zerofox logo
Advisories

Threat Intelligence Bulletin: 06/09/2023 - 06/15/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 06/09/2023 - 06/15/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - June 15, 2023

Brief Highlights

  • Understanding Ransomware Threat Actors: LockBit
  • CISA and NSA Release Joint Guidance on Hardening Baseboard Management Controllers
  • Fake Zero-Day PoC Exploits on GitHub Push Malware
  • Vulnerabilities: CVE-2023-3193, CVE-2023-35029, and CVE-2022-32757
  • Exploits: CVE-2018-8897, CVE-2015-3073, and CVE-2013-4113
  • Breaches: Telegram: 'Logs_8.8.7z' Botnet Breach, Credit Card Data Breach: 2023-6-14, and BreachForums/XSS: World Poker Tour Data Breach

Report: https://zerofox.com/advisories/20893


ZeroFox Daily Intelligence Brief - June 14, 2023

Brief Highlights

  • CISA: Binding Operational Directive 23-02
  • Pirated Copies of Windows 10 Conceal Malicious Code in EFI Partition
  • Over 3,000 Domains Used for Impersonating Apparel and Lifestyle Brands in Phishing Campaign
  • Vulnerabilities: CVE-2023-24329, CVE-2023-26555, and CVE-2023-3203
  • Exploits: CVE-2018-19423, CVE-2018-17463, and CVE-2009-0182
  • Breaches: Credit Card Data Breach: 2023-6-12 and BreachForums: Watchfinder & Co. Data Breach

Report: https://zerofox.com/advisories/20882


ZeroFox Daily Intelligence Brief - June 13, 2023

Brief Highlights

  • Swiss Government: Russia-Based DDoS Attacks Causing Access Problems
  • Researchers Report First Instance of Automated SaaS Ransomware Extortion
  • Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable
  • Vulnerabilities: CVE-2023-2876, CVE-2023-33986, and CVE-2023-32115
  • Exploits: CVE-2000-0884, CVE-2019-13623, and CVE-2017-12542
  • Breaches: BreachForums/XSS: Forex Investor Data Breach, Telegram: 'logs-a1.7z' Botnet Breach, and BreachForums/XSS: ViewPointS Data Breach

Report: https://zerofox.com/advisories/20861


ZeroFox Daily Intelligence Brief - June 12, 2023

Brief Highlights

  • Strava’s Heatmap Feature Could Expose Users' Home Addresses
  • Fortinet Releases Critical SSL VPN Patch to Address Remote Code Execution Vulnerability
  • Brand-New Security Bugs Addressed in MOVEit Transfer
  • Vulnerabilities: CVE-2023-35036, CVE-2020-36732, and CVE-2023-29753
  • Breaches: Credit Card Data Breach: 2023-6-10 and Telegram: 'ZEBRA CLOUD FREE.rar' Botnet Breach

Report: https://zerofox.com/advisories/20850


ZeroFox Daily Intelligence Brief - June 9, 2023

Brief Highlights

  • Asylum Ambuscade Combines Cyber Espionage and Cybercrime in Recent Attacks
  • CISA Releases Two Industrial Control Systems Advisories
  • Google Switches Email Authentication Standards Because of Spoofing Vulnerability
  • Vulnerabilities: CVE-2023-29536, CVE-2023-29533, and CVE-2023-29535
  • Exploits: CVE-2011-2371, CVE-2014-3704, and CVE-2021-38294
  • Breaches: BreachForums: UniverseGamers Gunz Data Breach and Credit Card Data Breach: 2023-6-7

Report: https://zerofox.com/advisories/20843


Breach Disclosures:


Breach Disclosure: ViewPointS

An alleged data breach at ViewPointS – a website that provides webcam access to historical sites and attractions in Florence (Italy) – exposed 46,443 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20892


Breach Disclosure: Watchfinder & Co.

An alleged data breach at Watchfinder & Co – a U.K.-based online retailer of second-hand watches– exposed 681,753 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20891


Breach Disclosure: EdilPortale

An alleged data breach at EdilPortale – an Italy-based company that operates in the architecture and planning industry – exposed 83,427 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20890


Breach Disclosure: Age of Wushu

An alleged data breach at Age of Wushu – a U.S.-based gaming site – exposed 107,027 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20881


Breach Disclosure: Xoffer

An alleged data breach at Xoffer – a Hong Kong-based company that operates in retail sale of computers and computer peripheral equipment – exposed 45,031 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20880


Breach Disclosure: Forex Investor

An alleged data breach at Forex Investor – a Russia-based trading platform – exposed 42,738 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20879


Breach Disclosure: Poshmark

An alleged data breach at Poshmark – a U.S.-based online apparel and accessories retail store – exposed 39,305 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20878


Breach Disclosure: Bondagestory

An alleged data breach at Bondagestory – a U.S.-based adult entertainment site – exposed 38,989 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20877


Breach Disclosure: HostMonster

An alleged data breach at HostMonster – a U.S.-based company that provides internet service providers, website hosting and internet-related services – exposed 36,665 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20876


Breach Disclosure: EpicNPC

An alleged data breach at EpicNPC – a U.S.-based video game and social media marketplace – exposed 50,338 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20875


Breach Disclosure: Avvo

An alleged data breach at Avvo – a U.S.-based consumer information website that specializes in providing data about practicing attorneys – exposed 19,018 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20874


Breach Disclosure: Forums Gre

An alleged data breach at Forums Gre – a U.S.-based online bulletin board – exposed 49,987 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20873


Breach Disclosure: Dogewallet

An alleged data breach at Dogewallet – a U.S.-based mobile app that works with several crypto tokens and blockchain wallets – exposed 22,542 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20872


Breach Disclosure: ButterFly Labs

An alleged data breach at ButterFly Labs – a U.S.-based company that makes machines that mine and locate bitcoins – exposed 18,459 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20871


Breach Disclosure: Xclan

An alleged data breach at Xclan – a U.S.-based gaming discussion forum – exposed 12,562 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20870


Breach Disclosure: PubPit

An alleged data breach at PubPit – a U.S.-based digital publishing software solution– exposed 51,415 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20869


Breach Disclosure: Btc60.net

An alleged data breach at Btc60.net – a Canada-based "play-to-earn" cryptocurrency gaming site – exposed 52,179 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20849


Breach Disclosure: JustSkins

An alleged data breach at JustSkins – a U.S.-based hacking forum – exposed 2,624 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20848


Breach Disclosure: Void

An alleged data breach at Void – a U.S.-based hacking forum – exposed 13,427 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20847


Breach Disclosure: Jobmada

An alleged data breach at Jobmada – a Madagascar-based firm that specializes in human resources – exposed 19,018 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20846


Breaking News:


New Report Reveals Shuckworm's Long-Running Intrusions on Ukrainian Organizations

The Russian threat actor known as Shuckworm has continued its cyber assault spree against Ukrainian entities in a bid to steal sensitive information from compromised environments. Targets of the recent intrusions, which began in February/March 2023, include security services, military, and government organizations. In some cases, the Russian group succeeded in staging long-running intrusions, lasting for as long as three months

See the full report here: https://thehackernews.com/2023/06/new-report-reveals-shuckworms-long.html


New Supply Chain Attack Exploits Abandoned S3 Buckets to Distribute Malicious Binaries

In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 buckets to serve rogue binaries without altering the modules themselves. Malicious binaries steal the user IDs, passwords, local machine environment variables, and local host name, and then exfiltrates the stolen data to the hijacked bucket.

See the full report here: https://thehackernews.com/2023/06/new-supply-chain-attack-exploits.html


CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly USD 91 million following approximately 1,700 attacks against U.S. organizations since 2020.


Chinese hackers use DNS-over-HTTPS for Linux malware communication

The Chinese threat group "ChamelGang" infects Linux devices with a previously unknown implant named "ChamelDoH" allowing DNS-over-HTTPS communications with attackers' servers. The particular threat actor was first documented back in September 2021; however, the researchers only focused on the Windows toolkit.

See the full report here: https://www.bleepingcomputer.com/news/security/chinese-hackers-use-dns-over-https-for-linux-malware-communication/


Microsoft links data wiping attacks to new Russian GRU hacking group

Microsoft has linked a threat group it tracks as Cadet Blizzard since April 2023 to Russia’s Main Directorate of the General Staff of the Armed Forces (also known as GRU). The company previously connected this new GRU hacking group with the destructive WhisperGate data-wiping attacks in Ukraine that started on January 13, 2022, more than a month before the Russian invasion of Ukraine in February 2022. Cadet Blizzard was also behind the defacement of Ukrainian websites in early 2022 and several hack-and-leak operations that were promoted on a low-activity Telegram channel known as "Free Civilian."

See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-links-data-wiping-attacks-to-new-russian-gru-hacking-group/


WannaCry ransomware impersonator targets Russian "Enlisted" FPS players

A ransomware operation targets Russian players of the Enlisted multiplayer first-person shooter, using a fake website to spread trojanized versions of the game. Enlisted is a legitimate game published by Gaijin Entertainment in 2021, having between 500,000 and a million active monthly players. The game is free, so threat actors could easily download the installer from the publisher and modify it to distribute malicious payloads to unsuspecting users.

See the full report here: https://www.bleepingcomputer.com/news/security/wannacry-ransomware-impersonator-targets-russian-enlisted-fps-players/


New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs

A new Golang-based information stealer called Skuld has compromised Windows systems across Europe, Southeast Asia, and the U.S. To accomplish this task, it searches for data stored in applications such as Discord and web browsers; information from the system and files stored in the victim's folders.

See the full report here: https://thehackernews.com/2023/06/new-golang-based-skuld-malware-stealing.html


Hackers can steal cryptographic keys by video-recording power LEDs 60 feet away

Researchers have devised a novel attack that recovers the secret encryption keys stored in smart cards and smartphones by using cameras in iPhones or commercial surveillance systems to video record power LEDs that show when the card reader or smartphone is turned on. The attacks enable a new way to exploit two previously disclosed side channels, a class of attack that measures physical effects that leak from a device as it performs a cryptographic operation.

See the full report here: https://arstechnica.com/information-technology/2023/06/hackers-can-steal-cryptographic-keys-by-video-recording-connected-power-leds-60-feet-away/


Chinese hackers used VMware ESXi zero-day to backdoor VMs

VMware patched a VMware ESXi zero-day vulnerability exploited by a Chinese-sponsored hacking group to backdoor Windows and Linux virtual machines and steal data. The cyber espionage group—tracked as UNC3886, abused the CVE-2023-20867 VMware Tools authentication bypass flaw to deploy VirtualPita and VirtualPie backdoors on guest VMs from compromised ESXi hosts where they escalated privileges to root. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

See the full report here: https://www.bleepingcomputer.com/news/security/chinese-hackers-used-vmware-esxi-zero-day-to-backdoor-vms/


CISA orders federal agencies to secure Internet-exposed network devices

CISA issued this year's first binding operational directive (BOD) ordering federal civilian agencies to secure misconfigured or Internet-exposed networking equipment within 14 days of discovery. The cybersecurity agency's Binding Operational Directive 23-02 applies to networked devices with Internet-exposed management interfaces (e.g., routers, firewalls, proxies, and load balancers) that grant authorized users the necessary access for performing network administrative duties.

See the full report here: https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-secure-internet-exposed-network-devices/


Fake zero-day PoC exploits on GitHub push Windows, Linux malware

Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Windows and Linux with malware. These malicious exploits are promoted by alleged researchers at a fake cybersecurity company named "High Sierra Cyber Security," who promote the GitHub repositories on Twitter, likely to target cybersecurity researchers and firms involved in vulnerability research. The repositories appear legitimate, and the users who maintain them impersonate real security researchers, even using their headshots.

See the full report here: https://www.bleepingcomputer.com/news/security/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware/


Pirated Windows 10 ISOs install clipper malware via EFI partitions

Hackers are distributing malicious copies of Windows 10 using torrents that hide cryptocurrency hijackers in the EFI (Extensible Firmware Interface) partition to evade detection.

See the full report here: https://www.bleepingcomputer.com/news/security/pirated-windows-10-isos-install-clipper-malware-via-efi-partitions/


Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer

Security researchers have warned about an "easily exploitable" flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute malicious extensions.

See the full report here: https://thehackernews.com/2023/06/researchers-uncover-publisher-spoofing.html


Swiss government warns of ongoing DDoS attacks, data leak

The Swiss government has disclosed that a recent ransomware attack on an IT supplier might have impacted its data, while today, it warns that it is now targeted in DDoS attacks. The situation reflects the complex threats affecting organizations and governments as they utilize third-party services to host data and publicly expose online services.

See the full report here: https://www.bleepingcomputer.com/news/security/swiss-government-warns-of-ongoing-ddos-attacks-data-leak/


Exploit released for MOVEit RCE bug used in data theft attacks

Security researchers have released proof-of-concept (PoC) exploit code for a remote code execution (RCE) bug in the MOVEit Transfer managed file transfer (MFT) solution abused by the Clop ransomware gang in data theft attacks. This critical flaw (tracked as CVE-2023-34362) is an SQL injection vulnerability that lets unauthenticated attackers gain access to unpatched MOVEit servers and execute arbitrary code remotely.

See the full report here: https://www.bleepingcomputer.com/news/security/exploit-released-for-moveit-rce-bug-used-in-data-theft-attacks/


Have I Been Pwned warns of new Zacks data breach impacting 8 million

Zacks Investment Research (Zacks) has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum. The firm previously disclosed a data breach that occurred between November 2021 and August 2022, warning that unauthorized network intruders accessed the personal and sensitive information of about 820,000 customers.

See the full report here: https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-new-zacks-data-breach-impacting-8-million/


Microsoft: Azure Portal outage was caused by traffic “spike”

Microsoft revealed in an update to the Azure status page that the preliminary root cause behind an outage that impacted the Azure Portal worldwide was what it described as a traffic "spike." The connectivity issues also impacted other Microsoft websites, according to Redmond's update on the Azure status page, including the Entra Admin center at entra.microsoft.com and Intune at intune.microsoft.com.

See the full report here: https://www.bleepingcomputer.com/news/microsoft/microsoft-azure-portal-outage-was-caused-by-traffic-spike-/


Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

A fully undetectable (FUD) malware obfuscation engine named BatCloak is being used to deploy various malware strains since September 2022, while persistently evading antivirus detection. About 79.6% of the total 784 artifacts unearthed have no detection across all security solutions, highlighting BatCloak's ability to circumvent traditional detection mechanisms.

See the full report here: https://thehackernews.com/2023/06/cybercriminals-using-powerful-batcloak.html


UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims

Two more organizations hit in the mass exploitation of the MOVEit file-transfer tool have been named – the Minnesota Department of Education in the US, and the UK's telco regulator Ofcom – just days after security researchers discovered additional flaws in Progress Software's buggy suite

See the full report here: https://www.theregister.com/2023/06/13/ofcom_minnesota_moveit/


Indian Agency Investigating Alleged Covid Vaccination Data Leak On Telegram

The Indian government is investigating reports that the personal details of people registered on the CoWIN portal - the country's Covid-19 vaccination tracking platform - were leaked on Telegram. A report has claimed that sensitive personal information of several politicians, bureaucrats, and individuals - who had signed up on CoWIN - was shared by a bot account on Telegram.

See the full report here: https://www.ndtv.com/india-news/cowin-telegram-saket-gokhale-centre-investigating-alleged-cowin-data-leak-on-telegram-sources-4114313


New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies

Vietnamese public companies have been targeted as part of an ongoing campaign that deploys a novel backdoor called SPECTRALVIPER. SPECTRALVIPER is a heavily obfuscated, previously undisclosed, x64 backdoor that brings PE loading and injection, file upload and download, file and directory manipulation, and token impersonation capabilities. The attacks have been attributed to an actor it tracks as REF2754, which overlaps with a Vietnamese threat group known as APT32, Canvas Cyclone (formerly Bismuth), Cobalt Kitty, and OceanLotus

See the full report here: https://thehackernews.com/2023/06/new-spectralviper-backdoor-targeting.html


Russians charged with hacking Mt. Gox crypto exchange, running BTC-e

Two Russian nationals have been charged with the 2011 hacking of the leading cryptocurrency exchange Mt. Gox and the laundering of around 647,000 bitcoins they stole. The U.S. Department of Justice also charged the individuals for running the unlicensed BTC-e Bitcoin trading platform between 2011 and 2017. According to the unsealed indictment, in September 2011, a group including the two defendants hacked Mt. Gox, the largest bitcoin exchange at the time, stealing roughly 647,000 bitcoins over the next few years. \

See the full report here: https://www.bleepingcomputer.com/news/security/russians-charged-with-hacking-mt-gox-crypto-exchange-running-btc-e/


New MOVEit Transfer critical flaws found after security audit, patch now

Progress Software warned customers of newly found critical SQL injection vulnerabilities in its MOVEit Transfer managed file transfer (MFT) solution that can let attackers steal information from customers' databases. They affect all MOVEit Transfer versions and enable unauthenticated attackers to compromise Internet-exposed servers to alter or extract customer information.

See the full report here: https://www.bleepingcomputer.com/news/security/new-moveit-transfer-critical-flaws-found-after-security-audit-patch-now/


Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now

Fortinet has released new Fortigate firmware updates that fix an undisclosed, critical pre-authentication remote code execution vulnerability in SSL VPN devices. The security fixes were released in FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5.

See the full report here: https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-rce-flaw-in-fortigate-ssl-vpn-devices-patch-now/


Hackers steal USD 3 million by impersonating crypto news journalists

A hacking group tracked as "Pink Drainer" is impersonating journalists in phishing attacks to compromise Discord and Twitter accounts for cryptocurrency-stealing attacks. Pink Drainer compromised the accounts of 1,932 victims to steal roughly USD 2,997,307 worth of digital assets on the Mainnet and Arbitrum. ScamSniffer's on-chain monitoring bots caught the threat actor when they snatched USD 327,000 worth of NFTs from a single person.

See the full report here: https://www.bleepingcomputer.com/news/cryptocurrency/hackers-steal-3-million-by-impersonating-crypto-news-journalists/


University of Manchester says hackers stole data in cyberattack

The University of Manchester warns staff and students that they suffered a cyberattack where threat actors likely stole data from the University's network. In a statement published on its website, the University of Manchester says they discovered the breach on June 6 2023, and immediately launched an investigation.

See the full report here: https://www.bleepingcomputer.com/news/security/university-of-manchester-says-hackers-likely-stole-data-in-cyberattack/


Strava heatmap feature can be abused to find home addresses

Researchers at the North Carolina State University Raleigh have discovered a privacy risk in the Strava app's heatmap feature that could lead to identifying users' home addresses.

See the full report here: https://www.bleepingcomputer.com/news/security/strava-heatmap-feature-can-be-abused-to-find-home-addresses/


Ukrainian hackers take down service provider for Russian banks

A group of Ukrainian hackers known as the Cyber.Anarchy.Squad claimed an attack that took down Russian telecom provider Infotel JSC. Moscow-based Infotel provides connectivity services between the Russian Central Bank and other Russian banks, online stores, and credit institutions. Following the attack, multiple major banks across Russia had their access cut off from the country's banking systems so that they can no longer make online payments.

See the full report here: https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/


Google changes email authentication after spoof shows a bad delivery for UPS

Google says it has fixed a flaw that allowed a scammer to impersonate delivery service UPS on Gmail, The problem stemmed from an issue in an email authentication program called Brand Indicators for Message Identification (BIMI) that aims to protect email users from brand spoofing and phishing attacks claiming to be from a trusted org.

See the full report here: https://www.theregister.com/2023/06/09/google_bimi_email_authentication/


Shell Recharge security lapse exposed EV drivers’ data

Oil giant Shell said it is investigating after a security researcher found an exposed internal database spilling the personal information of drivers who use the company’s electric vehicle charging stations.

See the full report here: https://techcrunch.com/2023/06/09/shell-recharge-security-lapse-exposed-drivers-data/


Japanese pharma giant Eisai discloses ransomware attack

Pharmaceutical company Eisai has disclosed it suffered a ransomware incident that impacted its operations, admitting that attackers encrypted some of its servers. In a notification posted to their website, Eisai disclosed that it suffered a ransomware attack over the weekend, a typical time for attackers to deploy encryptors as IT teams are understaffed and unable to respond effectively to the rapidly evolving situation.

See the full report here: https://www.bleepingcomputer.com/news/security/japanese-pharma-giant-eisai-discloses-ransomware-attack/


Microsoft OneDrive down worldwide following claims of DDoS attacks

Microsoft is investigating an ongoing outage that is preventing OneDrive customers from accessing the cloud file hosting service worldwide, just as a threat actor group known as "Anonymous Sudan" claims to be DDoSing the service. Users who are trying to open the OneDrive website have reported seeing "Sorry, an error has occurred" and "This page isn't working right now" error messages.

See the full report here: https://www.bleepingcomputer.com/news/microsoft/microsoft-onedrive-down-worldwide-following-claims-of-ddos-attacks/


Asylum Ambuscade hackers mix cybercrime with espionage

A hacking group tracked as "Asylum Ambuscade" was observed in recent attacks targeting small to medium-sized companies worldwide, combining cyber espionage with cybercrime. The particular threat group, believed to have been operational since at least 2020, was first identified in a March 2022 report that focused on a phishing campaign against entities aiding the Ukrainian refugees' movement.

See the full report here: https://www.bleepingcomputer.com/news/security/asylum-ambuscade-hackers-mix-cybercrime-with-espionage/


PoC released for Windows Win32k bug exploited in attacks

Researchers have released a proof-of-concept (PoC) exploit for an actively exploited Windows local privilege escalation vulnerability fixed as part of the May 2023 Patch Tuesday. The vulnerability is tracked as CVE-2023-29336 and was assigned a CVSS v3.1 severity rating of 7.8 as it allows low-privileged users to gain Windows SYSTEM privileges, the highest user mode privileges in Windows

See the full report here: https://www.bleepingcomputer.com/news/security/poc-released-for-windows-win32k-bug-exploited-in-attacks/


Stealth Soldier: A New Custom Backdoor Targets North Africa with Espionage Attacks

A new custom backdoor dubbed Stealth Soldier has been deployed as part of a set of highly-targeted espionage attacks in North Africa. Stealth Soldier malware is an undocumented backdoor that primarily operates surveillance functions such as file exfiltration, screen and microphone recording, keystroke logging and stealing browser information.

See the full report here: https://thehackernews.com/2023/06/stealth-soldier-new-custom-backdoor.html


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report - Clop Ransomware Collective Targets New Victims Across Multiple Sectors

In this flash report, ZeroFox researchers provide updates on recent developments with the Clop ransomware collective, including multiple updates to its shame site.

Report: https://zerofox.com/advisories/20901


ZeroFox Intelligence Cyber Threat Advisory - KillNet Claims Imminent Attack

In this advisory, ZeroFox Intelligence provides analysis around KillNet's recent claims of an imminent attack against Western Financial Systems, and assesses the likelihood of such an attack taking place.

Report: https://zerofox.com/advisories/20900


ZeroFox Intelligence Flash Report - Israel’s Judicial Overhaul and Associated Mass Protests

In this flash report, ZeroFox's Geopolitical Working Group provides an update on the current situation in Israel, where a proposed judicial overhaul has led to widespread and recurring protests and where any communication concerning ongoing negotiations has been limited.

Report: https://zerofox.com/advisories/20845


Tags: tlp:clear,  all industries,  global