Threat Intelligence Bulletin: 05/26/2023 - 06/01/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 05/26/2023 - 06/01/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - June 1, 2023
Brief Highlights
- ZeroFox Intelligence Flash Report: EDR Bypass Claims Spark Mixed Reactions
- Enzo Biochem Discloses Ransomware Attack Affecting Clinical Data of 2.5 Million Individuals
- Abandoned Salesforce Sites Pose Data-Security Risks
- Vulnerabilities: CVE-2023-2942, CVE-2023-2944, and CVE-2023-32964
- Exploits: CVE-2016-9793, CVE-2017-17562, and CVE-2010-1870
- Breaches: Credit Card Data Breach: 2023-5-30 and Credit Card Data Breach: 2023-5-31
Report: https://zerofox.com/advisories/20736
ZeroFox Daily Intelligence Brief - May 31, 2023
Brief Highlights
- ZeroFox Intelligence Cyber Threat Advisory: Ransomware Update
- CISA Industrial Control Systems Advisory: Advantech WebAccess/SCADA
- DogeRAT Malware Impersonates BFSI, Entertainment, and E-Commerce Apps
- Vulnerabilities: CVE-2022-47178, CVE-2023-2952, and CVE-2023-29741
- Exploits: CVE-2020-5741 and CVE-2021-2529
- Breach: Credit Card Data Breach: 2023-5-29
Report: https://zerofox.com/advisories/20727
ZeroFox Daily Intelligence Brief - May 30, 2023
Brief Highlights
- U.S. Department of Defense Sends Classified Cyber Strategy to Congress
- GobRAT Malware Attacking Japanese Routers
- New Hacking Forum “Exposed” Leaks RaidForums User Details
- Vulnerabilities: CVE-2021-3610, CVE-2023-30253, and CVE-2023-32687
- Exploits: CVE-2002-0061, CVE-2012-5931, and CVE-2017-5135
- Breach: Credit Card Data Breach: 2023-5-28
Report: https://zerofox.com/advisories/20707
ZeroFox Daily Intelligence Brief - May 29, 2023
Brief Highlights
- ZeroFox Intelligence - Q1 2023 Public Sector Quarterly Threat Landscape Report
- Russia-Linked COSMICENERGY Malware Threatens to Sabotage Power Grids
- New Phishing Kit Abuses ZIP domains
- Vulnerabilities: CVE-2022-36345, CVE-2023-33926, and CVE-2023-33332
- Exploits: CVE-2013-1763 and CVE-2018-9023
- Breaches: Credit Card Data Breach - 2023-5-27 and Credit Card Data Breach - 2023-5-26
Report: https://zerofox.com/advisories/20706
ZeroFox Daily Intelligence Brief - May 26, 2023
Brief Highlights
- CISA Alert: Social Engineering Attacks Could Target Potential Disaster Victims
- Scandinavian Airlines Operations Disrupted by Anonymous Sudan
- Operation Magalenha Targets Portuguese Banks via Phishing Attacks
- CVE-2023-2713
- CVE-2020-36694
- CVE-2023-2837
- CVE-2016-8584
- CVE-2009-4484
- CVE-2019-7195
- Credit Card Data Breach: 2023-5-25
Report: https://zerofox.com/advisories/20692
Breach Disclosures:
Breach Disclosure: HP China Customer Support
Summary
HP China Customer Support - the official HP China website for customer support – exposed 189,450 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20751
Breach Disclosure: MineSerwer.pl
Summary
MineSerwer.pl - a Poland-based minecraft discussion forum – exposed 14,311 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20750
Breach Disclosure: Apolyton
Summary
An alleged data breach at Apolyton – a U.S.-based forums for discussing the civilization and call to power games – exposed 123,014 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20735
Breach Disclosure: Club Factory
Summary
An alleged data breach at Club Factory – a China-based online apparel and accessories retail site – exposed 10,853 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20734
Breach Disclosure: 850K_UK Combolist
Summary
A combolist breach package titled “850K_UK" exposed 711,690 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20733
Breach Disclosure: BTC.com
Summary
An alleged data breach at BTC.com – a Netherlands-based online crypto wallet site – exposed 12,775 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20732
Breach Disclosure: Hitlerattacks
Summary
An alleged data breach at Hitlerattacks – an Iceland-based online hacking site – exposed 996 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/20731
Breaking News:
Cybercriminals Targeting Apache NiFi Instances for Cryptocurrency Mining
A financially motivated threat actor is actively scouring the internet for unprotected Apache NiFi instances to covertly install a cryptocurrency miner and facilitate lateral movement. The findings come from infosec researchers who detected a spike in HTTP requests for "/nifi" on May 19, 2023. The attack script is not saved to the system. The attack scripts are kept in memory only.
See the full report here: https://thehackernews.com/2023/05/cybercriminals-targeting-apache-nifi.html
Dark Pink APT Group Leverages TelePowerBot and KamiKakaBot in Sophisticated Attacks
The threat actor known as Dark Pink has been linked to five new attacks aimed at various entities in Belgium, Brunei, Indonesia, Thailand, and Vietnam between February 2022 and April 2023. This includes educational institutions, government agencies, military bodies, and non-profit organizations, indicating the adversarial crew's continued focus on high-value targets. Dark Pink, also called Saaiwc Group, is an advanced persistent threat (APT) actor believed to be of Asia-Pacific origin, with attacks targeting entities primarily located in East Asia and, to a lesser extent, in Europe. The group employs a set of custom malware tools such as TelePowerBot and KamiKakaBot that provide various functions to exfiltrate sensitive data from compromised hosts.
See the full report here: https://thehackernews.com/2023/05/dark-pink-apt-group-leverages.html
Beware of Ghost Sites Lurking in Salesforce Communities
Improperly deactivated and abandoned Salesforce Sites and Communities (aka Experience Cloud) could pose severe risks to organizations, leading to unauthorized access to sensitive data. Since the sites are not maintained, they are not tested against vulnerabilities, and Admins fail to update the site's security measures according to newer guidelines.
See the full report here: https://thehackernews.com/2023/05/beware-of-ghost-sites-silent-threat.html
Critical Firmware Vulnerability in Gigabyte Systems Exposes 7 Million Devices
Cybersecurity researchers have found "backdoor-like behavior" within Gigabyte systems, which they say enables the UEFI firmware of the devices to drop a Windows executable and retrieve updates in an unsecure format. Firmware security researchers said that it first detected the anomaly in April 2023. Gigabyte has since acknowledged and addressed the issue.
See the full report here: https://thehackernews.com/2023/05/critical-firmware-vulnerability-in.html
N. Korean ScarCruft Hackers Exploit LNK Files to Spread RokRAT
Cybersecurity researchers have offered a closer look at the RokRAT remote access trojan that's employed by the North Korean state-sponsored actor known as ScarCruft. RokRAT is a sophisticated remote access trojan (RAT) that has been observed as a critical component within the attack chain, enabling the threat actors to gain unauthorized access, exfiltrate sensitive information, and potentially maintain persistent control over compromised systems. ScarCruft, active since at least 2012, is a cyber espionage group that operates on behalf of the North Korean government, exclusively focusing on targets in its southern counterpart.
See the full report here: https://thehackernews.com/2023/06/n-korean-scarcruft-hackers-exploit.html
Toyota finds more misconfigured servers leaking customer info
Toyota Motor Corporation has discovered two additional misconfigured cloud services that leaked car owners' personal information for over seven years. This finding came after the Japanese carmaker conducted a thorough investigation on all cloud environments managed by Toyota Connected Corporation after previously discovering a misconfigured server that exposed the location data of over 2 million customers for ten years.
See the full report here: https://www.bleepingcomputer.com/news/security/toyota-finds-more-misconfigured-servers-leaking-customer-info/
Stealthy SeroXen RAT malware increasingly used to target gamers
A stealthy remote access trojan (RAT) named "SeroXen" has recently gained popularity as cybercriminals begin using it for its low detection rates and powerful capabilities. AT&T reports that the malware is sold under the guise of a legitimate remote access tool for Windows 11 and 10 for USD 15/month or a single "lifetime" license payment of USD60.
See the full report here: https://www.bleepingcomputer.com/news/security/stealthy-seroxen-rat-malware-increasingly-used-to-target-gamers/
Terminator antivirus killer is a vulnerable Windows driver in disguise
A threat actor known as Spyboy is promoting a tool called "Terminator" on a Russian-speaking hacking forum that can allegedly terminate any antivirus, XDR, and EDR platform. Terminator is allegedly capable of bypassing 24 different antivirus (AV), Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR) security solutions, including Windows Defender, on devices running Windows 7 and later, Spyboy sells the software for prices ranging from USD 300 for a single bypass to USD 3,000 for an all-in-one bypass.
See the full report here: https://www.bleepingcomputer.com/news/security/terminator-antivirus-killer-is-a-vulnerable-windows-driver-in-disguise/
Amazon faces USD 30 million fine over Ring, Alexa privacy violations
Amazon will pay USD 30 million in fines to settle allegations of privacy violations related to the operation of its Ring video doorbell and Alexa virtual assistant services. The company's Ring home security camera subsidiary has been accused by the Federal Trade Commission (FTC) of engaging in unlawful surveillance of customers and failing to prevent hackers from gaining control of users' cameras. According to a proposed order, Ring will have to pay USD 5.8 million in refunds to consumers and will be barred from profiting from unlawfully obtained consumer videos.
See the full report here: https://www.bleepingcomputer.com/news/technology/amazon-faces-30-million-fine-over-ring-alexa-privacy-violations/
Exploit released for RCE flaw in popular ReportLab PDF library
A researcher has published a working exploit for a remote code execution (RCE) flaw impacting ReportLab Toolkit, a popular Python library used by numerous projects to generate PDF files from HTML input. The proof-of-concept (PoC) exploit for the flaw, tracked as CVE-2023-33733, was published on GitHub along with a write-up that provides technical details about the vulnerability, thus increasing the likelihood of in-the-wild exploitation. ReportLab Toolkit is used by multiple projects as a PDF library and has approximately 3.5 million monthly downloads on PyPI (Python Package Index).
See the full report here: https://www.bleepingcomputer.com/news/security/exploit-released-for-rce-flaw-in-popular-reportlab-pdf-library/
Android apps with spyware installed 421 million times from Google Play
A new Android malware distributed as an advertisement SDK has been discovered in multiple apps, many previously on Google Play and collectively downloaded over 400 million times. Security researchers discovered the spyware module and tracked it as "SpinOk," warning that it can steal private data stored on users' devices and send it to a remote server. The researchers say that SpinkOk demonstrates a seemingly legitimate behavior, using minigames that lead to rewards to spark user interest.
See the full report here: https://www.bleepingcomputer.com/news/security/android-apps-with-spyware-installed-421-million-times-from-google-play/
Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian Android Users
A new open source remote access trojan (RAT) called DogeRAT targets Android users primarily located in India as part of a sophisticated malware campaign. The malware is distributed via social media and messaging platforms under the guise of legitimate applications like Opera Mini, OpenAI ChatGPT, and Premium versions of YouTube, Netflix, and Instagram. Once installed on a victim's device, the malware gains unauthorized access to sensitive data, including contacts, messages, and banking credentials.
See the full report here: https://thehackernews.com/2023/05/sneaky-dogerat-trojan-poses-as-popular.html
CAPTCHA-Breaking Services with Human Solvers Helping Cybercriminals Defeat Security
Cybersecurity researchers are warning about CAPTCHA-breaking services that are being offered for sale to bypass systems designed to distinguish legitimate users from bot traffic. These CAPTCHA-solving services don't use [optical character recognition] techniques or advanced machine learning methods; instead, they break CAPTCHAs by farming out CAPTCHA-breaking tasks to actual human solvers.
See the full report here: https://thehackernews.com/2023/05/captcha-breaking-services-with-human.html
Hackers Win USD 105,000 for Reporting Critical Security Flaws in Sonos One Speakers
Multiple security flaws uncovered in Sonos One wireless speakers could be potentially exploited to achieve information disclosure and remote code execution. The vulnerabilities were demonstrated by three different teams at the Pwn2Own hacking contest held in Toronto late last year, netting them USD 105,000 in monetary rewards.
See the full report here: https://thehackernews.com/2023/05/hackers-win-105000-for-reporting.html
RomCom malware spread via Google Ads for ChatGPT, GIMP, more
A new campaign distributing the RomCom backdoor malware is impersonating the websites of well-known or fictional software, tricking users into downloading and launching malicious installers. The researchers report that the threat actors behind the malware have escalated its evasion by using payload encryption and obfuscation and expanded the tool's capabilities by introducing new and powerful commands.
See the full report here: https://www.bleepingcomputer.com/news/security/romcom-malware-spread-via-google-ads-for-chatgpt-gimp-more/
Microsoft finds macOS bug that lets hackers bypass SIP root restrictions
Apple has recently addressed a vulnerability that lets attackers with root privileges bypass System Integrity Protection (SIP) to install "undeletable" malware and access the victim's private data by circumventing Transparency, Consent, and Control (TCC) security checks. Discovered and reported to Apple by a team of Microsoft security researchers, the flaw (dubbed Migraine) is now tracked as CVE-2023-32369. Apple patched the vulnerability in security updates for macOS Ventura 13.4, macOS Monterey 12.6.6, and macOS Big Sur 11.7.7, on May 18 2023.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-finds-macos-bug-that-lets-hackers-bypass-sip-root-restrictions/
WordPress plugin "Gravity Forms" vulnerable to PHP object injection
The premium WordPress plugin "Gravity Forms," currently used by over 930,000 websites, is vulnerable to unauthenticated PHP Object Injection. Gravity Forms is a custom form builder website owners use for creating payment, registration, file upload, or any other form required for visitor-site interactions or transactions. On its website, Gravity Forms claims it is used by a wide variety of large companies, including Airbnb, ESPN, Nike, NASA, PennState, and Unicef. The vulnerability, which is tracked as CVE-2023-28782, impacts all plugin versions from 2.73 and below.
See the full report here: https://www.bleepingcomputer.com/news/security/wordpress-plugin-gravity-forms-vulnerable-to-php-object-injection/
WordPress force installs critical Jetpack patch on 5 million sites
Automattic, the company behind the open-source WordPress content management system, has started force installing a security patch on millions of websites to address a critical vulnerability in the Jetpack WordPress plug-in. Jetpack is an immensely popular plug-in that provides free security, performance, and website management improvements, including site backups, brute-force attack protection, secure logins, malware scanning, and more. According to the official WordPress plug-in repository, the plug-in is maintained by Automattic, and it now has over 5 million active installations.
See the full report here: https://www.bleepingcomputer.com/news/security/wordpress-force-installs-critical-jetpack-patch-on-5-million-sites/
Senegalese government websites hit with cyber attack
A group of hackers called Mysterious Team made multiple Senegalese government websites go offline overnight by hitting them with denial-of-service (DDoS) attacks, a government spokesperson said. The group claimed responsibility for the cyber attacks in a series of Twitter posts using the hashtag #FreeSenegal used by campaigners alleging political repression in Senegal.
See the full report here: https://www.reuters.com/world/africa/senegalese-government-websites-hit-with-cyberattack-2023-05-27/
Hackers breach website of Russian Skolkovo Foundation
The foundation, a non-government organization, confirmed the breach in a statement on its Telegram channel. The foundation was the brainchild of former Russian President, who founded it during his presidency in 2010 to develop advanced technologies. It is named after the Moscow suburb of Skolkovo. Skolkovo Foundation officials reported that hackers gained access to certain information systems and resources, including a file-sharing platform hosted on the physical infrastructure of the foundation.
See the full report here: https://news.yahoo.com/hackers-breach-website-russian-skolkovo-132800120.html
Hackers post photos of Iranian opposition leaders on government websites
A series of websites linked to Iran’s presidency bore the images of two leaders of an exiled opposition group, with others showing the pictures of Islamic Republic’s supreme leader and president crossed out. An internet account describing itself as a group of hackers claimed responsibility for allegedly taking down websites. The account GhyamSarnegouni, whose name in Farsi means “Rise to Overthrow,” previously claimed responsibiity for hacking websites associated with Iran’s Foreign Ministry.
See the full report here: https://www.timesofisrael.com/hackers-post-photos-of-iranian-opposition-leaders-on-government-websites/
New GobRAT Remote Access Trojan Targeting Linux Routers in Japan
Linux routers in Japan are the target of a new Golang remote access trojan (RAT) called GobRAT. Initially, the attacker targets a router whose WEBUI is open to the public, executes scripts possibly by using vulnerabilities, and finally infects the GobRAT. The compromise of an internet-exposed router is followed by the deployment of a loader script that acts as a conduit for delivering GobRAT, which, when launched, masquerades as the Apache daemon process (apached) to evade detection.The loader is also equipped to disable firewalls, establish persistence using the cron job scheduler, and register an SSH public key in the .ssh/authorized_keys file for remote access.
See the full report here: https://thehackernews.com/2023/05/new-gobrat-remote-access-trojan.html
AceCryptor: Cybercriminals' Powerful Weapon, Detected in 240K+ Attacks
A crypter (alternatively spelled cryptor) malware dubbed AceCryptor has been used to pack numerous strains of malware since 2016. Researchers identified over 240,000 detections of the crypter in its telemetry in 2021 and 2022. This amounts to more than 10,000 hits per month. Some of the prominent malware families contained within AceCryptor are SmokeLoader, RedLine Stealer, RanumBot, Raccoon Stealer, Stop ransomware, and Amadey, among others. The countries with the most detections include Peru, Egypt, Thailand, Indonesia, Turkey, Brazil, Mexico, South Africa, Poland, and India.
See the full report here: https://thehackernews.com/2023/05/acecryptor-cybercriminals-powerful.html
New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force
Researchers have discovered an inexpensive attack technique that could be leveraged to brute-force fingerprints on smartphones to bypass user authentication and seize control of the devices. The approach, dubbed BrutePrint, bypasses limits put in place to counter failed biometric authentication attempts by weaponizing two zero-day vulnerabilities in the smartphone fingerprint authentication (SFA) framework. The flaws, Cancel-After-Match-Fail (CAMF) and Match-After-Lock (MAL), leverage logical defects in the authentication framework, which arises due to insufficient protection of fingerprint data on the Serial Peripheral Interface (SPI) of fingerprint sensors.
See the full report here: https://thehackernews.com/2023/05/new-bruteprint-attack-lets-attackers.html
Lazarus hackers target Windows IIS web servers for initial access
The notorious North Korean state-backed hackers, known as the Lazarus Group, are now targeting vulnerable Windows Internet Information Services (IIS) web servers to gain initial access to corporate networks. Lazarus is primarily financially motivated, with many analysts believing that the hackers' malicious activities help fund North Korea's weapons development programs. However, the group has also been involved in several espionage operations. The latest tactic of targeting Windows IIS servers was discovered by South Korean researchers.
See the full report here: https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-windows-iis-web-servers-for-initial-access/
MCNA Dental data breach impacts 8.9 million people after ransomware attack
Managed Care of North America (MCNA) Dental has published a data breach notification on its website, informing almost 9 million patients that their personal data were compromised. MCNA Dental is one of the largest government-sponsored (Medicaid and CHIP) dental care and oral health insurance providers in the U.S. MCNA says it became aware of unauthorized access to its computer systems on March 6th, 2023, with an investigation revealing that the hackers first gained access to MCNA’s network on February 26th, 2023. During that time, the hackers stole data that contained the following information for almost nine million patients.
See the full report here: https://www.bleepingcomputer.com/news/security/mcna-dental-data-breach-impacts-89-million-people-after-ransomware-attack/
Flash loan attack on Jimbos Protocol steals over USD 7.5 million
Jimbos Protocol, an Arbitrum-based DeFi project, has suffered a flash loan attack that resulted in the loss of more than of 4000 ETH tokens, currently valued at over USD 7,500,000. The company disclosed the attack on Twitter that law enforcement has been notified and it is working with security professionals to remediate the situation. The attack occurred only three days after the platform launched its V2 protocol, at a moment when many people had just invested in its "jimbo" token, and the perpetrator managed to steal 4,090 in ETH tokens.
See the full report here: https://www.bleepingcomputer.com/news/security/flash-loan-attack-on-jimbos-protocol-steals-over-75-million/
New hacking forum leaks data of 478,000 RaidForums members
A database for the notorious RaidForums hacking forums has been leaked online, allowing threat actors and security researchers insight into the people who frequented the forum. Threat actors who frequented the forum would hack into websites or access exposed database servers to steal customer information. The threat actors then attempted to sell the data to other threat actors, who use it for their campaigns, such as phishing attacks, cryptocurrency scams, or distributing malware. In many cases, if data was not sold or some time had passed, the stolen data would be leaked for free on RaidForums to gain a reputation among the community.
See the full report here: https://www.bleepingcomputer.com/news/security/new-hacking-forum-leaks-data-of-478-000-raidforums-members/
Severe Flaw in Google Cloud's Cloud SQL Service Exposed Confidential Data
A new security flaw has been disclosed in the Google Cloud Platform's (GCP) Cloud SQL service that could be potentially exploited to obtain access to confidential data. The vulnerability could have enabled a malicious actor to escalate from a basic Cloud SQL user to a full-fledged sysadmin on a container, gaining access to internal GCP data like secrets, sensitive files, passwords, in addition to customer data.
See the full report here: https://thehackernews.com/2023/05/severe-flaw-in-google-clouds-cloud-sql.html
Critical OAuth Vulnerability in Expo Framework Allows Account Hijacking
A critical security vulnerability has been disclosed in the Open Authorization (OAuth) implementation of the application development framework Expo.io. The shortcoming, assigned the CVE identifier CVE-2023-28131, has a severity rating of 9.6 on the CVSS scoring system. The issue rendered services using the framework susceptible to credential leakage, which could then be used to hijack accounts and siphon sensitive data. Under certain circumstances, a threat actor could have taken advantage of the flaw to perform arbitrary actions on behalf of a compromised user on various platforms such as Facebook, Google, or Twitter.
See the full report here: https://thehackernews.com/2023/05/critical-oauth-vulnerability-in-expo.html
New Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets
A new stealthy information stealer malware called Bandit Stealer has caught the attention of cybersecurity researchers for its ability to target numerous web browsers and cryptocurrency wallets. It has the potential to expand to other platforms as Bandit Stealer was developed using the Go programming language, possibly allowing cross-platform compatibility. The malware is currently focused on targeting Windows by using a legitimate command-line tool called runas.exe that allows users to run programs as another user with different permissions.
See the full report here: https://thehackernews.com/2023/05/new-stealthy-bandit-stealer-targeting.html
Microsoft 365 phishing attacks use encrypted RPMSG messages
Attackers are now using encrypted RPMSG attachments sent via compromised Microsoft 365 accounts to steal Microsoft credentials in targeted phishing attacks designed to evade detection by email security gateways. RPMSG files (also known as restricted permission message files) are encrypted email message attachments created using Microsoft's Rights Management Services (RMS) and offer an extra layer of protection to sensitive info by restricting access to authorized recipients. Recipients who want to read them must authenticate using their Microsoft account or obtain a one-time passcode to decrypt the contents.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-365-phishing-attacks-use-encrypted-rpmsg-messages/
BlackByte ransomware claims City of Augusta cyberattack
The city of Augusta in Georgia, U.S., has confirmed that the most recent IT system outage was caused by unauthorized access to its network. The administration has not disclosed the nature of the cyberattack but the BlackByte ransomware gang has published the City of Augusta as one of its victims. The city explained on its online portal that it started "experiencing technical difficulties" on May 21 2023 which disrupted some of its computer systems.
See the full report here: https://www.bleepingcomputer.com/news/security/blackbyte-ransomware-claims-city-of-augusta-cyberattack/
Emby shuts down user media servers hacked in recent attack
Emby says it remotely shut down an undisclosed number of user-hosted media server instances that were recently hacked by exploiting a previously known vulnerability and an insecure admin account configuration. The company informed users of affected servers in new entries added to the log files. The attacks began in mid-May 2023 when the attackers started targeting Internet-exposed private Emby servers and infiltrating those configured to allow admin logins without a password on the local network.
See the full report here: https://www.bleepingcomputer.com/news/security/emby-shuts-down-user-media-servers-hacked-in-recent-attack/
US govt contractor ABB confirms ransomware attack, data theft
Swiss tech multinational and U.S. government contractor ABB has confirmed that some of its systems were impacted by a ransomware attack, previously described by the company as "an IT security incident." It also revealed that the attackers had stolen data from compromised devices and that it would notify affected individuals if their information was impacted in the incident. ABB has determined that an unauthorized third-party accessed certain ABB systems, deployed a type of ransomware that is not self-propagating, and exfiltrated certain data.
See the full report here: https://www.bleepingcomputer.com/news/security/us-govt-contractor-abb-confirms-ransomware-attack-data-theft/
Hot Pixels attack checks CPU temp, power changes to steal data
A team of researchers have developed a novel attack called "Hot Pixels," which can retrieve pixels from the content displayed in the target's browser and infer the navigation history. The attack exploits data-dependent computation times on modern system-on-a-chip (SoCs) and graphics processing units (GPUs) and applies them to stealthily extract information from visited web pages on Chrome and Safari, even if with the latest side-channel countermeasures enabled. The researchers found that modern processors struggle to balance power consumption requirements and heat dissipation limitations with high execution speeds. This leads to distinct behavior patterns that point to specific instructions and operations.
See the full report here: https://www.bleepingcomputer.com/news/security/hot-pixels-attack-checks-cpu-temp-power-changes-to-steal-data/
CISA warns govt agencies of recently patched Barracuda zero-day
CISA warned of a recently patched zero-day vulnerability exploited to hack into Barracuda Email Security Gateway (ESG) appliances. Barracuda says its security solutions are used by more than 200,000 organizations worldwide, including high-profile companies like Samsung, Mitsubishi, Kraft Heinz, and Delta Airlines. The U.S. cybersecurity agency also added the bug (CVE-2023-2868) to its catalog of security flaws exploited in the wild based on this evidence of active exploitation. Federal Civilian Executive Branch Agencies (FCEB) agencies must patch or mitigate the vulnerability as ordered by the BOD 22-01 binding operational directive.
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-warns-govt-agencies-of-recently-patched-barracuda-zero-day/
File Archiver In The Browser phishing trick uses ZIP domains
A new "File Archivers in the Browser" phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files. Ever since the TLD's release, there has been quite a bit of debate over whether they are a mistake and could pose a cybersecurity risk to users.
See the full report here: https://www.bleepingcomputer.com/news/security/clever-file-archiver-in-the-browser-phishing-trick-uses-zip-domains/
New Russian-linked CosmicEnergy malware targets industrial systems
Security researchers have discovered a new malware called CosmicEnergy designed to disrupt industrial systems and linked to Russian cybersecurity outfit Rostelecom-Solar (formerly Solar Security). The malware specifically targets IEC-104-compliant remote terminal units (RTUs) commonly used in electric transmission and distribution operations across Europe, the Middle East, and Asia. CosmicEnergy was discovered after a sample was uploaded to the VirusTotal malware analysis platform in December 2021 by someone with a Russian IP address.
See the full report here: https://www.bleepingcomputer.com/news/security/new-russian-linked-cosmicenergy-malware-targets-industrial-systems/
United Nations official and others in Armenia hacked by NSO Group spyware
Researchers have documented the first known case of NSO Group’s spyware being used in a military conflict after they discovered that journalists, human rights advocates, a United Nations official, and members of civil society in Armenia were hacked by a government using the spyware. The hacking campaign, which targeted at least a dozen victims from October 2020 to December 2022, appears closely linked to events in the long-running military conflict between Armenia and Azerbaijan over the contested Nagorno-Karabakh region.
See the full report here: https://www.theguardian.com/technology/2023/may/25/nso-group-spyware-armenia-war
SAS Hit By Cyber Attack As Hackers Demand USD 175,000
Scandinavian Airlines (SAS) was hit with a cyberattack that rendered its app and website inoperable for nearly a full day. A group known as Anonymous Sudan reportedly first demanded USD 3,500 from the carrier before upping its demands to USD 175,000.
See the full report here: https://simpleflying.com/sas-cyber-attack/
Dark Frost Botnet Launches Devastating DDoS Attacks on Gaming Industry
A new botnet called Dark Frost has been observed launching distributed denial-of-service (DDoS) attacks against the gaming industry. The Dark Frost botnet, modeled after Gafgyt, QBot, Mirai, and other malware strains, has expanded to encompass hundreds of compromised devices. Targets include gaming companies, game server hosting providers, online streamers, and even other gaming community members with whom the threat actor has interacted directly.
See the full report here: https://thehackernews.com/2023/05/dark-frost-botnet-launches-devastating.html
New Buhti ransomware gang uses leaked Windows, Linux encryptors
A new ransomware operation named "Buhti" uses the leaked code of the LockBit and Babuk ransomware families to target Windows and Linux systems, respectively. While the threat actors behind Buhti, now tracked as "Blacktail," have not developed their own ransomware strain, they have created a custom data exfiltration utility that they use to blackmail victims, a tactic known as "double-extortion." Buhti was first spotted in the wild in February 2023 by researchers, who identified it as a Go-based Linux-targeting ransomware.
See the full report here: https://www.bleepingcomputer.com/news/security/new-buhti-ransomware-gang-uses-leaked-windows-linux-encryptors/
Operation Magalenha targets credentials of 30 Portuguese banks
A Brazilian hacking group has been targeting thirty Portuguese government and private financial institutions since 2021 in a malicious campaign called "Operation Magalenha." Examples of the targeted entities include ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco. Researchers have uncovered details about the threat actor's origin and tactics because of a server misconfiguration that exposed files, directories, internal correspondence, and more.
See the full report here: https://www.bleepingcomputer.com/news/security/operation-magalenha-targets-credentials-of-30-portuguese-banks/
Zyxel warns of critical vulnerabilities in firewall and VPN devices
Zyxel is warning customers of two critical-severity vulnerabilities in several of its firewall and VPN products that attackers could leverage without authentication. Both security issues are buffer overflows and could allow denial-of-service (DoS) and remote code execution on vulnerable devices. Zyxel has released patches for firewalls affected by multiple buffer overflow vulnerabilities, the vendor stated in a security advisory. Users are advised to install them for optimal protection.
See the full report here: https://www.bleepingcomputer.com/news/security/zyxel-warns-of-critical-vulnerabilities-in-firewall-and-vpn-devices/
New Russian-linked CosmicEnergy malware targets industrial systems
Security researchers have discovered a new malware called CosmicEnergy designed to disrupt industrial systems. The malware specifically targets IEC-104-compliant remote terminal units (RTUs) commonly used in electric transmission and distribution operations across Europe, the Middle East, and Asia. The malware shares similarities with malware like Industroyer and Industroyer V2, both used in attacks targeting Ukrainian energy providers in December 2016 and April 2022.
See the full report here: https://www.bleepingcomputer.com/news/security/new-russian-linked-cosmicenergy-malware-targets-industrial-systems/
D-Link fixes auth bypass and RCE flaws in D-View 8 software
D-Link has fixed two critical-severity vulnerabilities in its D-View 8 network management suite that could allow remote attackers to bypass authentication and execute arbitrary code. D-View is a network management suite developed by D-Link, used by businesses for monitoring performance, controlling device configurations, creating network maps, and generally making network management and administration more efficient.
See the full report here: https://www.bleepingcomputer.com/news/security/d-link-fixes-auth-bypass-and-rce-flaws-in-d-view-8-software/
Microsoft 365 phishing attacks use encrypted RPMSG messages
Attackers are now using encrypted RPMSG attachments sent via compromised Microsoft 365 accounts to steal Microsoft credentials in targeted phishing attacks designed to evade detection by email security gateways. RPMSG files (also known as restricted permission message files) are encrypted email message attachments created using Microsoft's Rights Management Services (RMS) and offer an extra layer of protection to sensitive info by restricting access to authorized recipients. Recipients who want to read them must authenticate using their Microsoft account or obtain a one-time passcode to decrypt the contents.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-365-phishing-attacks-use-encrypted-rpmsg-messages/
Predator: Looking under the hood of Intellexa’s Android spyware
Security researchers have presented a new technical analysis of the commercial Android spyware "Predator" and its loader "Alien," sharing its data-theft capabilities and other operational details. Predator is a commercial spyware for mobile platforms (iOS and Android) developed and sold by Israeli company Intellex. The spyware family has been linked to surveillance operations targeting journalists, high-profile European politicians, and Meta executives.
See the full report here: https://www.bleepingcomputer.com/news/security/predator-looking-under-the-hood-of-intellexas-android-spyware/
ZeroFox Intelligence Reports:
ZeroFox Intelligence June 2023 Geopolitical Brief
In this ZeroFox Intelligence Geopolitical Brief for June 2023, the primary talking point is western containment efforts related to China and Chinese policy vis-à-vis western business interests. The issue has global relevance, with both sides courting new and improved relationships, particularly in Africa, Latin America, and the Asia-Pacific region. The start of Ukraine's counteroffensive is the key topic in Europe, along with noteworthy upcoming elections. In Latin America, the political impact of skyrocketing crime rates and elections is discussed. Potential social unrest and an upcoming BRICS summit are key issues in Africa, while Israeli political and protest developments are highlighted in the Middle East. Asia is also a mix of predicted episodes of social unrest and uncertain electoral outcomes.
Report: https://zerofox.com/advisories/20753
ZeroFox Intelligence Event Assessment - Champions League Final
In this ZeroFox Intelligence Event Assessment, ZeroFox researchers examine physical and cybersecurity risks to the final of The Champions League football tournament, which culminates in Istanbul on June 10, 2023.
Report: https://zerofox.com/advisories/20752
ZeroFox Intelligence Cyber Threat Advisory - Ransomware Update
In this cyber threat advisory, ZeroFox researchers provide an update around recent ransomware developments, specifically the significant uptick of ransomware and digital extortion activity during Q1 2023.
Report: https://zerofox.com/advisories/20730
ZeroFox Intelligence Flash Report - “Spyboy”: EDR Bypass Claims Spark Mixed Reactions
In this flash report, ZeroFox Intelligence provides an assessment of "spyboy"'s claims to be selling an Antivirus (AV) and Endpoint Detection and Response (EDR) killer that can bypass and disable a wide range of the most prominent AV and EDR solutions on the market. Reactions from reputable underground actors regarding spyboy's claims have been mixed, with some actors defending the assertions made while others raise doubts about their validity.
Report: https://zerofox.com/advisories/20729
Tags: tlp:clear, all industries, global