ZeroFox Daily Intelligence Brief - July 12, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 12, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Chinese Hackers Gained Access to Government Email Accounts
- Hackers Exploit Windows Kernel Loophole with Malicious Driver Signings
- Financially Motivated Threat Actor ScarletEel Exploiting AWS for Malicious Activities
- Data broker / initial-access broker / hacktivist group: Telegram channel 0x_dump and NoName057(16)
- Vulnerabilities: CVE-2022-39280 and CVE-2022-39294
- Exploits: CVE-2015-1701 and CVE-2013-6282
- Breaches: BreachForums/XSS: Corevin Data Breach and Belly Ballot Data Breach
Chinese Hackers Gained Access to Government Email Accounts
Microsoft has disclosed that it mitigated an attack by a China-based threat actor (Storm-0558) that primarily targeted emails in government agencies in Western Europe and focused on espionage, data theft, and credential access. Since May 15, 2023, Storm-0558 gained access to email data from about 25 organizations. Microsoft has completed the mitigation for the attack and notified all impacted customers—no user action is required to address this threat.
Hackers Exploit Windows Kernel Loophole with Malicious Driver Signings
Microsoft blocked code signing certificates used by Chinese hackers to sign and load malicious kernel drivers onto systems. These drivers operate at the highest privilege level, enabling undetectable data exfiltration, persistent stealth, and process termination. Exploiting a policy loophole, threat actors altered the signing dates of drivers using tools like "HookSignTool" and "FuckCertVerify." Although Microsoft revoked these certificates and suspended developer accounts, the risk persists as more exposed or stolen certificates may still exist.
Financially Motivated Threat Actor ScarletEel Exploiting AWS for Malicious Activities
Researchers have discovered that financially motivated threat actor ScarletEel is targeting Amazon Web Services (AWS) to perform various malicious activities. ScarletEel demonstrates a deep understanding of AWS tools, allowing it to infiltrate cloud environments easily. The threat actor engages in activities such as stealing credentials and intellectual property, planting crypto mining software, conducting DDoS attacks, and more.
Threat Activity: Data broker / initial-access broker / hacktivist group
- Telegram channel 0x_dump: Posted data relating to Matej Bel University (Slovakia)
- NoName057(16): Conducted DDoS attacks on entities in Lithuania
VULNERABILITIES
- CVE-2022-39280 - dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service.
- CVE-2022-39294 - An attacker could send a malicious request with an abnormally large
Content-Length, which could lead to a panic if memory allocation failed for that request.
EXPLOITS
- CVE-2015-1701 - Microsoft Windows ClientCopyImage Improper Object Handling
- CVE-2013-6282 - Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation
BREACHES
- BreachForums/XSS: Corevin Data Breach (732,512 Records) | Email address and password
- BreachForums/XSS: Belly Ballot Data Breach (665,244 Records) | Email address and password
Tags: DIB, tlp:green