zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 29, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 29, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence - Q1 2023 Public Sector Quarterly Threat Landscape Report
  • Russia-Linked COSMICENERGY Malware Threatens to Sabotage Power Grids
  • New Phishing Kit Abuses ZIP domains
  • Vulnerabilities: CVE-2022-36345, CVE-2023-33926, and CVE-2023-33332
  • Exploits: CVE-2013-1763 and CVE-2018-9023
  • Breaches: Credit Card Data Breach - 2023-5-27 and Credit Card Data Breach - 2023-5-26

ZeroFox Intelligence - Q1 2023 Public Sector Quarterly Threat Landscape Report

A ZeroFox Intelligence report has highlighted the significant threat to public-sector employees from SMS phishing (smishing), callback phishing (vishing), spear phishing, and multi-factor authentication (MFA) bypass attacks. State-aligned threat actors have also been observed conducting cyber espionage against public-sector bodies and personnel. Moreover, initial access brokers are increasingly selling illicit access to established buyers via private means of communication, making identification and mitigation challenging.

Russia-Linked COSMICENERGY Malware Threatens to Sabotage Power Grids

A strain of malicious software, COSMICENERGY, targets critical systems in industrial environments and can disrupt electricity transmission and distribution. A threat actor would first need to deduce the IEC-104 device IP addresses as well as gain access to Microsoft SQL Server credentials for a successful attack. The rarity of such malware amplifies the danger, as the malware exploits inherent vulnerabilities in operational technology (OT) environments that are unlikely to be addressed in the near future.

New Phishing Kit Abuses ZIP Domains

A new phishing kit called "File Archivers in the Browser" exploits ZIP domains by creating fake WinRAR or Windows File Explorer windows in the browser. Ever since the release of the ZIP top-level domain (TLD), there has been considerable debate regarding its potential for abuse by malicious actors. Such domains can lure users into launching malicious files through the use of clickable “.zip” strings, which can deliver malware or initiate phishing attacks.

VULNERABILITIES

  • CVE-2022-36345 - Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.
  • CVE-2023-33926 - Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.
  • CVE-2023-33332 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.

EXPLOITS

  • CVE-2013-1763 - Exploit for Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation 2013-1763 CVE-2013-1763
  • CVE-2018-9023 - FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - SETFKEY

BREACHES

Tags: DIB, tlp:green