ZeroFox Daily Intelligence Brief - August 02, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 02, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA: Threat Actors Exploiting Ivanti EPMM Vulnerabilities
- Iran-based VPS Company Provides C2 Services to Threat Actors
- European Bank Customers Targeted by Aggressive SpyNote Trojan Campaign
- Data broker / initial-access broker / hacktivist group: unkn0wn: New Russian hacktivist group claimed attack on U.S.-based CRM company Perfex and Anonymous Sudan: Threatened Nigerian government with attacks
- Vulnerabilities: CVE-2022-30521 and CVE-2022-34592
- Exploits: CVE-2015-1318 and CVE-2020-24214
- BreachForums/XSS: MyHeritage Data Breach and R2Games Data Breach
CISA: Threat Actors Exploiting Ivanti EPMM Vulnerabilities
U.S. and Norwegian authorities have published a joint advisory on the active exploitation of now-patched Ivanti zero-day bugs amid concerns about widespread attacks on governmental and private sector networks. Advanced persistent threat actors have exploited CVE-2023-35078 as a zero-day vulnerability to gather information and compromise targeted networks, while chaining it with the CVE-2023-35081 vulnerability (which permits actors with administrator privileges to write arbitrary files). Alongside noting IOCs and TTPs, the advisory includes a template to identify unpatched and compromised devices.
Iran-based VPS Company Provides C2 Services to Threat Actors
Researchers have uncovered an Iran-based company named Cloudzy that provides command-and-control (C2) services for various hacking groups, including ransomware operators, spyware vendors, and state-sponsored APT actors. Cloudzy is registered in the United States as a virtual private server (VPS) company but has no physical office and is believed to operate out of Tehran (Iran) in violation of sanctions. The company promotes its services as user anonymisation, does not appear to respond to queries about malware activity, never verifies identities, and allows anonymous crypto-payments.
European Bank Customers Targeted by Aggressive SpyNote Trojan Campaign
Various European bank customers were targeted by the SpyNote Android banking trojan in an aggressive campaign between June and July 2023. The malware, also known as SpyMax, spreads through email phishing and requires accessibility permissions to steal data. A malicious SMS prompts users to install a banking app, leading them to the legitimate TeamViewer QuickSupport app before attackers install the malware. SpyNote collects geolocation, keystrokes, screen recordings, and even bypasses SMS-based two-factor authentication.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- unkn0wn:: New Russian hacktivist group claimed attack on U.S.-based CRM company Perfex
- Anonymous Sudan: Threatened Nigerian government with attacks
VULNERABILITIES
- CVE-2022-30521 - The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions.
- CVE-2022-34592 - Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw.
EXPLOITS
- CVE-2015-1318 - Apport / ABRT chroot Privilege Escalation
- CVE-2020-24214 - HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow
BREACHES
- BreachForums/XSS: MyHeritage Data Breach - (82,996,009 Records) | Email address and password
- BreachForums/XSS: R2Games Data Breach - (7,808,200 Records)| Email address and password
Tags: DIB, tlp:green