zerofox logo
Advisories

Threat Intelligence Bulletin: 06/02/2023 - 06/08/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 06/02/2023 - 06/08/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - June 8, 2023

Brief Highlights

  • Researchers Link Lazarus to Atomic Wallet Attack
  • Honda API Exposed Customer Data and Internal Documents
  • Barracuda: Replace Hacked ESG Appliances
  • Vulnerabilities: CVE-2023-33326, CVE-2023-3068, and CVE-2023-33556
  • Exploits: CVE-2010-2227, CVE-2008-4696, and CVE-2009-3103
  • Breaches: BreachForums/XSS: EpicNPC Marketplace Data Breach and Credit Card Data Breach: 2023-6-6

Report: https://zerofox.com/advisories/20825


ZeroFox Daily Intelligence Brief - June 7, 2023

Brief Highlights

  • Malicious Actors Manipulating Photos and Videos to Create Explicit Content for Sextortion Schemes
  • NASA Website Flaw Jeopardized Astrobiology Fans
  • New “Powerdrop” Powershell Malware Targets U.S. Aerospace Industry
  • Vulnerabilities: CVE-2023-28321, CVE-2023-28322, and CVE-2023-33536
  • Exploits: CVE-2002-0289, CVE-2015-0336, and CVE-2020-11738
  • Breaches: BreachForums/XSS: Btc60.net Data Breach, Credit Card Data Breach: 2023-6-5, and Telegram: “TG hulk_logs 700LOGS .zip" Botnet Breach

Report: https://zerofox.com/advisories/20808


ZeroFox Daily Intelligence Brief - June 6, 2023

Brief Highlights

  • British Companies’ Staff Details Targeted in Russia-Linked Cyber Attack
  • KeePassUpdate Addresses Critical Master Password Vulnerability
  • Gigabyte Releases BIOS Updates to Bolster Security and Patch Backdoor Vulnerability
  • Vulnerabilities: CVE-2018-25087, CVE-2023-2546, and CVE-2023-32699
  • Exploit: CVE-2010-2743
  • Breaches: BreachForums/XSS: Kraken Data Breach, Telegram: Night Sorted.zip Botnet Breach, and BreachForums/Leakbase: Moon Valley Nurseries Data Breach

Report: https://zerofox.com/advisories/20797


ZeroFox Daily Intelligence Brief - June 5, 2023

Brief Highlights

  • Magecart Campaign Infects Legitimate Sites to Host Credit Card Stealer Scripts
  • Hackers Spoof Popular Brands in “Picture in Picture” Attack
  • Burton Snowboards Confirms Data Breach
  • Vulnerabilities: CVE-2023-34411, CVE-2023-34410, and CVE-2023-34408
  • Exploits: CVE-2005-0581 and CVE-2015-3306
  • Breach: Credit Card Data Breach: 2023-6-3

Report: https://zerofox.com/advisories/20783


ZeroFox Daily Intelligence Brief - June 2, 2023

Brief Highlights

  • iOS Exploits Infect iPhones with Never-Before-Seen Malware
  • CISA Alert: Security Advisory for MOVEit Transfer
  • ZeroFox Event Assessment: UEFA Champions League Final
  • Vulnerabilities: CVE-2023-30394, CVE-2023-29746, and CVE-2022-45938
  • Exploits: CVE-2012-0003, CVE-2006-2369, and CVE-2020-10884
  • Breaches: Telegram: XIII_LOGS Botnet Breach and Credit Card Data Breach: 2023-5-31

Report: https://zerofox.com/advisories/20765


Breach Disclosures:


Breach Disclosure: 1.6KK_VIP_GOLD Combolist

A combolist breach package titled “1.6KK_VIP_GOLD Combolist" exposed 904,791 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20824


Breach Disclosure: Bit2Visitor

An alleged data breach at Bit2Visitor – a U.S.-based site that informs visitors about topics such as bitcoin BTC, bit coin mining and bitcoin market – exposed 21,587 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20823


Breach Disclosure: Kraken

An alleged data breach at Kraken – a U.S.-based online cryptocurrency exchange site – exposed 19,011 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20822


Breach Disclosure: Cre8ASite

An alleged data breach at Cre8ASite– a U.S.-based web design forum – exposed 24,255 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20821


Breach Disclosure: Cracked.to

An alleged data breach at Cracked.to – a Tonga-based hacking forum – exposed 24,557 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20820


Breach Disclosure: BitsCircle

An alleged data breach at BitsCircle – a Philippines web consultancy agency – exposed 19,011 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20819


Breach Disclosure: Moon Valley Nurseries

An alleged data breach at Moon Valley Nurseries – a Pakistan-based online movies discussion forum – exposed 30,995 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20818


Breach Disclosure: Craft Apple Creations

An alleged data breach at Craft Apple Creations – a U.S.-based art and craft blog site – exposed 3,530 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20817


Breach Disclosure: Developers Heaven

An alleged data breach at Developers Heaven - an Egypt-based programmers discussion forum – exposed 4,171 email addresses, which were subsequently shared on several deep web platforms.

Report: https://zerofox.com/advisories/20816


Breach Disclosure: Amaderforum

An alleged data breach at Amaderforum – a Pakistan-based online movies discussion forum – exposed 21,143 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20815


Breach Disclosure: VaroXCrafT

An alleged data breach at VaroXCrafT – a German-based Minecraft server host and discussion forum – exposed 1,893 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20806


Breach Disclosure: Mobile Legends

An alleged data breach at Mobile Legends – a China-based gaming forum – exposed 204,02 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20805


Breach Disclosure: Moneycontrol

An alleged data breach at Moneycontrol – an India-based online financial and business portal – exposed 29,881 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20804


Breach Disclosure: BShoppy

An alleged data breach at BShoppy – an India-based ecommerce store – exposed 19,692 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20794


Breach Disclosure: Lixter

An alleged data breach at Lixter – a U.K.-based crypto trading platform – exposed 2,979 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20793


Breach Disclosure: SafeSkyHacks

An alleged data breach at SafeSkyHacks – U.S.-based hacking discussion forum – exposed 2,231 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20777


Breach Disclosure: Shopping Bitcoins

An alleged data breach at Shopping Bitcoins – a U.S.-based licensed cryptocurrency and mining platform – exposed 2,981 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20776


Breach Disclosure: Philips

An alleged data breach at Philips – a Russia-based online electronic product retail store – exposed 301,326 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20774


Breach Disclosure: Spohesap

An alleged data breach at Spohesap – a U.S.-based online store – exposed 6,207 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20773


Breach Disclosure: Fremont Unified School District

An alleged data breach at Fremont Unified School District – a public school district – exposed 88,606 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20764


Breach Disclosure: Blackhatdevil

An alleged data breach at Blackhatdevil – a U.S.-based forum dedicated dispersing internet marketing techniques – exposed 13,247 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20763


Breach Disclosure: Coins Numizmat

An alleged data breach at Coins Numizmat– a Chile-based minecraft server hosting and discussion forum – exposed 2,917 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20762


Breach Disclosure: Omega Craft

An alleged data breach at Omega Craft – a Chile-based minecraft server hosting and discussion forum – exposed 1,774 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20761


Breach Disclosure: VanityMC

An alleged data breach at VanityMC – a U.S.-based java edition for minecraft server – exposed 11,945 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20760


Breach Disclosure: Zloadr

An alleged data breach at Zloadr – a U.K.-based company that operates in blockchain finance – exposed 8,717 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20759


Breach Disclosure: Roll20

An alleged data breach at Roll20 – a U.S.-based online virtual tabletop site – exposed 12,998 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20758


Breach Disclosure: University of Maryland, Baltimore County

University of Maryland, Baltimore County - a U.S.-based online bulletin board – exposed 27,170 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20757


Breach Disclosure: Cannabis Card Pay

Cannabis Card Pay - a U.S.-based company that operates in merchant payment consultation – exposed 10,833 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20756


Breach Disclosure: Demon Forums

Demon Forums - a U.S.-based online bulletin board – exposed 6,722 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20755


Breach Disclosure: Saint Paul Public Schools

Saint Paul Public Schools - a public school district – exposed 104,477 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20754


Breaking News:


CEO guilty of selling counterfeit Cisco devices to military, govt orgs

A Florida man has pleaded guilty to importing and selling counterfeit Cisco networking equipment to various organizations, including education, government agencies, healthcare, and the military. The 39-year-old resident of Florida conducted the scheme through 19 companies formed in New Jersey and Florida and in several online storefronts, collectively known as "Pro Network Entities".

See the full report here: https://www.bleepingcomputer.com/news/security/ceo-guilty-of-selling-counterfeit-cisco-devices-to-military-govt-orgs/


VMware fixes critical vulnerabilities in vRealize network analytics tool

VMware issued multiple security patches to address critical and high-severity vulnerabilities in VMware Aria Operations for Networks, allowing attackers to gain remote execution or access sensitive information. Previously known as vRealize Network Insight (vRNI), this network visibility and analytics tool helps admins optimize network performance or manage and scale various VMware and Kubernetes deployments. The most severe of the three security bugs fixed today is a command injection vulnerability tracked as CVE-2023-20887, which unauthenticated threat actors can exploit in low-complexity attacks that don't require user interaction.

See the full report here: https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-vulnerabilities-in-vrealize-network-analytics-tool/


New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux

Hackers used the popular Minecraft modding platforms Bukkit and CurseForge to distribute a new "Fractureiser" information-stealing malware through uploaded modifications and by injecting malicious code into existing projects. According to multiple reports, the attack began when several CurseForge and Bukkit accounts were compromised and used to inject malicious code into plugins and mods, which were then adopted by popular modpacks such as "Better Minecraft," which has over 4.6 million downloads.

See the full report here: https://www.bleepingcomputer.com/news/security/new-fractureiser-malware-used-curseforge-minecraft-mods-to-infect-windows-linux/


Lazarus hackers linked to the USD 35 million Atomic Wallet heist

The notorious North Korean hacking group known as Lazarus has been linked to the recent Atomic Wallet hack, resulting in the theft of over USD 35 million in crypto. The attack on Atomic Wallet occurred when numerous users reported that their wallets were compromised and their funds had been stolen.

See the full report here: https://www.bleepingcomputer.com/news/security/lazarus-hackers-linked-to-the-35-million-atomic-wallet-heist/


Cisco fixes AnyConnect bug giving Windows SYSTEM privileges

Cisco has fixed a high-severity vulnerability found in Cisco Secure Client (formerly AnyConnect Secure Mobility Client) software that can let attackers escalate privileges to the SYSTEM account used by the operating system. Cisco Secure Client enables employees to work from anywhere via a secure Virtual Private Network (VPN) and provides admins with endpoint management and telemetry features. Low-privileged, local attackers can exploit this security flaw (tracked as CVE-2023-20178) in low-complexity attacks that don't require user interaction.

See the full report here: https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/


Honda API flaws exposed customer data, dealer panels, internal docs

Honda's e-commerce platform for power equipment, marine, lawn & garden, was vulnerable to unauthorized access by anyone due to API flaws that allow password reset for any account. Honda is a Japanese manufacturer of automobiles, motorcycles, and power equipment. In this case, only the latter division is impacted, so owners of Honda cars or motorcycles aren't affected.

See the full report here: https://www.bleepingcomputer.com/news/security/honda-api-flaws-exposed-customer-data-dealer-panels-internal-docs/


Barracuda says hacked ESG appliances must be replaced immediately

Email and network security company Barracuda warns customers they must replace Email Security Gateway (ESG) appliances hacked in attacks targeting a now-patched zero-day vulnerability. Impacted ESG appliances must be immediately replaced regardless of patch version level. Barracuda's remediation recommendation at this time is full replacement of the impacted ESG.

See the full report here: https://www.bleepingcomputer.com/news/security/barracuda-says-hacked-esg-appliances-must-be-replaced-immediately/


Royal ransomware gang adds BlackSuit encryptor to their arsenal

The Royal ransomware gang has begun testing a new encryptor called BlackSuit that shares many similarities with the operation's usual encryptor. Royal launched in January 2023, believed to be the direct successor to the notorious Conti operation, which shut down in June 2022. This group is a private ransomware operation comprised of pentesters, affiliates from "Conti Team 1," and affiliates they recruited from other enterprise-targeting ransomware gangs.

See the full report here: https://www.bleepingcomputer.com/news/security/royal-ransomware-gang-adds-blacksuit-encryptor-to-their-arsenal/


ChatGPT Hallucinations Open Developers to Supply-Chain Malware Attacks

Attackers can exploit ChatGPT's penchant for returning false information to spread malicious code packages, researchers have found. This poses a significant risk for the software supply chain, as it can allow malicious code and Trojans to slide into legitimate applications and code repositories like npm, PyPI, GitHub, and others.

See the full report here: https://www.darkreading.com/application-security/chatgpt-hallucinations-developers-supply-chain-malware-attacks


Android security update fixes Mali GPU flaw exploited by spyware

Google has released the monthly security update for the Android platform, adding fixes for 56 vulnerabilities, five of them with a critical severity rating and one exploited since at least last December 2022. The new security patch level 2023-06-05 integrates a patch for CVE-2022-22706, a high-severity flaw in the Mali GPU kernel driver from Arm that may have been used in a spyware campaign targeting Samsung phones. There are indications that CVE-2022-22706 may be under limited, targeted exploitation.

See the full report here: https://www.bleepingcomputer.com/news/security/android-security-update-fixes-mali-gpu-flaw-exploited-by-spyware/


Sextortionists are making AI nudes from your social media images

The Federal Bureau of Investigation (FBI) is warning of a rising trend of malicious actors creating deepfake content to perform sextortion attacks. Sextortion is a form of online blackmail where malicious actors threaten their targets with publicly leaking explicit images and videos they stole (through hacking) or acquired (through coercion), typically demanding money payments for withholding the material. FBI warns that sextortionists are now scraping publicly available images of their targets, like innocuous pictures and videos posted on social media platforms. These images are then fed into deepfake content creation tools that turn them into AI-generated sexually explicit content.

See the full report here: https://www.bleepingcomputer.com/news/security/sextortionists-are-making-ai-nudes-from-your-social-media-images/


Zero-Day Alert: Google Issues Patch for New Chrome Vulnerability

Google released security updates to patch a high-severity flaw in its Chrome web browser that it said is being actively exploited in the wild. Tracked as CVE-2023-3079, the vulnerability has been described as a type confusion bug in the V8 JavaScript engine. Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. The tech giant, as is typically the case, did not disclose details of the nature of the attacks, but noted it's "aware that an exploit for CVE-2023-3079 exists in the wild.

See the full report here: https://thehackernews.com/2023/06/zero-day-alert-google-issues-patch-for.html


New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency

A recent malware campaign has been found to leverage Satacom downloader as a conduit to deploy stealthy malware capable of siphoning cryptocurrency using a rogue extension for Chromium-based browsers.The main purpose of the malware that is dropped by the Satacom downloader is to steal BTC from the victim's account by performing web injections into targeted cryptocurrency websites. Targets of the campaign include Coinbase, Bybit, KuCoin, Huobi, and Binance users primarily located in Brazil, Algeria, Turkey, Vietnam, Indonesia, India, Egypt, and Mexico.

See the full report here: https://thehackernews.com/2023/06/new-malware-campaign-leveraging-satacom.html


New PowerDrop Malware Targeting U.S. Aerospace Industry

An unknown threat actor has been observed targeting the U.S. aerospace industry with a new PowerShell-based malware called PowerDrop. PowerDrop uses advanced techniques to evade detection such as deception, encoding, and encryption. The name is derived from the tool, Windows PowerShell, used to concoct the script, and "Drop" from the DROP (DRP) string used in the code for padding. PowerDrop is also a post-exploitation tool, meaning it's designed to gather information from victim networks after obtaining initial access through other means.

See the full report here: https://thehackernews.com/2023/06/new-powerdrop-malware-targeting-us.html


New tool scans iPhones for "Triangulation" malware infection

A new tool has released to detect if Apple iPhones and other iOS devices are infected with a new "Triangulation" malware. The "Operation Triangulation" malware campaign uses an unknown zero-day exploit on iMessage to perform code execution without user interaction and elevated privileges.

See the full report here: https://www.bleepingcomputer.com/news/security/new-tool-scans-iphones-for-triangulation-malware-infection/


Cyclops Ransomware Gang Offers Go-Based Info Stealer to Cybercriminals

Threat actors associated with the Cyclops ransomware have been observed offering an information stealer malware that's designed to capture sensitive data from infected hosts. Cyclops ransomware is notable for targeting all major desktop operating systems, including Windows, macOS, and Linux. It's also designed to terminate any potential processes that could interfere with encryption.

See the full report here: https://thehackernews.com/2023/06/cyclops-ransomware-gang-offers-go-based.html


KeePass v2.54 fixes bug that leaked cleartext master password

KeePass has released version 2.54, fixing the CVE-2023-32784 vulnerability that allows the extraction of the cleartext master password from the application's memory.

See the full report here: https://www.bleepingcomputer.com/news/security/keepass-v254-fixes-bug-that-leaked-cleartext-master-password/


Gigabyte Slams Backdoor Shut With Attack-Killing BIOS Update

Gigabyte has released a BIOS update with increased security following the discovery of an inadvertent system backdoor present on hundreds of models of Gigabyte PCs, ripe for cybercriminal misuse. The hardware, motherboard, and graphics card manufacturer released the Intel 700/600 and AMD 500/400 series Beta BIOS updates on June 1 2023, just one day after the Gigabyte backdoor was publicly revealed by researchers.

See the full report here: https://www.darkreading.com/vulnerabilities-threats/gigabyte-backdoor-attack-killing-bios-update


BA, Boots and BBC staff details targeted in Russia-linked cyber-attack

British Airways, Boots and the BBC are investigating the potential theft of personal details of staff after the companies were hit by a cyber-attack attributed to a Russia-linked criminal gang. BA confirmed it was one of the companies affected by the hack, which targeted software called MOVEit used by Zellis, a payroll provider.

See the full report here: https://www.theguardian.com/technology/2023/jun/05/ba-boots-and-bbc-staff-details-targeted-in-russian-linked-cyber-attack


DEF CON hackers will attempt to pwn a Moonlighter satellite in space

A US government-funded satellite dubbed Moonlighter will launched into space, hitching a ride on a SpaceX rocket before being releasing into Earth's orbit. And in roughly two months later, five teams of DEF CON hackers will do their best to successfully remotely infiltrate and hijack the satellite while it's in space in order to try out offensive and defensive techniques and methods on actual in-orbit hardware and software.

See the full report here: https://www.theregister.com/2023/06/03/moonlighter_satellite_hacking/


Picture-in-Picture Obfuscation Spoofs Delta, Kohl's for Credential Harvesting

Hackers are turning to obfuscation tactics relying on glossy advertising photos from Delta Airlines and retailer Kohl's, tricking users into visiting credential harvesting sites and giving up personal information. Researchers, who dubbed the obfuscation technique "picture in picture," noted that the cybercriminals behind the attacks are simply linking the marketing photos to malicious URLs. This is not to be confused with steganography, which encodes malicious payloads at the pixel level within an image.

See the full report here: https://www.darkreading.com/endpoint/picture-in-picture-obfuscation-spoofs-delta-kohls-credential-harvesting


PostalFurious' SMS Attacks Target UAE Citizens for Data Theft

Residents of the United Arab Emirates have been targeted by SMS campaigns that aim to steal payment and personal details. Previously targeted at users in Asia-Pacific, the campaign has been named PostalFurious as it impersonates postal services. Investigations by researchers attributed both campaigns to a Chinese-speaking phishing ring dubbed PostalFurious. This group has been active since at least 2021 and are able to rapidly set up large network infrastructures, which they also change quite frequently to avoid detection by security tools, and utilize access-control techniques to avoid automated detection and blocking.

See the full report here: https://www.darkreading.com/dr-global/postalfurious-sms-attacks-target-uae-citizens-data-theft


New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

An analysis of the Linux variant of a new ransomware strain called BlackSuit has covered significant similarities with another ransomware family called Royal. BlackSuit first came to light in early May 2023 when researchers drew attention to its ability to target both Windows and Linux hosts.

See the full report here: https://thehackernews.com/2023/06/new-linux-ransomware-strain-blacksuit.html


Alarming Surge in TrueBot Activity Revealed with New Delivery Vectors

A surge in TrueBot activity was observed in May 2023, cybersecurity researchers disclosed. TrueBot is a downloader trojan botnet that uses command and control servers to collect information on compromised systems and uses that compromised system as a launching point for further attacks. Active since at least 2017, TrueBot is linked to a group known as Silence that's believed to share overlaps with the notorious Russian cybercrime actor known as Evil Corp. Recent TrueBot infections have leveraged a critical flaw in Netwrix auditor (CVE-2022-31199, CVSS score: 9.8) as well as Raspberry Robin as delivery vectors.

See the full report here: https://thehackernews.com/2023/06/alarming-surge-in-truebot-activity.html


Brazilian Cybercriminals Using LOLBaS and CMD Scripts to Drain Bank Accounts

An unknown cybercrime threat actor has been observed targeting Spanish- and Portuguese-speaking victims to compromise online banking accounts in Mexico, Peru, and Portugal. This threat actor employs tactics such as LOLBaS (living-off-the-land binaries and scripts), along with CMD-based scripts to carry out its malicious activities. Researchers attributed the campaign, dubbed Operation CMDStealer, to a Brazilian threat actor based on an analysis of the artifacts.

See the full report here: https://thehackernews.com/2023/06/brazilian-cybercriminals-using-lolbas.html


Atomic Wallet hacks lead to over USD 35 million in crypto stolen

The developers of Atomic Wallet are investigating reports of large-scale theft of cryptocurrency from users' wallets, with over USD 35 million in crypto reportedly stolen. Atomic Wallet is a mobile and desktop crypto wallet allowing users to store various cryptocurrencies. The wallet is offered for multiple operating systems, including Windows, Android, iOS, macOS, and Linux. On June 3rd 2023, Atomic Wallet tweeted that they had received reports of compromised wallets and had begun investigating the issue.

See the full report here: https://www.bleepingcomputer.com/news/security/atomic-wallet-hacks-lead-to-over-35-million-in-crypto-stolen/


Online sellers targeted by new information-stealing malware campaign

Online sellers are targeted in a new campaign to push the Vidar information-stealing malware, allowing threat actors to steal credentials for more damaging attacks. The new campaign involved threat actors sending complaints to online store admins through email and website contact forms. These emails pretend to be from a customer of an online store who had USD 550 deducted from their bank account after an alleged order did not properly go through.

See the full report here: https://www.bleepingcomputer.com/news/security/online-sellers-targeted-by-new-information-stealing-malware-campaign/


Hackers hijack legitimate sites to host credit card stealer scripts

A new Magecart credit card stealing campaign hijacks legitimate sites to act as "makeshift" command and control (C2) servers to inject and hide the skimmers on targeted eCommerce sites. A Magecart attack is when hackers breach online stores to inject malicious scripts that steal customers' credit cards and personal information during checkout. According to the researchers monitoring this campaign, it has compromised organizations in the United States, the United Kingdom, Australia, Brazil, Peru, and Estonia.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-hijack-legitimate-sites-to-host-credit-card-stealer-scripts/


Russia says US hacked thousands of iPhones in iOS zero-click attacks

Russian cybersecurity firm Kaspersky says some iPhones on its network were hacked using an iOS vulnerability that installed malware via iMessage zero-click exploits. The delivery of the message exploits a vulnerability that leads to code execution without requiring any user interaction, leading to the download of additional malicious from the attackers' server. Subsequently, the message and attachment are wiped from the device. At the same time, the payload stays behind, running with root privileges to collect system and user information and execute commands sent by the attackers.

See the full report here: https://www.bleepingcomputer.com/news/security/russia-says-us-hacked-thousands-of-iphones-in-ios-zero-click-attacks/


Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

Harvard Pilgrim Health Care (HPHC) has disclosed that a ransomware attack it suffered in April 2023 impacted 2,550,922 people, with the threat actors also stealing their sensitive data from compromised systems. The Massachusetts-based non-profit health services provider shared this information—which corresponds to roughly all its members—to the U.S. Department of Health and Human Services breach portal. The organization published a notice informing that ransomware actors maintained access to its systems between March 28 and April 17, 2023, when the breach was discovered.

See the full report here: https://www.bleepingcomputer.com/news/security/harvard-pilgrim-health-care-ransomware-attack-hits-25-million-people/


Sustained "Red Deer" Phishing Attacks Impersonate Israel Post, Drop RATs

Israeli engineering and telecommunications companies have been targeted with a sustained phishing message campaign that is convincingly impersonating Israel's postal service. Researchers found the phishing email typically appears to be a missed delivery note containing an HTML link. When clicked, it downloads and opens an .html file attachment on the user's browser. This html file then opens an ISO image file that contains an obfuscated Visual Basic script, which ultimately downloads a modified version of the AsyncRAT malware.

See the full report here: https://www.darkreading.com/dr-global/sustained-red-deer-phishing-attacks-israel-post-rats


Novel PyPI Malware Uses Compiled Python Bytecode to Evade Detection

In a new twist on software supply chain attacks, researchers have discovered a Python package hiding malware inside of compiled code, allowing it to evade ordinary detection measures. On April 17 2023, researchers reported a packaged called "fshec2" to the administrators of the Python open source repository PyPI. Malicious packages aren't new — or particularly rare — in PyPI, but unlike the lot of them, fshec2 contained all of its malicious functionality inside of its compiled code, making it hard to spot as bad news. The PyPI admins immediately removed the package.

See the full report here: https://www.darkreading.com/application-security/novel-pypi-malware-compiled-python-bytecode-evade-detection


Google Drive Deficiency Allows Attackers to Exfiltrate Workspace Data Without a Trace

A lack of event logging in the free-subscription version of Google Workspace can allow attackers to download data from Google Drive without leaving behind a trace of their illicit activity. Though users with a paid license, such as Google Workspace Enterprise Plus, enjoy the benefit of visibility into Google Drive activity through "drive log events" — which record actions such as copying, deleting, downloading, and viewing files — those with a default Cloud Identity Free license don't, the researchers said. This makes organizations blind to potential data manipulation and exfiltration attacks, limiting how quickly and effectively organizations can respond.

See the full report here: https://www.darkreading.com/endpoint/google-drive-deficiency-exfiltrate-workspace-data


New Horabot campaign takes over victim's Gmail, Outlook accounts

A previously unknown campaign involving the Hotabot botnet malware has targeted Spanish-speaking users in Latin America since at least November 2020, infecting them with a banking trojan and spam tool. The malware enables the operators to take control of the victim's Gmail, Outlook, Hotmail, or Yahoo email accounts, steal email data and 2FA codes arriving in the inbox, and send phishing emails from the compromised accounts.

See the full report here: https://www.bleepingcomputer.com/news/security/new-horabot-campaign-takes-over-victims-gmail-outlook-accounts/


New MOVEit Transfer zero-day mass-exploited in data theft attacks

Hackers are actively exploiting a zero-day vulnerability in the MOVEit Transfer file transfer software to steal data from organizations. The attacks started over the long US Memorial Day holiday when fewer staff were monitoring systems. The MOVEit Transfer flaw is a SQL injection vulnerability that leads to remote code execution and does not currently have a CVE assigned to it. There are 2,500 exposed MOVEit Transfer servers, with the majority located in the US, and that the same webshell was found on all exploited devices.

See the full report here: https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report - Reports of Active Exploitation of MOVEit Transfer SQL Zero-Day Vulnerability

In this flash report, ZeroFox researchers provide an overview of a zero-day vulnerability that was disclosed in MOVEit Transfer, a secure managed file transfer software developed by Progress Software Corporation. All MOVEit Transfer versions are affected by this vulnerability, with security patches released for five supported versions.

Report: https://zerofox.com/advisories/20782


ZeroFox Intelligence Flash Report - Kosovo-Serbia Tensions Reignite

In this flash report, ZeroFox’s Geopolitical Working Group provides an overview of recent Kosovo-Serbia tensions, the background of them, and what implications of the current conflict may look like.

Report: https://zerofox.com/advisories/20780


Tags: tlp:clear,  all industries,  global