zerofox logo
Advisories

Threat Intelligence Bulletin: 08/04/2023 - 08/10/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 08/04/2023 - 08/10/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - August 10, 2023

Brief Highlights

  • Ukraine Issues Alert on Hackers Employing “Merlin” Framework on State-Attacks
  • China-Linked Hackers Targeted 17 Countries in Cross-Continental Campaign
  • Security-Evading EvilProxy Phishing Campaign Targets 120,000 Microsoft 365 Users
  • Data broker / initial-access broker / hacktivist group: BreachForums user “Black” and ACEH ABOUT HACKED WORLD
  • Vulnerabilities: CVE-2023-38348 and CVE-2023-39006
  • Breaches: Combolist: '636K FRANCE Combolist Email' and 248K_Germany_ComboList_Hq

Report: https://zerofox.com/advisories/21530


ZeroFox Daily Intelligence Brief - August 9, 2023

Brief Highlights

  • Joint Law-Enforcement Operation Shuts Down Notorious Phishing Platform “16shop”
  • U.K. Electoral Commission Discloses Data Breach
  • Intel Provides Mitigation for New Downfall Attacks that Can Steal Steal Encryption Keys from CPUs
  • Data broker / initial-access broker / hacktivist group: Killmilk and Anonymous Sudan
  • Vulnerabilities: CVE-2023-22403 and CVE-2023-36213
  • Breaches: XSS/Leakbase: Federal Direct Access Expositions Data Breach and BreachForums: Gameshop Twente Data Breach

Report: https://zerofox.com/advisories/21521


ZeroFox Daily Intelligence Brief - August 08, 2023

Brief Highlights

  • HC3 Sounds Alarm About Rhysida Ransomware Group
  • North Korean Hackers Breach Top Russian Missile Maker
  • Malicious OpenBullet Configs Used To Target Inexperienced Cybercriminals
  • Data broker / initial-access broker / hacktivist group: NET - WORKER ALLIANCE: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach
  • Vulnerabilities: CVE-2023-39530 and CVE-2023-38956
  • BreachForums: BreachForums/XSS: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach

Report: https://zerofox.com/advisories/21511


ZeroFox Daily Intelligence Brief - August 07, 2023

Brief Highlights

  • Beware of Criminals Posing as Non-Fungible Token (NFT) Developers
  • New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy
  • Colorado Department of Higher Education (CDHE) Hit by Massive Data Breach
  • Data broker / initial-access broker / hacktivist group: Telegram channel NEFARIAN EMPIRE and Pro-Russia group Killnet
  • Vulnerabilities: CVE-2023-20817 and CVE-2023-20800
  • BreachForums: Vietanamobile Data Breach and BreachForums: İstanbul Büyükşehir Belediyesi

Report: https://zerofox.com/advisories/21501


ZeroFox Daily Intelligence Brief - August 04, 2023

Brief Highlights

  • Five Eyes Authorities Release Joint Report on Top Exploited Vulnerabilities of 2022
  • 1.7 TB of Leaked Mondee Database Exposes Sensitive Customer Information
  • Serco Inc. Discloses Data Breach of 10,000 Individuals' Personal Information from Third-Party Vendor's Server
  • Data broker / initial-access broker / hacktivist group: Exploit user “proper12” and Exploit user “sandocan”:
  • Vulnerabilities: CVE-2023-36053 and CVE-2023-4056
  • Exploits: CVE-2020-12800
  • BreachForums: Turkey İş Bankası Data Breach and Credit Card Data Breach

Report: https://zerofox.com/advisories/21487


Breach Disclosures:


Federal Direct Access Expositions

An alleged data breach at Federal Direct Access Expositions – a U.S.-based technology exposition provider – exposed 7,672 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21520


Gameshop Twente

An alleged data breach at Gameshop Twente – a Netherland-based game and toy seller – exposed 8,082 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21519


Vietanamobile

An alleged data breach at Vietanamobile – a Vietnam-based mobile network operator – exposed 74,272 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21490


İstanbul Büyükşehir Belediyesi

An alleged data breach at İstanbul Büyükşehir Belediyesi – a Turkey-based metropolitan municipality – exposed 3,020 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21489


Breaking News:


Rhysida ransomware behind recent attacks on healthcare

The emerging ransomware group "Rhysdia" has targeted healthcare organizations in a wave of attacks. A bulletin published by the U.S. Department of Health and Human Services (HHS) warned that while Rhysida still uses an elementary locker, the scale of its activities has grown to dangerous proportions, and recently, the threat actors demonstrated a focus on the healthcare and public sector

See the full report here: https://www.bleepingcomputer.com/news/security/rhysida-ransomware-behind-recent-attacks-on-healthcare/


Missouri warns that health info was stolen in IBM MOVEit data breach

Missouri's Department of Social Services warns that protected Medicaid healthcare information was exposed in a data breach after IBM suffered a MOVEit data theft attack.

See the full report here: https://www.bleepingcomputer.com/news/security/missouri-warns-that-health-info-was-stolen-in-ibm-moveit-data-breach/


Windows Defender-Pretender Attack Dismantles Flagship Microsoft EDR

Researchers uncovered an issue with Windows Defender during an attempt take over the antivirus tool's update process.The research goal was to verify if the update process could be used to sneak known malware into systems while also checking if they could get Windows Defender to delete signatures of known threats and worse, to delete benign files and trigger a denial-of-service condition on a compromised system.The researchers were able to achieve all three objectives and even develop an automated tool dubbed wd-pretender for the attacks.

See the full report here: https://www.darkreading.com/attacks-breaches/-researchers-detail-vuln-that-allowed-for-windows-defender-update-process-hijack


CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a zero-day flaw affecting Microsoft’s .NET and Visual Studio products to its Known Exploited Vulnerabilities Catalog. CVE-2023-38180 can be exploited for denial-of-service (DoS) attacks, and Microsoft noted in its advisory that it’s aware of malicious exploitation. No details are available on the attacks leveraging the vulnerability but it is known to not require additional privileges or user interactions.

See the full report here: https://www.securityweek.com/cisa-warns-organizations-of-exploited-vulnerability-in-net-visual-studio/


MoustachedBouncer' APT Spies on Embassies, Likely via ISPs

A Belarus-linked APT spied on staff in at least four embassies operating in the country, likely by leveraging the country's local Internet service provider (ISP).

See the full report here: https://www.darkreading.com/attacks-breaches/moustached-bouncer-apt-spied-embassies-belarus


Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

Ukraine is warning of a wave of attacks targeting state organizations using "Merlin," an open-source post-exploitation and command and control framework. It is spread through emails and once the malicious executable is run on the victims system, their computer gets infected by MerlinAgent, giving the threat actors access to their machine, data, and a foothold to move laterally in the network.

See the full report here: https://thehackernews.com/2023/08/cybercriminals-increasingly-using.html


INTERPOL shutters "16shop" phishing platform

The international police co-operation org revealed that a research project investigating cyber threats in the ten-nation Association of Southeast Asian Nations (ASEAN) bloc detected the existence of 16shop, which it characterized as a vendor of "phishing kits" sold to cyber crims.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/09/interpol_16shop_phishing_shutdown/


Microsoft Visual Studio Code flaw lets extensions steal passwords

Microsoft's Visual Studio Code (VS Code) code editor and development environment contains a flaw that allows malicious extensions to retrieve authentication tokens stored in Windows, Linux, and macOS credential managers. The security problem is caused by a lack of isolation of authentication tokens in VS Code's "Secret Storage," an API that allows extensions to store authentication tokens in the operating system.

See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-visual-studio-code-flaw-lets-extensions-steal-passwords/


LockBit threatens to leak medical data of cancer patients stolen from Varian Medical Systems

The LockBit ransomware group threatens to leak medical data of cancer patients stolen from Varian Medical Systems. The LockBit ransomware group claims to have hacked the healthcare company Varian Medical Systems and threatens to leak the medical data of cancer patients.

See the full report here: https://securityaffairs.com/149307/cyber-crime/varian-medical-systems-lockbit-ransomware.html


Malicious Campaigns Exploit Weak Kubernetes Clusters for Crypto Mining

From a collection of Kubernetes clusters belonging to more than 350 organizations, open-source projects, and individuals. 60% of them were discovered to be the target of an active crypto-mining campaign. Found among the exposed K8s clusters are pods lists containing sensitive environment variables and access keys that could be exploited by bad actors to burrow deep into the target environment, access source code repositories, and worse, introduce malicious modifications if possible.

See the full report here: https://thehackernews.com/2023/08/malicious-campaigns-exploit-weak.html


SAP Patches Critical Vulnerability in PowerDesigner Product

German software giant SAP has fixed more than a dozen new vulnerabilities with its August 2023 Patch Tuesday updates, including a critical flaw affecting the company’s PowerDesigner data modeling and enterprise architecture product. The critical (HotNews) PowerDesigner flaw, tracked as CVE-2023-37483, is an improper access control issue that can be exploited by an unauthenticated attacker to run arbitrary queries against the backend database.

See the full report here: https://www.securityweek.com/sap-patches-critical-vulnerability-in-powerdesigner-product/


New Report Exposes Vice Society's Collaboration with Rhysida Ransomware

Tactical similarities have been unearthed between the double extortion ransomware group known as Rhysida and Vice Society, including in their targeting of education and healthcare sectors. First observed in May 2023, the Rhysida ransomware group is known to rely on phishing attacks and Cobalt Strike to breach targets' networks and deploy their payloads.

See the full report here: https://thehackernews.com/2023/08/new-report-exposes-vice-societys.html


U.K. Electoral Commission Breach Exposes Voter Data of 40 Million Britons

The U.K. Electoral Commission disclosed a cyber attack on its systems that went undetected for over a year, allowing the threat actors to access years worth of voter data belonging to 40 million people.The intrusion enabled unauthorized access to the Commission's servers hosting email, control systems, and copies of the electoral registers it maintains for research purposes.

See the full report here: https://thehackernews.com/2023/08/uk-electoral-commission-breach-exposes.html


Tesla infotainment jailbreak unlocks paid features and secrets

Researchers from the Technical University of Berlin have developed a method to jailbreak the AMD-based infotainment systems used in all recent Tesla car models and make it run any software they choose. Additionally, the hack allows the researchers to extract the unique hardware-bound RSA key that Tesla uses for car authentication in its service network, as well as voltage glitching to activate software-locked features such as seat heating and "Acceleration Boost" that Tesla car owners normally have to pay for.

See the full report here: https://www.bleepingcomputer.com/news/security/tesla-infotainment-jailbreak-unlocks-paid-features-extracts-secrets/


New SkidMap Malware Attacking Wide Range of Linux Distributions

According to recent reports, there have been instances of threat actors using malware called “SkidMap” to exploit vulnerable Redis systems. Earlier versions of SkidMap were used to surreptitiously mine cryptocurrency and create false network traffic and CPU usage by loading malicious kernel modules. However, this malware’s recent version seems quite sophisticated and targets only open Redis instances.

See the full report here: https://gbhackers.com/skidmap-malware-attacking-linux-distributions/


Nigerian Man Admits to USD 1.3M Business Email Compromise Scam

A Nigerian national pleaded guilty to participating in a business email compromise scheme that stole USD 1.25 million from a Boston investment firm. The perpetrator pleaded guilty to one count of wire fraud, which carries a maximum sentence of 20 years' imprisonment and a USD 250,000 fine.

See the full report here: https://www.bankinfosecurity.com/nigerian-man-admits-to-13m-business-email-compromise-scam-a-22751


China reportedly hacked sensitive Japanese defense networks

Japan’s defense chief that Tokyo has not confirmed that top secret information was leaked, after a U.S. media report said China had hacked the country’s classified defense networks. The hacking of Japan’s "most sensitive computer systems" — the Defense Ministry’s classified defense networks — was uncovered in the fall of 2020 according to former senior U.S. officials. It quoted the officials as saying that the hackers “had deep, persistent access and appeared to be after anything they could get their hands on — plans, capabilities, assessments of military shortcomings.”

See the full report here: https://www.japantimes.co.jp/news/2023/08/08/japan/japan-china-hack-defense-network/#:~:text=Japan's%20defense%20chief%20said%20Tuesday,the%20country's%20classified%20defense%20networks.


Severe Cyberattack Forces Hospitals Offline, FBI Involved

Dozens of hospitals across the US have shut down emergency rooms and suspended services due to a ransomware attack on the facilities’ parent company, Prospect Medical Holdings (PMH), and the FBI is involved. The company said in a statement that it took its systems offline to protect them and launched an investigation with the help of third-party cybersecurity specialists. It also said it was focused on addressing the pressing needs of its patients and restoring normal operations as soon as possible.

See the full report here: https://i-hls.com/archives/120288


New Yashma Ransomware Variant Targets Multiple English-Speaking Countries

An unknown threat actor is using a variant of the Yashma ransomware to target various entities in English-speaking countries, Bulgaria, China, and Vietnam at least since June 4, 2023. The threat actor uses an uncommon technique to deliver the ransom note. Instead of embedding the ransom note strings in the binary, they download the ransom note from the actor-controlled GitHub repository by executing an embedded batch file.

See the full report here: https://thehackernews.com/2023/08/new-yashma-ransomware-variant-targets.html


North Korean Hackers Compromise Russian Missile Maker

Security researchers have discovered a likely North Korean cyber-espionage campaign targeting the IT network of a Russian manufacturer of intercontinental ballistic missiles and aerospace equipment. Leaked emails from NPO Mashinostroyeniya, which is sanctioned by the US for its role in Russia’s invasion of Ukraine, helped researchers work out what had happened.

See the full report here: https://www.infosecurity-magazine.com/news/north-korean-hackers-russian/


Spyware maker LetMeSpy shuts down after hacker deletes server data

Poland-based spyware LetMeSpy is no longer operational and said it will shut down after a June 2023 data breach wiped out its servers, including its huge trove of data stolen from thousands of victims’ phones. In a notice on its website LetMeSpy confirmed the “permanent shutdown” of the spyware service and that it would cease operations by the end of August 2023. The notice said LetMeSpy is blocking users from logging in or signing up with new accounts.

See the full report here: https://techcrunch.com/2023/08/05/letmespy-spyware-shuts-down-wiped-server/


Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems

Threat actors are using an open-source rootkit called Reptile to target Linux systems in South Korea. Unlike other rootkit malware that typically only provide concealment capabilities, Reptile goes a step further by offering a reverse shell, allowing threat actors to easily take control of systems.

See the full report here: https://thehackernews.com/2023/08/reptile-rootkit-advanced-linux-malware.html


Fake VMware vConnector package on PyPI targets IT pros

A malicious package that mimics the VMware vSphere connector module "vConnector" was uploaded on the Python Package Index (PyPI) under the name "VMConnect," targeting IT professionals. The malicious package uploaded onto PyPI on July 28, 2023, gathered 237 downloads until its removal on August 1, 2023. An investigation revealed two more packages with identical code as ‘VMConnect,’ namely ‘ethter’ and ‘quantiumbase,’ downloaded 253 and 216 times, respectively.

See the full report here: https://www.bleepingcomputer.com/news/security/fake-vmware-vconnector-package-on-pypi-targets-it-pros/


FBI warns of scammers posing as NFT devs to steal your crypto

The FBI warned of fraudsters posing as Non-Fungible Token (NFT) developers to prey upon NFT enthusiasts and steal their cryptocurrency and NFT assets. In these attacks, the criminals gain unauthorized access to NFT developer social media accounts or create nearly identical accounts to promote "exclusive" NFT releases.

See the full report here: https://www.bleepingcomputer.com/news/security/fbi-warns-of-scammers-posing-as-nft-devs-to-steal-your-crypto/


New PaperCut critical bug exposes unpatched servers to RCE attacks

PaperCut recently fixed a critical security vulnerability in its NG/MF print management software that allows unauthenticated attackers to gain remote code execution on unpatched Windows servers. Tracked as CVE-2023-39143, the flaw results from a chain of two path traversal weaknesses discovered by security researchers that enabled threat actors to read, delete, and upload arbitrary files on compromised systems following low-complexity attacks that don't require user interaction.

See the full report here: https://www.bleepingcomputer.com/news/security/new-papercut-critical-bug-exposes-unpatched-servers-to-rce-attacks/


Microsoft fixes flaw in Power Platform

Microsoft fixed a security flaw in the Power Platform Custom Connectors feature that let unauthenticated attackers access cross-tenant applications and Azure customers' sensitive data. The root cause of the issue stemmed from inadequate access control measures for Azure Function hosts launched by connectors within the Power Platform.

See the full report here: https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-flaw-after-being-called-irresponsible-by-tenable-ceo/


New acoustic attack steals data from keystrokes with 95% accuracy

A team of researchers from British universities have trained a deep learning model that can steal data from keyboard keystrokes recorded using a microphone with an accuracy of 95%. When Zoom was used for training the sound classification algorithm, the prediction accuracy dropped to 93%, which is still dangerously high, and a record for that medium. Such an attack severely affects the target's data security, as it could leak people's passwords, discussions, messages, or other sensitive information to malicious third parties.

See the full report here: https://www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy/


Clop ransomware now uses torrents to leak data and evade takedowns

The Clop ransomware gang has once again altered extortion tactics and is now using torrents to leak data stolen in MOVEit attacks. Starting on May 27 2023, the Clop ransomware gang launched a wave of data-theft attacks exploiting a zero-day vulnerability in the MOVEit Transfer secure file transfer platform. Exploiting this zero-day allowed the threat actors to steal data from almost 600 organizations worldwide before they realized they were hacked.

See the full report here: https://www.bleepingcomputer.com/news/security/clop-ransomware-now-uses-torrents-to-leak-data-and-evade-takedowns/


Colorado Department of Higher Education warns of massive data breach

The Colorado Department of Higher Education (CDHE) disclosed a massive data breach impacting students, past students, and teachers after suffering a ransomware attack in June 2023. CDHE took steps to secure the network and have been working with third-party specialists to conduct a thorough investigation into this incident. CDHE also worked to restore systems and return to normal operations.

See the full report here: https://www.bleepingcomputer.com/news/security/colorado-department-of-higher-education-warns-of-massive-data-breach/


Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber Attack

Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by malicious actors to deploy web shells. The attacks take advantage of CVE-2023-3519, a critical code injection vulnerability that could lead to unauthenticated remote code execution. The flaw carries a CVSS score of 9.8. The largest number of impacted IP addresses are based in Germany, followed by France, Switzerland, Italy, Sweden, Spain, Japan, China, Austria, and Brazil.

See the full report here: https://thehackernews.com/2023/08/hundreds-of-citrix-netscaler-adc-and.html


Malicious Apps Use Sneaky Versioning Technique to Bypass Google Play Store Scanners

Threat actors are leveraging a technique called versioning to evade Google Play Store's malware detections and target Android users. Campaigns using versioning commonly target users' credentials, data, and finances. In this method, a developer releases an initial version of an app on the Play Store that passes Google's pre-publication checks, but is later updated with a malware component.

See the full report here: https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html


Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information. While the end goal of the undertaking is not clear, it's suspected to be a highly targeted campaign aimed at the cryptocurrency sector based on references to modules such as "rocketrefer" and "binarium."

See the full report here: https://thehackernews.com/2023/08/malicious-npm-packages-found.html


Chrome malware Rilide targets enterprise users via PowerPoint guides

The malicious Rilide Stealer Chrome browser extension has returned in new campaigns targeting crypto users and enterprise employees to steal credentials and crypto wallets. When first discovered, the Rilide browser extension impersonated the legitimate Google Drive extensions to hijack the browser, monitor all user activity, and steal information like email account credentials or cryptocurrency assets.

See the full report here: https://www.bleepingcomputer.com/news/security/chrome-malware-rilide-targets-enterprise-users-via-powerpoint-guides/


Hackers can abuse Microsoft Office executables to download malware

The list of legitimate binaries and scripts present in Windows that can be abused for malicious purposes, will soon include the main executables for Microsoft’s Outlook email client and Access database management system. The main executable for the Microsoft Publisher application has been confirmed to be able to download payloads from a remote server.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-can-abuse-microsoft-office-executables-to-download-malware/


US govt contractor Serco discloses data breach after MoveIT attacks

Serco Inc, the Americas division of multinational outsourcing company Serco Group, has disclosed a data breach after attackers stole the personal information of over 10,000 individuals from a third-party vendor's MoveIT managed file transfer (MFT) server. The personal information compromised in the attack includes any combination of the following: name, U.S. Social Security Number, date of birth, home mailing address, Serco and/or personal e-mail address, and selected health benefits for the year.

See the full report here: https://www.bleepingcomputer.com/news/security/us-govt-contractor-serco-discloses-data-breach-after-moveit-attacks/


New Microsoft Azure AD CTS feature can be abused for lateral movement

Microsoft's new Azure Active Directory Cross-Tenant Synchronization (CTS) feature, introduced in June 2023, has created a new potential attack surface that might allow threat actors to more easily spread laterally to other Azure tenants.

See the full report here: https://www.bleepingcomputer.com/news/security/new-microsoft-azure-ad-cts-feature-can-be-abused-for-lateral-movement/


FBI, CISA, and NSA reveal top exploited vulnerabilities of 2022

In collaboration with CISA, the NSA, and the FBI, Five Eyes cybersecurity authorities have issued today a list of the 12 most exploited vulnerabilities throughout 2022. Cybersecurity agencies in the United States, Australia, Canada, New Zealand, and the United Kingdom called on organizations worldwide to address these security flaws and deploy patch management systems to minimize their exposure to potential attacks.

See the full report here: https://www.bleepingcomputer.com/news/security/fbi-cisa-and-nsa-reveal-top-exploited-vulnerabilities-of-2022/


Mondee security lapse exposed flight itineraries and unencrypted credit card numbers

Travel giant Mondee has secured an exposed database that was spilling sensitive customer information, including detailed flight and hotel itineraries and unencrypted credit card numbers. The database was exposed to the internet without a password, allowing anyone to access the sensitive data inside using a web browser, just with its IP address.

See the full report here: https://techcrunch.com/2023/08/02/mondee-data-exposed-credit-cards-flight-itineraries/


ZeroFox Intelligence Reports:


ZeroFox Intelligence Event Assessment – BRICS Summit

In this ZeroFox Intelligence Assessment, ZeroFox researchers provide an overview of the expected agenda and the possible outcomes of the upcoming BRICS Summit in Johannesburg, South Africa, on August 22-24, 2023.

Report: https://zerofox.com/advisories/21500


Tags: tlp:clear,  all industries,  global, weekly bulletin