ZeroFox Daily Intelligence Brief - June 27, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 27, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- 19,000 Documents Exposed in Cyberattack on NYC DOE
- Spike in Credential Stealing Attacks by Russian State-Affiliated Hackers
- Anatsa Android Trojan Stealing Banking Information in Europe and America
- Vulnerabilities: CVE-2023-3420, CVE-2023-34463, and CVE-2023-34924
- Exploits: CVE-2019-9194, CVE-2010-3275, and CVE-2009-3843
- Breaches: BreachForums/XSS: RuneScape Data Breach and BreachForums/XSS: Cannabis.com Data Breach
19,000 Documents Exposed in Cyberattack on NYC DOE
The New York City Department of Education (DOE) has fallen victim to a data breach via a MOVEit Transfer bug exploit. About 19,000 documents were accessed in the breach, compromising data relating to 45,000 students, staff, and service providers. ZeroFox Intelligence notes that Clop has named prominent organizations—including Siemens Energy, Schneider Electric, and one of America’s largest public universities—as victims in the past 24 hours, as part of its MOVEit Transfer bug exploit campaign.
Spike in Credential Stealing Attacks by Russian State-Affiliated Hackers
Security researchers have observed an increase in credential-stealing attacks by Russian state-affiliated group Midnight Blizzard (APT29 / Cozy Bear) on government entities, IT companies, NGOs, defense bodies, and critical-manufacturing organizations. Researchers have warned defenders of the group’s use of credential attacks and session-replay attacks and highlighted the use of residential proxy services to hide the source IP address.
Anatsa Android Trojan Stealing Banking Information in Europe and America
A new mobile malware campaign has been targeting online banking customers in the United States, the United Kingdom, Germany, Austria, and Switzerland since March 2023. The new Anatsa malware strain, distributed via Android's Play Store, masquerades as a PDF viewer, editor app, or office suite. It collects users’ financial information by overlaying phishing pages and keylogging. The stolen funds are converted to cryptocurrency and funneled through an extensive network of money launderers.
VULNERABILITIES
- CVE-2023-3420 - Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2023-34463 - In affected versions of DataEase, unauthorized users can delete an application erroneously.
- CVE-2023-34924 - H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById.
EXPLOITS
- CVE-2019-9194 - elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection
- CVE-2010-3275 - VideoLAN VLC Media Player 1.1.4 - AMV Dangling Pointer
- CVE-2009-3843 - Apache Tomcat Manager Code Execution
BREACHES
- BreachForums/XSS: RuneScape Data Breach - (78,749 Records) | Email address and password
- BreachForums/XSS: Cannabis.com Data Breach - (194,308 Records) | Email address and password
Tags: DIB, tlp:green