ZeroFox Daily Intelligence Brief - July 17, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 17, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russia-Backed Gamaredon Hackers Steal Data Within an Hour After a Breach
- Dark Web Domain and Infrastructure of Genesis Market Sold
- Tens of Thousands of Public Docker Container Images Expose Secret Keys
- Vulnerabilities: CVE-2023-2156 and CVE-2023-36813
- Breaches: Credit Card Data Breach and BreachForums/Leakforums: Eternity Modern Data Breach
Russia-Backed Gamaredon Hackers Steal Data Within an Hour After a Breach
Ukraine's Computer Emergency Response Team (CERT-UA) has disclosed that Russian state-sponsored cyber-espionage group Gamaredon has been observed stealing data from breached systems in under an hour, operating in rapid attacks. The hackers (also known as Armageddon, UAC-0010, and Shuckworm) deploy over 100 malicious infected files per week on the compromised system to increase the chances of re-infection—even after a disinfection process.
Dark Web Domain and Infrastructure of Genesis Market Sold
Administrators of stolen-credentials marketplace Genesis Market announced that they have sold the forum along with its data to an anonymous buyer, who would take over operations next month. This follows the seizure of the marketplace’s clearnet domains by law enforcement via Operation Cookie Monster. However, the market remained operational despite these actions. The sold package reportedly includes “the store with all the developments,” device fingerprints, cookies, form grabber, saved passwords, and persona details from networked computers.
Tens of Thousands of Public Docker Container Images Expose Secret Keys
Security researchers have published a study revealing that tens of thousands of images on Docker Hub contain confidential information, posing a significant attack risk. The analysis of 337,171 Docker Hub images and registries found that around 8.5% include sensitive data like private keys and API secrets. 95% of the keys and 90% of API secrets were unintentionally leaked from single-user images. The study also discovered compromised certificates and identified hosts relying on the exposed secrets.
Threat Activity: Data broker / initial-access broker / hacktivist group
- Exploit user Elpizozo : Auctioning VPN & RDP Access To Software Company In UAE
- XSS user 2drots:: VPN Access To Unnamed U.S.-Based Transportation Company
VULNERABILITIES
- CVE-2023-2156 - This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
- CVE-2023-36813 - In Kanboard versions prior to 1.2.31, an authenticated user is able to perform SQL Injection, leading to a privilege escalation or loss of confidentiality.
BREACHES
- Credit Card Data Breach: (966c51 | 3479)| Credit Card Data Breach
- BreachForums/Leakforums: Eternity Modern Data Breach: (36,397 Records)| Email address and password
Tags: DIB, tlp:green