ZeroFox Daily Intelligence Brief - June 26, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 26, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- American Airlines and Southwest Airlines Disclose Breach of Employee Data
- Trojanized Super Mario Game Used to Install Windows Malware
- Muddled Libra Targets BPO Sector with Advanced Social Engineering
- Vulnerabilities: CVE-2023-27476 and CVE-2023-36663
- Exploits: CVE-2006-4868, CVE-2018-13784 and CVE-2010-3275
- Breaches: Credit Card Data Breach: 2023-6-24 (516422 | 3014) and BreachForums/XSS: Wealth Start Business Data Breach (205,785 Records)
American Airlines and Southwest Airlines Disclose Breach of Employee Data
A cyberattack on a third-party vendor's systems resulted in the compromise of sensitive and personally identifiable information (PII) of thousands of employees of American Airlines and Southwest Airlines. The breached data included names, Social Security numbers, driver's license numbers, passport details, dates of birth, and Airman Certificate number of pilots and other members of the staff. The airlines’ internal networks and systems were not affected.
Trojanized Super Mario Game Used to Install Windows Malware
A trojanized installer for the popular Super Mario 3: Mario Forever game on Windows has been infecting unsuspecting players with malware infections. The game, developed by Buziol Games in 2003, gained immense popularity for its classic Mario mechanics with updated graphics and sound. However, researchers discovered that threat actors are distributing a modified version of the installer containing malicious executables that install a Monero miner and a SupremeBot mining client.
Muddled Libra Targets BPO Sector with Advanced Social Engineering
The business process outsourcing (BPO) industry is under attack by a threat actor referred to as "Muddled Libra," which employs sophisticated social engineering tactics for initial access. Muddled Libra emerged in late 2022 with the release of the 0ktapus phishing kit. The group leverages compromised infrastructure and stolen data for downstream attacks on victims' customers, obtained by manipulating endpoint security solutions, exploiting MFA notification fatigue, and engaging in social engineering.
VULNERABILITIES
- CVE-2023-27476 - OWSLib's XML parser does not disable entity resolution, and could lead to arbitrary file reads from an attacker-controlled XML payload.
- CVE-2023-36663 - it-novum openITCOCKPIT before 4.6.5 allows SQL Injection via the sort parameter of the API interface.
EXPLOITS
- CVE-2006-4868 - Microsoft Internet Explorer - VML Remote Buffer Overflow (SP2)
- CVE-2018-13784 - PrestaShop < 1.6.1.19 - AES CBC Privilege Escalation Exploit
BREACHES
- Credit Card Data Breach: 2023-6-24 (516422 | 3014) - Credit card
- BreachForums/XSS: Wealth Start Business Data Breach - (205,785 Records) | Email address and password
Tags: DIB, tlp:green