Threat Intelligence Bulletin: 07/28/2023 - 08/03/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 07/28/2023 - 08/03/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - August 03, 2023
Brief Highlights
- Hackers Exploit Zero-Day Flaw in Salesforce Email Services to Target Social Media Accounts
- Collide+Power Side-Channel Vulnerability Present in Almost All CPUs
- Ivanti Declares New Critical Bug, Days After CISA Advisory on Exploitation of Two Other Bugs
- Data broker / initial-access broker / hacktivist group: NET - WORKER ALLIANCE and Anonymous Sudan
- Vulnerabilities: CVE-2023-38602 and CVE-2023-4125
- Exploits: CVE-2020-12800 and CVE-2013-5945
- BreachForums: Nerdweb Data Breach and BreachForums: BuyPersonalProxy Data Breach
Report: https://zerofox.com/advisories/21476
ZeroFox Daily Intelligence Brief - August 02, 2023
Brief Highlights
- CISA: Threat Actors Exploiting Ivanti EPMM Vulnerabilities
- Iran-based VPS Company Provides C2 Services to Threat Actors
- European Bank Customers Targeted by Aggressive SpyNote Trojan Campaign
- Data broker / initial-access broker / hacktivist group: unkn0wn: New Russian hacktivist group claimed attack on U.S.-based CRM company Perfex and Anonymous Sudan: Threatened Nigerian government with attacks
- Vulnerabilities: CVE-2022-30521 and CVE-2022-34592
- Exploits: CVE-2015-1318 and CVE-2020-24214
- BreachForums/XSS: MyHeritage Data Breach and R2Games Data Breach
Report: https://zerofox.com/advisories/21462
ZeroFox Daily Intelligence Brief - August 01, 2023
Brief Highlights
- ZeroFox: Brand Protection Trend Report
- Unsecured Canon Inkjet Bug Could Put Users at Risk
- Spear-Phishing Campaign Deploying Android Spyware
- Data broker / initial-access broker / hacktivist group: Killnet and Anonymous Sudan: Claim to have DDoS attacked the London Metal Exchange (LME) and Telegram channel 0x_dump: Posted data from identity management software company Avatier
- Vulnerabilities: CVE-2023-0009 and CVE-2023-20593
- Exploits: CVE-2016-4997 and CVE-2015-3113
- Breaches: Telegram: 'SEGA 2006 @segacloud.rar' and BreachForums/XSS:HauteLook Data Breach
Report: https://zerofox.com/advisories/21456
ZeroFox Daily Intelligence Brief - July 31, 2023
Brief Highlights
- Western Europe: A Regional Assessment by ZeroFox
- CISA Releases Malware Analysis Reports on Remote Execution Vulnerability in Barracuda Email Gateway
- New Android Malware Uses OCR to Steal Data and Cryptocurrency Wallets
- Data broker / initial-access broker / hacktivist group: Exploit: Actor Auctioning RDP Access To Unnamed Australian Boat Dealer and Actor Auctioning RDP Access To U.S.-Based Media & Internet Company
- Vulnerabilities: CVE-2023-3390 and CVE-2023-28130
- Exploits: CVE-2013-3763
- Breaches: Credit Card Data Breach and CafePress Data Breach
Report: https://zerofox.com/advisories/21422
ZeroFox Daily Intelligence Brief - July 28, 2023
Brief Highlights
- Zimbra Patches Zero-Day Exploited in XSS Attacks
- CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse
- U.S. Government Contractor Maximus Discloses Data Breach
- Data broker / initial-access broker / hacktivist group: XSS user Fluxter and XSS user blackh4t
- Vulnerabilities: CVE-2023-38408 and CVE-2023-3984
- Exploits: CVE-2001-1442 and CVE-2007-1785
- Breaches: BreachForums/XSS: Yahoo! Data Breach and BreachForums/XSS: Bitly Data Breach
Report: https://zerofox.com/advisories/21399
Breach Disclosures:
Turkey İş Bankası
An alleged data breach at Turkey İş Bankası – a Turkey-based banking institution – exposed 88,845 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21486
BuyPersonalProxy
An alleged data breach at BuyPersonalProxy – a U.S.-based company that secure private proxies – exposed 25,141 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21485
Nerdweb
An alleged data breach at Nerdweb – a Brazil-based marketing and advertising company – exposed 10,275 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21484
Spasibosberbank
An alleged data breach at Spasibosberbank – a Russia-based site for loyalty program – exposed 3,372,842 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21475
Hostinger International
An alleged data breach at Hostinger International – a Lithuania-based web hosting provider – exposed 311,787 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21474
MyHeritage
An alleged data breach at MyHeritage – an Israel-based online genealogy platform – exposed 82,996,009 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21473
CashCrate
An alleged data breach at CashCrate – a U.S.-based saving and earning club – exposed 5,997,340 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21472
Ecco Perú
An alleged data breach at Ecco Perú – a Peru-based retail site – exposed 6,827 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21453
iMesh
An alleged data breach at iMesh – a U.S.-based software development company – exposed 43,292,802 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21452
MyFitnessPal
An alleged data breach at MyFitnessPal – a U.S.-based nutrition and food tracking app – exposed 49,043,906 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21451
Zing id
An alleged data breach at Zing id – a Vietnam-based website that creates account used for VNG games – exposed 30,900,452 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21450
Lsgb
An alleged data breach at Lsgb – a China-based manufacturer of water pumps and pipeline supporting products – exposed 9,555,466 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21449
Lifeboat
An alleged data breach at Lifeboat – a U.S.-based Minecraft Bedrock server network – exposed 9,293,473 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21448
GFAN
An alleged data breach at GFAN – a China-based social media platform – exposed 10,434,660 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21447
R2Games
An alleged data breach at R2Games – a China-based online game publisher – exposed 7,808,200 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21446
Armor Games
An alleged data breach at Armor Games – a U.S.-based online gaming site – exposed 7,650,455 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21445
HauteLook
An alleged data breach at HauteLook – a U.S.-based shopping website – exposed 6,510,520 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21444
8Tracks
An alleged data breach at 8Tracks – a Canada-based internet radio and social networking website – exposed 5,139,751 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21443
Cross Fire
An alleged data breach at Cross Fire – a Russia-based online game discussion forum – exposed 8,615,281 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21442
CafePress
An alleged data breach at CafePress – a U.S.-based online gift shop – exposed 11,088,831 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21441
Dubsmash
An alleged data breach at Dubsmash – a U.S.-based video sharing social media service application – exposed 12,289,406 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21440
Animoto_Additional Dataset
An alleged data breach at Animoto – a U.S.-based online video maker site – exposed 13,372,208 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21439
Mate1
An alleged data breach at Mate1 now edate – a Canada-based online dating website – exposed 27,397,825 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21438
Shein
An alleged data breach at Shein – a China-based apparel and accessories retail company – exposed 27,933,693 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21437
Chegg
An alleged data breach at Chegg – a U.S.-based education technology company – exposed 29,306,354 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21436
Tunngle
An alleged data breach at Tunngle – a Germany-based VPN tool – exposed 5,308,543 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21435
EyeEm
An alleged data breach at EyeEm – a Germany-based photography community and marketplace – exposed 3,810,558 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21418
Parapa
An alleged data breach at Parapa – a Russia-based online game site – exposed 4,463,898 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21417
Toondoo
An alleged data breach at Toondoo – a U.S.-based web-based tool that enables users to create a comic strip – exposed 4,229,240 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21416
Estante Virtual
An alleged data breach at Estante Virtual – a Brazil-based leading book marketplace – exposed 4,395,589 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21415
ixigo
An alleged data breach at ixigo – an India-based tour planning and travel website – exposed 4,307,420 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21414
Nexus Mods
An alleged data breach at Nexus Mods – a U.K.-based site which allows users to upload and download "mods" (modifications) for computer games – exposed 4,847,422 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21413
Bitly
An alleged data breach at Bitly – a U.S.-based URL shortening service and a link management platform – exposed 4,693,622 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21412
PM Simplify
An alleged data breach at PM Simplify – a U.S.-based company that provides project management professional trainings – exposed 8,629 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21411
Breaking News:
Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures
A Russia-nexus adversary has been linked to 94 new domains starting March 2023, suggesting that the group is actively modifying its infrastructure in response to public disclosures about its activities. Cybersecurity fresearchers linked the revamped infrastructure to a threat actor it tracks under the name BlueCharlie, a hacking crew that's broadly known by the names Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446.
See the full report here: https://thehackernews.com/2023/08/russian-cyber-adversary-bluecharlie.html
Hackers exploited Salesforce zero-day in Facebook phishing attack
Hackers exploited a zero-day vulnerability in Salesforce's email services and SMTP servers to launch a sophisticated phishing campaign targeting valuable Facebook accounts. The attackers chained a flaw dubbed "PhishForce," to bypass Salesforce's sender verification safeguards and quirks in Facebook's web games platform to mass-send phishing emails.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-exploited-salesforce-zero-day-in-facebook-phishing-attack/
Amazon's AWS SSM agent can be used as post-exploitation RAT malware
Researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows hackers to use the platform's System Manager (SSM) agent as an undetectable Remote Access Trojan (RAT). The attack concept impacts both Windows and Linux machines and is preferable to using common malware and backdoors as its abuse will less likely be detected by security software.
See the full report here: https://www.bleepingcomputer.com/news/security/amazons-aws-ssm-agent-can-be-used-as-post-exploitation-rat-malware/
New Collide+Power side-channel attack impacts almost all CPUs
A new software-based power side-channel attack called "Collide+Power" was discovered, impacting almost all CPUs and potentially allowing data to leak. However, the researchers advised that the flaw is low-risk and will likely not be used in attacks on end users.
See the full report here: https://www.bleepingcomputer.com/news/security/new-collide-pluspower-side-channel-attack-impacts-almost-all-cpus/
Over 640 Citrix servers backdoored with web shells in ongoing attacks
Hundreds of Citrix Netscaler ADC and Gateway servers have already been breached and backdoored in a series of attacks targeting a critical remote code execution (RCE) vulnerability tracked as CVE-2023-3519. The vulnerability was previously exploited as a zero-day to breach the network of a U.S. critical infrastructure organization.
See the full report here: https://www.bleepingcomputer.com/news/security/over-640-citrix-servers-backdoored-with-web-shells-in-ongoing-attacks/
Russian hackers target govt orgs in Microsoft Teams phishing attacks
Microsoft says a hacking group tracked as APT29 and linked to Russia's Foreign Intelligence Service (SVR) targeted dozens of organizations worldwide, including government agencies, in Microsoft Teams phishing attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/russian-hackers-target-govt-orgs-in-microsoft-teams-phishing-attacks/
Fake FlipperZero sites promise free devices after completing offer
A site impersonating Flipper Devices promises a free Flipper Zero after completing an offer but only leads to shady browser extensions and scam sites. Flipper Zero is a portable multi-functional cybersecurity tool for pen-testers and hacking enthusiasts.
See the full report here: https://www.bleepingcomputer.com/news/security/fake-flipperzero-sites-promise-free-devices-after-completing-offer/
Retail chain Hot Topic discloses wave of credential-stuffing attacks
American apparel retailer Hot Topic is notifying customers about multiple cyberattacks between February 7 and June 21 2023 that resulted in exposing sensitive information to hackers. Hot Topic is a retail chain specialized in counter-culture clothing and accessories, and licensed music, that has 675 stores across the U.S. In a data breach notification, the company explained that hackers used stolen account credentials and accessed the Rewards platform multiple times, potentially stealing customer data, too.
See the full report here: https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/
Threat actors abuse Google AMP for evasive phishing attacks
Security researchers are warning of increased phishing activity that abuses Google Accelerated Mobile Pages (AMP) to bypass email security measures and get to inboxes of enterprise employees. AMP pages are hosted on Google’s servers, where content is simplified and some of the heavier media elements are pre-loaded for faster delivery.
See the full report here: https://www.bleepingcomputer.com/news/security/threat-actors-abuse-google-amp-for-evasive-phishing-attacks/
Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan
Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer, and spyware referred to as Ursnif (aka Gozi). The malware uses multiple mechanisms to evade detection and was likely developed to be rented out to select cybercriminal threat actors. WikiLoader is so named due to the malware making a request to Wikipedia and checking that the response has the string "The Free."
See the full report here: https://thehackernews.com/2023/08/cybercriminals-renting-wikiloader-to.html
China's APT31 Suspected in Attacks on Air-Gapped Systems in Eastern Europe
A nation-state actor with links to China is suspected of being behind a series of attacks against industrial organizations in Eastern Europe that took place last year to siphon data stored on air-gapped systems. Researchers attributed the intrusions with medium to high confidence to a hacking crew called APT31, which is also tracked under the monikers Bronze Vinewood, Judgement Panda, and Violet Typhoon (formerly Zirconium), citing commonalities in the tactics observed.
See the full report here: https://thehackernews.com/2023/08/chinas-apt31-suspected-in-attacks-on.html
Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia
The threat actor known as Space Pirates has been linked to attacks against at least 16 organizations in Russia and Serbia over the past year by employing novel tactics and adding new cyber weapons to its arsenal. The cybercriminals' main goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks,.
See the full report here: https://thehackernews.com/2023/08/researchers-expose-space-pirate-cyber.html
European Bank Customers Targeted in SpyNote Android Trojan Campaign
Various European customers of different banks are being targeted by an Android banking trojan called SpyNote as part of an aggressive campaign detected in June and July 2023. The spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack.
See the full report here: https://thehackernews.com/2023/08/european-bank-customers-targeted-in.html
New NodeStealer Variant Targeting Facebook Business Accounts and Crypto Wallets
Cybersecurity researchers have unearthed a Python variant of a stealer malware NodeStealer that's equipped to fully take over Facebook business accounts as well as siphon cryptocurrency. NodeStealer was first observed in May 2023,as a stealer capable of harvesting cookies and passwords from web browsers to compromise Facebook, Gmail, and Outlook accounts. While the prior samples were written in JavaScript, the latest versions are coded in Python.
See the full report here: https://thehackernews.com/2023/08/new-nodestealer-targeting-facebook.html
Norwegian Entities Targeted in Ongoing Attacks Exploiting Ivanti EPMM Vulnerability
Advanced persistent threat (APT) actors exploited a recently disclosed critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) as a zero-day since at least April 2023 in attacks directed against Norwegian entities, including a government network. The disclosure comes as part of a new joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian National Cyber Security Centre (NCSC-NO).
See the full report here: https://thehackernews.com/2023/08/norwegian-entities-targeted-in-ongoing.html
Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers
Services offered by an obscure Iranian company known as Cloudzy are being leveraged by multiple threat actors, including cybercrime groups and nation-state crews. Although Cloudzy is incorporated in the United States, it operates out of Tehran, Iran in possible violation of U.S. sanctions. The company acts as a command-and-control provider (C2P), which provides attackers with Remote Desktop Protocol (RDP) virtual private servers and other anonymized services that hackers utilize.
See the full report here: https://thehackernews.com/2023/08/iranian-company-cloudzy-accused-of.html
Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor
Threat actors associated with the hacking crew known as Patchwork have been spotted targeting universities and research organizations in China as part of a recently observed campaign. The activity entailed the use of a backdoor codenamed EyeShell. Active since at least December 2015, attack chains mounted by the outfit have a narrow focus and tend to single out Pakistan and China with custom implants such as BADNEWS via spear-phishing and watering hole attacks.
See the full report here: https://thehackernews.com/2023/07/patchwork-hackers-target-chinese.html
Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan
Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer, and spyware called Ursnif (aka Gozi). t is a sophisticated downloader with the objective of installing a second malware payload. The malware uses multiple mechanisms to evade detection and was likely developed as a malware that can be rented out to select cybercriminal threat actors.
See the full report here: https://thehackernews.com/2023/08/cybercriminals-renting-wikiloader-to.html
P2PInfect server botnet spreads using Redis replication feature
Threat actors are actively targeting exposed instances of SSH and Redis Redis open-source data store with a peer-to-peer self-replicating worm with versions for both Windows and Linux that the malware authors named P2Pinfect. Written in Rust, the malware relies on at least two methods to establish foothold: a critical vulnerability disclosed and patched in 2022, and a feature that allows replicating the main database for high availability and to counter failover scenarios.
See the full report here: https://www.bleepingcomputer.com/news/security/p2pinfect-server-botnet-spreads-using-redis-replication-feature/
Canon warns of Wi-Fi security risks when discarding inkjet printers
Canon is warning users of home, office, and large format inkjet printers that their Wi-Fi connection settings stored in the devices' memories are not wiped, as they should, during initialization, allowing others to gain access to the data. This flaw could introduce a security and privacy risk for impacted users if the printer memory is extracted by repair technicians, temporary users, or future buyers of the devices, allowing them to get the connection details for your Wi-FI network.
See the full report here: https://www.bleepingcomputer.com/news/security/canon-warns-of-wi-fi-security-risks-when-discarding-inkjet-printers/
Hackers steal Signal, WhatsApp user data with fake Android chat app
Hackers are using a fake Android app named "SafeChat" to infect devices with spyware malware that steals call logs, texts, and GPS locations from phones. The Android spyware is suspected to be a variant of "Coverlm," which steals data from communication apps such as Telegram, Signal, WhatsApp, Viber, and Facebook Messenger.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-steal-signal-whatsapp-user-data-with-fake-android-chat-app/
Hawaii Community College pays ransomware gang to prevent data leak
The Hawaii Community College has admitted that it paid a ransom to ransomware actors to prevent the leaking of stolen data of approximately 28,000 people. Hawaiʻi Community College is an accredited public community college operating two campuses on the island of Hawaii and is part of the University of Hawai'i (UH), which has over 50,000 students. On June 19, 2023, the relatively new NoEscape ransomware gang listed UH on its extortion portal, threatening to publish 65 GB of stolen data in a week if a ransom was not paid.
See the full report here: https://www.bleepingcomputer.com/news/security/hawaii-community-college-pays-ransomware-gang-to-prevent-data-leak/
Israel's largest oil refinery website offline after DDoS attack
The website of Israel's largest oil refinery operator, BAZAN Group is inaccessible from most parts of the world as threat actors claim to have hacked the Group's cyber systems. The company has a total oil refining capacity of about 9.8 million tons of crude oil per year.
See the full report here: https://www.bleepingcomputer.com/news/security/israels-largest-oil-refinery-website-offline-after-ddos-attack/
Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required
Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the discovery of an "extremely severe" flaw that could result in pre-authenticated remote code execution on affected installations. Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1.
See the full report here: https://thehackernews.com/2023/07/major-security-flaw-discovered-in.html
BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities
The Russian nation-state actor known as BlueBravo has been observed targeting diplomatic entities throughout Eastern Europe with the goal of delivering a new backdoor called GraphicalProton, exemplifying the continuous evolution of the threat. The phishing campaign is characterized by the use of legitimate internet services (LIS) for command-and-control (C2) obfuscation. The activity was observed between March and May 2023.
See the full report here: https://thehackernews.com/2023/07/bluebravo-deploys-graphicalproton.html
Hackers Abusing Windows Search Feature to Install Remote Access Trojans
A legitimate Windows search feature is being exploited by unknown malicious actors to download arbitrary payloads from remote servers and compromise targeted systems with remote access trojans such as AsyncRAT and Remcos RAT. The novel attack technique takes advantage of the "search-ms:" URI protocol handler, which offers the ability for applications and HTML links to launch custom local searches on a device, and the "search:" application protocol, a mechanism for calling the desktop search application on Windows.
See the full report here: https://thehackernews.com/2023/07/hackers-abusing-windows-search-feature.html
STARK#MULE Targets Koreans with U.S. Military-themed Document Lures
An ongoing cyber attack campaign has set its sights on Korean-speaking individuals by employing U.S. Military-themed document lures to trick them into running malware on compromised systems. The scale of the attacks is currently not known, and it's not clear if any of these attack attempts turned out to be successful.
See the full report here: https://thehackernews.com/2023/07/starkmule-targets-koreans-with-us.html
IcedID Malware Adapts and Expands Threat with Updated BackConnect Module
The threat actors linked to the malware loader known as IcedID have made updates to the BackConnect (BC) module that's used for post-compromise activity on hacked systems.
See the full report here: https://thehackernews.com/2023/07/icedid-malware-adapts-and-expands.html
Hackers Deploy "SUBMARINE" Backdoor in Barracuda Email Security Gateway Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) disclosed details of a "novel persistent backdoor" called SUBMARINE deployed by threat actors in connection with the hack on Barracuda Email Security Gateway (ESG) appliances. SUBMARINE comprises multiple artifacts including a SQL trigger, shell scripts, and a loaded library for a Linux daemon that together enable execution with root privileges, persistence, command and control, and cleanup.
See the full report here: https://thehackernews.com/2023/07/hackers-deploy-submarine-backdoor-in.html
New Android Malware CherryBlos Utilizing OCR to Steal Sensitive Data
A new Android malware strain called CherryBlos has been observed making use of optical character recognition (OCR) techniques to gather sensitive data stored in pictures. CherryBlos is distributed via bogus posts on social media platforms and comes with capabilities to steal cryptocurrency wallet-related credentials.
See the full report here: https://thehackernews.com/2023/07/new-android-malware-cherryblos.html
Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable
Multiple security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by threat actors to escalate privileges and steal sensitive data. The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, impact versions 3.6.25 and below. Ninja Forms is installed on over 800,000 sites.
See the full report here: https://thehackernews.com/2023/07/multiple-flaws-found-in-ninja-forms.html
Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT
Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT. Among the software in question are various instruments for fine-tuning CPUs, graphic cards, and BIOS; PC hardware-monitoring tools; and some other apps.
See the full report here: https://thehackernews.com/2023/07/fruity-trojan-uses-deceptive-software.html
AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service
Details have emerged about a botnet called AVRecon, which has been observed making use of compromised small office/home office (SOHO) routers as part of a multi-year campaign active since at least May 2021. The malware has been used to create residential proxy services to shroud malicious activity such as password spraying, web-traffic proxying, and ad fraud.
See the full report here: https://thehackernews.com/2023/07/avrecon-botnet-leveraging-compromised.html
Swiss visa appointments cancelled in UK due to "IT incident"
All appointments for Swiss (Schengen) tourist and transit visas have been cancelled across the UK. TLScontact, the Swiss government's chosen IT provider for facilitating visa applicants for citizens of third countries, has blamed an "IT incident" at its London, Manchester, and Edinburgh centers for appointment cancellations.
See the full report here: https://www.bleepingcomputer.com/news/security/swiss-visa-appointments-cancelled-in-uk-due-to-it-incident/
SSNDOB cybercrime market admin faces 15 years after pleading guilty
A Ukrainian man has pleaded guilty in the United States to conspiracy to commit access device fraud and trafficking in unauthorized access devices through the now-shutdown SSNDOB Marketplace. The man was the administrator of the SSNDOB Marketplace, a series of websites that sold sensitive personal information of people in the United States, including their full names, dates of birth, and Social Security Numbers (SSNs).
See the full report here: https://www.bleepingcomputer.com/news/security/ssndob-cybercrime-market-admin-faces-15-years-after-pleading-guilty/
BreachForums database and private chats for sale in hacker data breach
In November 2022, the well-known hacking forum "BreachForums" was itself breached. The operator of the website was arrested and the site seized by law enforcement agencies. The breach exposed 212,000 records including usernames, IP and email addresses, private messages between site members and passwords stored as argon2 hashes. The Breached database is currently being sold by a threat actor going by the name "breached_db_person."
See the full report here: https://www.bleepingcomputer.com/news/security/breachforums-database-and-private-chats-for-sale-in-hacker-data-breach/
WordPress Ninja Forms plugin flaw lets hackers steal submitted data
Popular WordPress form-building plugin Ninja Forms contains three vulnerabilities that could allow attackers to achieve privilege escalation and steal user data. Researchers discovered and disclosed the three vulnerabilities to the plugin's developer, Saturday Drive, on June 22nd, 2023, warning that it affects NinjaForms versions 3.6.25 and older.
See the full report here: https://www.bleepingcomputer.com/news/security/wordpress-ninja-forms-plugin-flaw-lets-hackers-steal-submitted-data/
Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining
Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners. Researchers detected more than 800 attacks against its Tomcat server honeypots over a two-year time period, with 96% of the attacks linked to the Mirai botnet. Of these attack attempts, 20% (or 152) entailed the use of a web shell script dubbed "neww" that originated from 24 unique IP addresses, with 68% of them originating from a single IP address (104.248.157[.]218).
See the full report here: https://thehackernews.com/2023/07/hackers-target-apache-tomcat-servers.html
New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads
A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks.
See the full report here: https://thehackernews.com/2023/07/new-malvertising-campaign-distributing.html
Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required
Users of Metabase, a popular business intelligence and data visualization software package, are advised to update to the latest version following the discovery of an "extremely severe" flaw that could result in pre-authenticated remote code execution on affected installations. Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1.
See the full report here: https://thehackernews.com/2023/07/major-security-flaw-discovered-in.html
Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners. Of these attack attempts, 20% (or 152) entailed the use of a web shell script dubbed "neww" that originated from 24 unique IP addresses, with 68% of them originating from a single IP address (104.248.157[.]218).
See the full report here: https://thehackernews.com/2023/07/hackers-target-apache-tomcat-servers.html
US, Australia cyber agencies warn IDOR security flaws can be exploited "at scale"
U.S. and Australian government cybersecurity agencies are warning that common and easily exploitable security vulnerabilities in websites and web apps can be abused to carry out large-scale data breaches.
See the full report here: https://techcrunch.com/2023/07/27/cisa-nsa-australia-idor-flaws/
CardioComm, a provider of ECG monitoring devices, confirms cyberattack downed its services
CardioComm Solutions, a Canadian provider of consumer and professional-grade heart monitoring technologies, has been downed by an ongoing cybersecurity incident. The Toronto-based organization that its business operations will be “impacted for several days and potentially longer” following a “cybersecurity incident on the Company’s servers.”
See the full report here: https://techcrunch.com/2023/07/26/cardiocomm-ecg-monitoring-cyberattack/
ZeroFox Intelligence Reports:
ZeroFox Intelligence Brief - Brand Protection Trend Report
In this Intelligence Brief, ZeroFox researchers examine threats to brands and recent trends that have been most impactful, as protecting an organization’s brand has never been more crucial as external cybersecurity threats toward brands continue to increase significantly.
Report: https://zerofox.com/advisories/21455
ZeroFox Intelligence Geopolitical Brief for August 2023
In this ZeroFox Intelligence Geopolitical Brief for August 2023, ZeroFox researchers cover the myriad security challenges in Africa, and how they pose a threat to global security are discussed in detail. Developments in Russia's economic and military targeting of Ukraine are covered, as are important upcoming elections in Europe and Latin America. In Asia, the potential for instability in Thailand is the primary issue, while the Middle East section focuses on judicial reform in Israel, which risks physical security and international investment.
Report: https://zerofox.com/advisories/21421
ZeroFox Intelligence - Western Europe Regional Assessment
In this regional assessment, ZeroFox researchers establish the key geopolitical and security risks facing Western Europe and provide forward-looking statements on how these will likely impact the region in the coming months.
Report: https://zerofox.com/advisories/21420
Tags: tlp:clear, all industries, global, weekly bulletin