged data breach at Tuprode – an Argentina-based online sports forecasting gaming site – exposed 21,704 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20608
Breach Disclosure: USA_Gov_Emails
Summary
A combolist breach package titled “USA_Gov_Emails" exposed 3,709 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20606
Breach Disclosure: 500K_Email_Pass
Summary
A combolist breach package titled “500K_Email_Pass" exposed 486,499 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20605
Breach Disclosure: CoinDesk
Summary
An alleged data breach at CoinDesk– a U.S.-based media outlet for news and information on cryptocurrency and digital asset – exposed 17,792 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20604
Breach Disclosure: usa_med
Summary
A combolist breach package titled “usa_med" exposed 21,443 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20603
Breach Disclosure: Argentina_100k
Summary
A combolist breach package titled “Argentina_100k" exposed 99,998 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20602
Breach Disclosure: Information Britain
Summary
An alleged data breach at Information Britain– a U.K.-based website that provides information about various aspects of travel and tourism in the United Kingdom – exposed 4,118 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20601
Breach Disclosure: NOVA Entertainment
Summary
An alleged data breach at NOVA Entertainment – an Australia-based company that operates in media and entertainment – exposed 249,136 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20600
Breach Disclosure: Battlefy
Summary
An alleged data breach at Battlefy – a Canada-based online gaming platform – exposed 83,651 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20599
Breach Disclosure: Killbillet
Summary
An alleged data breach at Killbillet – a U.S.-based rat road store – exposed 29,005 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20598
Breach Disclosure: Weee!
Summary
An alleged data breach at Weee! – a U.S.-based grocery store – exposed 1,136,413 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20597
Breach Disclosure: World Media Rights
Summary
An alleged data breach at World Media Rights – a U.K.-based producer of television shows and series – exposed 35,851 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20596
Breaking News:
Harvard Pilgrim Health Care Notifies Individuals of Privacy Incident
On April 17, 2023, Point32Health, the parent organization of Harvard Pilgrim Health Care ("Harvard Pilgrim") and Tufts Health Plan, identified a cybersecurity ransomware incident on its computer systems and is working with third-party cybersecurity experts to conduct a thorough investigation into this incident and remediate the situation. The investigation identified signs that data was copied and taken from Harvard Pilgrim systems between March 28, 2023, and April 17, 2023.
See the full report here: https://www.darkreading.com/endpoint/harvard-pilgrim-health-care-notifies-individuals-of-privacy-incident
Cyber Attacks Strike Ukraine's State Bodies in Espionage Operation
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks targeting state bodies in the country as part of an espionage campaign. The intrusion set, attributed to a threat actor tracked by the authority as UAC-0063 since 2021, leverages phishing lures to deploy a variety of malicious tools on infected systems. The origins of the hacking crew are presently unknown. In the attack chain described by the agency, the emails targeted an unspecified ministry and purported to be from the Embassy of Tajikistan in Ukraine.
See the full report here: https://thehackernews.com/2023/05/cyber-attacks-strike-ukraines-state.html
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage Malware
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to deploy malware on targeted systems. The findings detailed the advanced persistent threat's (APT) continued abuse of DLL side-loading techniques to run arbitrary payloads. The threat actor places a malicious DLL (msvcr100.dll) in the same folder path as a normal application (Wordconv.exe) via the Windows IIS web server process, w3wp.exe. They then execute the normal application to initiate the execution of the malicious DLL.
See the full report here: https://thehackernews.com/2023/05/n-korean-lazarus-group-targets.html
Legion Malware Upgraded to Target SSH Servers and AWS Credentials
An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials associated with DynamoDB and CloudWatch. Legion, a Python-based hack tool, was first documented in May 2023, detailing its ability to breach vulnerable SMTP servers in order to harvest credentials.
See the full report here: https://thehackernews.com/2023/05/legion-malware-upgraded-to-target-ssh.html
Data Stealing Malware Discovered in Popular Android Screen Recorder App
Google has removed a screen recording app named "iRecorder - Screen Recorder" from the Play Store after it was found to sneak in information stealing capabilities nearly a year after the app was published as an innocuous app. The app (APK package name "com.tsoft.app.iscreenrecorder"), which accrued over 50,000 installations, was first uploaded on September 19, 2021. The malicious functionality is believed to have been introduced in version 1.3.8, which was released on August 24, 2022.
See the full report here: https://thehackernews.com/2023/05/data-stealing-malware-discovered-in.html
Barracuda warns of email gateways breached via zero-day flaw
Barracuda, a company known for its email and network security solutions, warned customers that some of its Email Security Gateway (ESG) appliances were breached by targeting a now-patched zero-day vulnerability. A vulnerability was discovered in the email attachment scanning module. The issue was addressed by applying two security patches on May 20 and 21, 2023.While the flaw was patched over the weekend, Barracuda warned that some of its customers' ESG appliances were compromised by exploiting the now-patched security bug.
See the full report here: https://www.bleepingcomputer.com/news/security/barracuda-warns-of-email-gateways-breached-via-zero-day-flaw/
Iranian hackers use new Moneybird ransomware to attack Israeli orgs
A suspected Iranian state-supported threat actor known as "Agrius" is now deploying a new ransomware strain named "Moneybird" against Israeli organizations. Agrius has been actively targeting entities in Israel and the Middle East region since at least 2021 under multiple aliases while deploying data wipers in destructive attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/iranian-hackers-use-new-moneybird-ransomware-to-attack-israeli-orgs/
New PowerExchange malware backdoors Microsoft Exchange servers
A new PowerShell-based malware dubbed PowerExchange was used in attacks linked to APT34 Iranian state hackers to backdoor on-premise Microsoft Exchange servers. After infiltrating the mail server via a phishing email containing an archived malicious executable, the threat actors deployed a web shell named ExchangeLeech (first observed by the Digital14 Incident Response team in 2020) that can steal user credentials.
See the full report here: https://www.bleepingcomputer.com/news/security/new-powerexchange-malware-backdoors-microsoft-exchange-servers/
GitLab strongly recommends patching max-severity flaw
GitLab has released an emergency security update, version 16.0.1, to address a maximum severity (CVSS v3.1 score: 10.0) path traversal flaw tracked as CVE-2023-2825. The vulnerability impacts GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0.0, but all versions older than these aren't affected.
See the full report here: https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/
Chinese hackers breach US critical infrastructure in stealthy attacks
A Chinese cyberespionage group tracked as Volt Typhoon has been targeting critical infrastructure organizations across the United States, including Guam, since at least mid-2021. Their victims span a wide range of critical sectors, including government, maritime, communications, manufacturing, information technology, utilities, transportation, construction, and education. The Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises. The initial attack vector is the compromise of Internet-exposed Fortinet FortiGuard devices by exploiting an unknown zero-day vulnerability.
See the full report here: https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-us-critical-infrastructure-in-stealthy-attacks/
Hackers target 1.5 million WordPress sites with cookie consent plugin exploit
Ongoing attacks are targeting an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in a WordPress cookie consent plugin named Beautiful Cookie Consent Banner with more than 40,000 active installs. In XSS attacks, threat actors inject malicious JavaScript scripts into vulnerable websites that will execute within the visitors' web browsers. The impact can include unauthorized access to sensitive information, session hijacking, malware infections via redirects to malicious websites, or a complete compromise of the target's system.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-target-15m-wordpress-sites-with-cookie-consent-plugin-exploit/
The FBI Warns of False Job Advertisements Linked to Labor Trafficking at Scam Compounds
The FBI has warned U.S. citizens and individuals who travel or live abroad of the risk of false job advertisements linked to labor trafficking at Southeast Asia-based scam compounds where victims are held against their will, intimidated, and forced to commit international cryptocurrency investment fraud schemes. Criminal actors target victims, primarily in Asia, in employment fraud schemes by posting false job advertisements on social media and online employment sites.
See the full report here: https://www.ic3.gov/Media/Y2023/PSA230522#fn2
Russian Hackers Target Indian Insurance Body
The Insurance Information Bureau of India (IIB), an independent body which maintains a repository of insurance-related information in the country, approached Cyberabad police stating that hackers from Russia encrypted their data through ransomware attack and demanded BTC worth USD 250,000 to undo the damage. On April 2, 2023, some IIB staff failed to log into their office network and a subsequent inquiry showed a ransomware attack. The data in the IIB servers was encrypted by the attackers making it inaccessible for the agency. The IIB officials did not publicise the attack and it is suspected that most data is still with cyber attackers.
See the full report here: https://m.timesofindia.com/city/hyderabad/russian-hackers-carry-out-ransomware-attack-iib-hit/articleshow/100433653.cms
China Bans U.S. Chip Giant Micron, Citing Serious Cybersecurity Problems
China has banned U.S. chip maker Micron from selling its products to Chinese companies working on key infrastructure projects, citing national security risks. The development comes nearly two months after the country's cybersecurity authority initiated a probe in late March 2023 to assess potential network security risks.
See the full report here: https://thehackernews.com/2023/05/china-bans-us-chip-giant-micron-citing.html
New WinTapix.sys Malware Engages in Multi-Stage Attack Across Middle East
An unknown threat actor has been observed leveraging a malicious Windows kernel driver in attacks likely targeting the Middle East since at least May 2020. "WinTapix.sys is essentially a loader," security researchers Geri Revay and Hossein Jazi said in a report. The campaign's primary focus is on Saudi Arabia, Jordan, Qatar, and the United Arab Emirates. The activity has not been tied to a known threat actor or group.
See the full report here: https://thehackernews.com/2023/05/new-wintapixsys-malware-engages-in.html
Cuba ransomware claims cyberattack on Philadelphia Inquirer
The Cuba ransomware gang has claimed responsibility for a cyberattack on The Philadelphia Inquirer, which temporarily disrupted the newspaper's distribution and disrupted some business operations. The Philadelphia Inquirer is the third-longest continuously operating daily newspaper in the U.S. On May 14, 2023, the company disclosed that it had suffered a cyberattack that forced its IT team to take computer systems offline to prevent the attack's spread.
See the full report here: https://www.bleepingcomputer.com/news/security/cuba-ransomware-claims-cyberattack-on-philadelphia-inquirer/
New AhRat Android malware hidden in app with 50,000 installs
Researchers found a new remote access trojan (RAT) on the Google Play Store, hidden in an Android screen recording app with tens of thousands of installs. While first added to the store in September 2021, the '"Recorder - Screen Recorder" app was likely trojanized via a malicious update released almost a year later, in August 2022. The app's name made it easier to ask permission to record audio and access files on the infected devices since the request matched the expected capabilities of a screen recording tool. Before its removal, the app amassed over 50,000 installations on the Google Play Store, exposing users to malware infections.
See the full report here: https://www.bleepingcomputer.com/news/security/new-ahrat-android-malware-hidden-in-app-with-50-000-installs/
IT employee impersonates ransomware gang to extort employer
A person from the United Kingdom has been convicted of unauthorized computer access with criminal intent and blackmailing his employer. A press release published by the South East Regional Organised Crime Unit (SEROCU) explains that in February 2018, the convicted man worked as an IT Security Analyst at an Oxford-based company that suffered a ransomware attack. Like many ransomware attacks, the threat actors contacted the company's executives, demanding a ransom payment.
See the full report here: https://www.bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/
Arms maker Rheinmetall confirms BlackBasta ransomware attack
German automotive and arms manufacturer Rheinmetall AG confirmed that it suffered a BlackBasta ransomware attack that impacted its civilian business. Rheinmetall is a German manufacturer of automotive, military vehicles, armaments, air defense systems, engines, and various steel products, which employs over 25,000 people and has an annual revenue of over USD 7 billion. On Saturday, May 20th, 2023, BlackBasta posted Rheinmetall on its extortion site along with samples of the data the hackers claimed to have stolen from the German company.
See the full report here: https://www.bleepingcomputer.com/news/security/arms-maker-rheinmetall-confirms-blackbasta-ransomware-attack/
US sanctions orgs behind North Korea’s ‘illicit’ IT worker army
The Treasury Department's Office of Foreign Assets Control (OFAC) announced sanctions against four entities and one individual for their involvement in illicit IT worker schemes and cyberattacks generating revenue to finance North Korea's weapons development programs. North Korea's illicit revenue generation strategy relies heavily on a massive "army" of thousands of IT workers who hide their identities to get hired by companies overseas. To secure employment with targeted companies, they employ various deceptive tactics, including using stolen identities, fake personas, and falsified or forged documentation.
See the full report here: https://www.bleepingcomputer.com/news/security/us-sanctions-orgs-behind-north-koreas-illicit-it-worker-army/
GoldenJackal state hackers silently attacking govts since 2019
A relatively unknown advanced persistent threat (APT) group named "GoldenJackal" has been targeting government and diplomatic entities in Asia since 2019 for espionage. The threat actors have maintained a low profile for stealthiness, carefully selecting their victims and keeping the number of attacks at a minimum to reduce the likelihood of exposure. Researchers have been tracking GoldenJackal since 2020, and report that the threat actors have had notable activity in Afghanistan, Azerbaijan, Iran, Iraq, Pakistan, and Turkey.
See the full report here: https://www.bleepingcomputer.com/news/security/goldenjackal-state-hackers-silently-attacking-govts-since-2019/
New BATLOADER campaign leverages generative AI ads for RedLine stealer delivery
RedLine stealer has been distributed in a new BATLOADER campaign exploiting Google Search advertisements for the ChatGPT and Midjourney generative AI services. Attackers have been leveraging keywords on Google that would show fraudulent ads that would redirect to webpages facilitating the installation of ChatGPT or Midjourney executables along with a PowerShell script enabling RedLine stealer downloads, while detection of malicious activity after installation is averted by the binary's use of Microsoft Edge WebView2 that would allow the loading of legitimate ChatGPT and Midjourney URLs.
See the full report here: https://www.scmagazine.com/brief/malware/new-batloader-campaign-leverages-generative-ai-ads-for-redline-stealer-delivery
Golden Chickens malware developer unmasked
Golden Chickens malware, which has been used by the Russian Cobalt Group and FIN6 cybercrime operations, had its second developer identified to be a Romanian citizen known as Lucky and badbullzvenom. Password stealers were Jack's main specialty when he began engaging in cybercrime as a teen, releasing the Voyer malware tool for exfiltrating Yahoo instant messages between 2007 and 2008, followed by the FlyCatcher tool for keystroke logging between 2008 and 2009, and the Con password stealer for browser, instant messenger, VPN, and FTP app credential theft in 2010.
See the full report here: https://www.scmagazine.com/brief/uncategorized/golden-chickens-malware-developer-unmasked
Sanctioned Crypto Mixer Tornado Cash Hijacked by Hackers
Tornado Cash, a service that allows users to mask cryptocurrency transactions, suffered a hostile takeover by hackers through a malicious governance proposal. A security researcher said on Twitter that an attacker granted themselves 1.2 million fake votes. As the fake votes exceeded the 700,000 legitimate votes, it allowed the attacker to gain full control over the governance of Tornado Cash.
See the full report here: https://www.bloomberg.com/news/articles/2023-05-21/sanctioned-crypto-mixer-tornado-cash-hijacked-by-hackers#xj4y7vzkg
U.K. Fraudster Behind iSpoof Scam Receives 13-Year Jail Term for Cyber Crimes
A U.K. national responsible for his role as the administrator of the now-defunct iSpoof online phone number spoofing service has been sentenced to 13 years and 4 months in prison. iSpoof, which was available as a paid service, allowed fraudsters to mask their phone numbers and masquerade as representatives from banks, tax offices, and other official bodies to defraud victims.
See the full report here: https://thehackernews.com/2023/05/uk-fraudster-behind-ispoof-scam.html
Bad Magic's Extended Reign in Cyber Espionage Goes Back Over a Decade
New findings about a hacker group linked to cyber attacks targeting companies in the Russo-Ukrainian conflict area reveal that it may have been around for much longer than previously thought. The threat actor, tracked as Bad Magic (aka Red Stinger), has not only been linked to a fresh sophisticated campaign, but also to an activity cluster that first came to light in May 2016. While the previous targets were primarily located in the Donetsk, Luhansk, and Crimea regions, the scope has now widened to include individuals, diplomatic entities, and research organizations in Western and Central Ukraine.
See the full report here: https://thehackernews.com/2023/05/bad-magics-extended-reign-in-cyber.html
Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations
A financially motivated threat actor of Indonesian origin has been observed leveraging Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances to carry out illicit crypto mining operations.The researchers who first detected the group in November 2021 have assigned it the moniker GUI-vil (pronounced Goo-ee-vil). The group displays a preference for Graphical User Interface (GUI) tools, specifically S3 Browser (version 9.5.5) for their initial operations.
See the full report here: https://thehackernews.com/2023/05/indonesian-cybercriminals-exploit-aws.html
CISA orders govt agencies to patch iPhone bugs exploited in attacks
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) ordered federal agencies to address three recently patched zero-day flaws affecting iPhones, Macs, and iPads known to be exploited in attacks. The security bugs are tracked as CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373, all found in the WebKit browser engine. They allow attackers to escape the browser sandbox, access sensitive information on the compromised device, and achieve arbitrary code execution following successful exploitation.
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-patch-iphone-bugs-exploited-in-attacks/
Crypto phishing service Inferno Drainer defrauds thousands of victims
A cryptocurrency phishing and scam service called '"Inferno Drainer" has reportedly stolen over USD 5.9 million worth of crypto from 4,888 victims. According to a report, the phishing service has created at least 689 fake websites since March 27, 2023. The malicious websites created with Inferno Drainer target 229 popular brands, including Pepe, Bob, MetaMask, OpenSea, Collab.Land, LayerZero, and others.
See the full report here: https://www.bleepingcomputer.com/news/security/crypto-phishing-service-inferno-drainer-defrauds-thousands-of-victims/
Pentagon explosion hoax goes viral after verified Twitter accounts push
Highly realistic AI-generated images depicting an explosion near the Pentagon that went viral on Twitter caused the stock market to dip. Tweets with images supposedly depicting an explosion near the Pentagon building in Arlington, Virginia, were amplified by many verified Twitter accounts, including a Russian state media one with millions of followers and a verified account impersonating the Bloomberg news agency. Even though the viral pictures seemed real at first glance, it's filled with hints that they were generated using artificial intelligence, proving that the entire thing is a hoax.
See the full report here: https://www.bleepingcomputer.com/news/security/pentagon-explosion-hoax-goes-viral-after-verified-twitter-accounts-push/
Malicious Windows kernel drivers used in BlackCat ransomware attacks
The ALPHV ransomware group (aka BlackCat) was observed employing signed malicious Windows kernel drivers to evade detection by security software during attacks. The driver is an improved version of the malware known as "POORTRY" that was spotted in earlier ransomware attacks. The POORTRY malware is a Windows kernel driver signed using stolen keys belonging to legitimate accounts in Microsoft's Windows Hardware Developer Program.
See the full report here: https://www.bleepingcomputer.com/news/security/malicious-windows-kernel-drivers-used-in-blackcat-ransomware-attacks/
“Hackers” demonstrate vulerabilities in European Space Agency’s OPS-SAT nanosatellite
In a capability demonstrator during an annual event on cybersecurity for the space industry, the European Space Agency (ESA) issued a challenge to cybersecurity professionals in the space industry ecosystem to interfere with the operation of the ESAs “OPS-SAT” demonstration nanosatellite.
See the full report here: https://eurasiantimes.com/cyberattack-on-esas-spacecraft-how-hackers-took-control-of/
Luxottica confirms 2021 data breach after info of 70M leaks online
Luxottica, an eyewear company has confirmed one of its partners suffered a data breach in 2021 that exposed the personal information of 70 million customers after a database was posted on hacking forums. In November 2022, a member of the now-defunct “Breached” hacker forum attempted to sell what he claimed to be a 2021 database containing 300 million records of personal information related to Luxottica customers in the United States and Canada. According to the seller, the database contained customers' personal information, such as email addresses, first and last names, addresses, and date of birth.
See the full report here: https://www.bleepingcomputer.com/news/security/luxottica-confirms-2021-data-breach-after-info-of-70m-leaks-online/
ASUS routers knocked offline worldwide by bad security update
ASUS has apologized to its customers for a server-side security maintenance error that has caused a wide range of impacted router models to lose network connectivity. The problem has been extensively reported on social media and discussion platforms since May 16, 2023, with people appearing puzzled by the simultaneous connectivity issues on multiple ASUS routers and others complaining about the lack of communication from the vendor's side.
See the full report here: https://www.bleepingcomputer.com/news/hardware/asus-routers-knocked-offline-worldwide-by-bad-security-update/
Microsoft: Notorious FIN7 hackers return in Clop ransomware attacks
A financially motivated cybercriminal group known as FIN7 resurfaced last month, with threat analysts linking it to attacks where the end goal was the deployment of Clop ransomware payloads on victims' networks. The group was observed deploying the Clop ransomware in opportunistic attacks in April 2023, its first ransomware campaign since late 2021. In these recent attacks, FIN7 attackers utilized the PowerShell-based POWERTRASH in-memory malware dropper to deploy the Lizar post-exploitation tool on compromised devices.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-notorious-fin7-hackers-return-in-clop-ransomware-attacks/
CISA warns of Samsung ASLR bypass flaw exploited in attacks
CISA has warned of a security vulnerability affecting Samsung devices used in attacks to bypass Android address space layout randomization (ASLR) protection. ASLR is an Android security feature that randomizes the memory addresses where key app and OS components are loaded into the device's memory. This makes it more difficult for attackers to exploit memory-related vulnerabilities and successfully launch attacks like buffer overflow, return-oriented programming, or other memory-based exploits. The flaw (CVE-2023-21492) impacts Samsung mobile devices running Android 11, 12, and 13 and is due to an insertion of sensitive information into log files.
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-warns-of-samsung-aslr-bypass-flaw-exploited-in-attacks/
npm packages caught serving TurkoRAT binaries that mimic NodeJS
Researchers have discovered multiple npm packages named after NodeJS libraries that even pack a Windows executable that resembles NodeJS but instead drops a sinister trojan. These packages, given their stealthiness and a very low detection rate, had been present on npm for over two months prior to their detection by the researchers.
See the full report here: https://www.bleepingcomputer.com/news/security/npm-packages-caught-serving-turkorat-binaries-that-mimic-nodejs/
HP rushes to fix bricked printers after faulty firmware update
HP is working to address a bad firmware update that has been bricking HP Office Jet printers worldwide since it was released earlier this month. Impacted printers include HP OfficeJet 902x models, including HP OfficeJet Pro 9022e, HP OfficeJet Pro 9025e, HP OfficeJet Pro 9020eAll-in-One, HP OfficeJet Pro 9025e All-in-One Printer Affected customers report that their devices display blue screens with "83C0000B" errors on the built-in touchscreen.
See the full report here: https://www.bleepingcomputer.com/news/technology/hp-rushes-to-fix-bricked-printers-after-faulty-firmware-update/
Cloned CapCut websites push information stealing malware
A new malware distribution campaign is underway, impersonating the CapCut video editing tool to push various malware strains to unsuspecting victims. CapCut is ByteDance's official video editor and maker for TikTok which has over 500 million downloads on Google Play alone, and its website receives over 30 million hits monthly. The application's popularity, combined with nationwide bans in Taiwan, India, and other places, has pushed users to seek alternative ways of downloading the program. Threat actors exploit this by creating websites that distribute malware disguised as CapCut installers.
See the full report here: https://www.bleepingcomputer.com/news/security/cloned-capcut-websites-push-information-stealing-malware/
PyPI temporarily pauses new users, projects amid high volume of malware
PyPI, the official third-party registry of open source Python packages has temporarily suspended new users from signing up, and new projects from being uploaded to the platform until further notice. The unexpected move comes amid the registry's struggle to upkeep with a large influx of malicious users and packages. PyPI temporarily halts new user, project signups. The Python Package Index, more commonly known as PyPI, has temporarily suspended new user registrations and project creations until further notice. New user and new project name registration on PyPI is temporarily suspended.
See the full report here: https://www.bleepingcomputer.com/news/security/pypi-temporarily-pauses-new-users-projects-amid-high-volume-of-malware/
Android phones are vulnerable to fingerprint brute-force attacks
Researchers have presented a new attack called "BrutePrint," which brute-forces fingerprints on modern smartphones to bypass user authentication and take control of the device. The researchers managed to overcome safeguards on smartphones, like attempt limits and liveness detection that protect against brute-force attacks, by exploiting what they claim are two zero-day vulnerabilities, namely Cancel-After-Match-Fail (CAMF) and Match-After-Lock (MAL). The authors of the technical paper also found that biometric data on the fingerprint sensors' Serial Peripheral Interface (SPI) were inadequately protected, allowing for a man-in-the-middle (MITM) attack to hijack fingerprint images.
See the full report here: https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/
Ransomware attack disrupts Lacroix production sites
International technological equipment supplier and IIoT solutions provider Lacroix Group had its electronic system production sites in Germany, France, and Tunisia shut down following a ransomware attack on May 12, 2023. Despite immediate action to contain the attack, Lacroix Group discovered that attackers were able to distribute file-encrypting ransomware that was able to compromise some of the company's local infrastructures. Investigation into the attack's extent is underway.
See the full report here: https://www.scmagazine.com/brief/ransomware/ransomware-attack-disrupts-lacroix-production-sites
Temu accused of data risks after sister app was suspended for malware
The U.S. has accused discount shopping site Temu of possible data risks after its Chinese sister app was pulled from Google’s app store over “malware” — but some security analysts say they’re not that worried. Compared with Pinduoduo, which was suspended by Google in March 2023 after versions offered outside Google’s Play store were found to contain malware, Temu is reportedly “not as aggressive.”
See the full report here: https://www.cnbc.com/2023/05/17/temu-accused-of-data-risks-amid-tiktok-pinduoduo-fears.html
New cybersecurity bills passed by House, Senate panels
Cybersecurity bills targeted at addressing vulnerabilities in open-source software and satellites have been approved by the House and Senate Homeland Security Committees. Bipartisan legislation mandating the Cybersecurity and Infrastructure Security Agency to create a risk framework for open-source software usage in the federal government has been advanced by the House panel to accompany a measure approved by the Senate panel in March 2023, which also seeks to significantly mitigate open-source vulnerabilities that have gained the spotlight following the widespread Log4j hack.
See the full report here: https://www.scmagazine.com/brief/critical-infrastructure/new-cybersecurity-bills-passed-by-house-senate-panels
Darknet Carding Kingpin Pleads Guilty: Sold Financial Info of Tens of Thousands
A U.S. national has pleaded guilty in a Missouri court to operating a darknet carding site and selling financial information belonging to tens of thousands of victims in the country. The suspect has been accused of setting up a carding site called Skynet Market that specialized in the trafficking of credit and debit card data. He and his associates also peddled their wares on other dark web marketplaces such as AlphaBay Market, Wall Street Market, and Hansa Market between February 22, 2016, and October 1, 2019.
See the full report here: https://thehackernews.com/2023/05/darknet-carding-kingpin-pleads-guilty.html
8220 Gang Exploiting Oracle WebLogic Flaw to Hijack Servers and Mine Cryptocurrency
The notorious cryptojacking group tracked as 8220 Gang has been spotted weaponizing a six-year-old security flaw in Oracle WebLogic servers to ensnare vulnerable instances into a botnet and distribute cryptocurrency mining malware. The flaw in question is CVE-2017-3506 (CVSS score: 7.4), which, when successfully exploited, could allow an unauthenticated attacker to execute arbitrary commands remotely. This allows attackers to gain unauthorized access to sensitive data or compromise the entire system.
See the full report here: https://thehackernews.com/2023/05/8220-gang-exploiting-oracle-weblogic.html
Escalating China-Taiwan Tensions Fuel Alarming Surge in Cyber Attacks
The rising geopolitical tensions between China and Taiwan in recent months have sparked a noticeable uptick in cyber attacks on the East Asian island country. From malicious emails and URLs to malware, the strain between China's claim of Taiwan as part of its territory and Taiwan's maintained independence has evolved into a worrying surge in attacks.
See the full report here: https://thehackernews.com/2023/05/escalating-china-taiwan-tensions-fuel.html
KeePass exploit helps retrieve cleartext master password, fix coming soon
The popular KeePass password manager is vulnerable to extracting the master password from the application's memory, allowing attackers who compromise a device to retrieve the password even with the database is locked. Password managers allow users to create unique passwords for every online account and store the credentials in an easy-to-search database, or password vault, so you do not have to remember each one. However, to properly secure this password vault, users must remember the one master password used to unlock it and access stored credentials.
See the full report here: https://www.bleepingcomputer.com/news/security/keepass-exploit-helps-retrieve-cleartext-master-password-fix-coming-soon/
Apple fixes three new zero-days exploited to hack iPhones, Macs
Apple has addressed three new zero-day vulnerabilities exploited in attacks to hack into iPhones, Macs, and iPads. The security bugs were all found in the multi-platform WebKit browser engine and are tracked as CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373.
See the full report here: https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/
18-year-old charged with hacking 60,000 DraftKings betting accounts
The U.S. Department of Justice revealed that an 18-year-old man from Wisconsin had been charged with hacking into the accounts of around 60,000 users of the DraftKings sports betting website in November 2022. According to the complaint, the suspect used an extensive list of credentials from other breaches to hack into the accounts. He then sold the hijacked accounts, and the buyers stole approximately USD 600,000 from around 1,600 compromised accounts.
See the full report here: https://www.bleepingcomputer.com/news/security/18-year-old-charged-with-hacking-60-000-draftkings-betting-accounts/
ZeroFox Intelligence Reports:
ZeroFox Intelligence Brief - Continued Backlash over Pension Reform Expected in France
Summary Since January 2023, France has been gripped by union strikes, protests, and violence on the streets due to President Macron’s centerpiece domestic reform that raised the retirement age from 62 to 64 years. The ZeroFox Geopolitical Working Group has been monitoring these events, in addition to assessing how upcoming major world events such as the French Open tennis tournament and Summer Olympics in 2024 could serve as the backdrop for more intense social unrest.
Report: https://zerofox.com/advisories/20643
ZeroFox Intelligence Brief - An Overview of 5G and Potential Vulnerabilities
Summary In this ZeroFox Intelligence Brief, ZeroFox researchers provide an overview of 5G and its associated potential vulnerabilities. The technology will eventually serve as a successor to 4G Long-Term Evolution (LTE) technology, and reporting approximates that there were one billion 5G subscriptions across the globe at the end of 2022, which is forecasted to rise as high as five billion by 2026. However, the implementation and commercial availability of 5G has been subject to criticism across North America, Western Europe, and Asia.
Report: https://zerofox.com/advisories/20642
Tags: tlp:clear, all industries, global