Threat Intelligence Bulletin: 08/11/2023 - 08/17/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 08/11/2023 - 08/17/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - August 17, 2023
Brief Highlights
- CISA Releases JCDC Remote Monitoring and Management Cyber Defense Plan
- CISA Cautions Against Actively Exploited Citrix ShareFile Vulnerability
- Vulnerabilities in PowerShell Gallery Allow Attackers to Spoof Genuine Packages
- Data broker / initial-access broker / hacktivist group: Killnet and NoName057(16)
- Vulnerabilities: CVE-2023-4392 and CVE-2023-34213
- Telegram: 'Logs 1.rar' Botnet Breach and 'Logs 5k.rar'
Report: https://zerofox.com/advisories/21579
ZeroFox Daily Intelligence Brief - August 16, 2023
Brief Highlights
- XML-Injection Flaw Present in Widely Used Network-Monitoring Tool
- Ivanti Avalanche Impacted By Stack Buffer Overflows Bugs
- Cybercriminals Exploit Cloudflare R2 to Hosting Phishing Pages
- Data broker / initial-access broker / hacktivist group: Türk Hack Team and ACEH ABOUT HACKED WORLD
- Vulnerabilities: CVE-2019-19921 and CVE-2023-32004
- Telegram: 'logi5.rar' Botnet Breach and XSS/Leakbase: FPuiki dovana Data Breach
Report: https://zerofox.com/advisories/21569
ZeroFox Daily Intelligence Brief - August 15, 2023
Brief Highlights
- FBI Warns Users About Companies Claiming to Recover Stolen Cryptocurrency
- Data of 760,000 Individuals Leaked from Third-Party Discord Service
- Multiple Vulnerabilities Discovered in Globally-Used ATM Management Software
- Data broker / initial-access broker / hacktivist group: NDT Sec and Hacktivist Indonesia
- Vulnerabilities: CVE-2023-34966 and CVE-2023-38208
- Leakbase: Lash FX Data Breach and Foodmazone Data Breach
Report: https://zerofox.com/advisories/21561
ZeroFox Daily Intelligence Brief - August 14, 2023
Brief Highlights
- Vulnerabilities in CODESYS V3 Expose Millions of Industrial PLCs
- Python Parsing Flaw Could Allow Attackers to Bypass Security Filters
- Ford: Cars with WiFi Bug Safe to Drive
- Data broker / initial-access broker / hacktivist group: Anonymous Collective and Alatus Aerosystems
- Vulnerabilities: CVE-2020-13654 and CVE-2023-0950
- Breaches: BreachForums: Noveo solutions and XSS/Nulled: Billy Hyde Music
Report: https://zerofox.com/advisories/21547
ZeroFox Daily Intelligence Brief - August 11, 2023
Brief Highlights
- Cross-Platform TunnelCrack Attack Leaks VPN Traffic by Interrupting Routing Tables
- CISA Warns Against Newly Exploited Backdoors in Barracuda Email Gateway Devices
- Researchers Bring Attention to Potential Abuse of ANSI Escape Sequence in Terminal Software
- Data broker / initial-access broker / hacktivist group: Killmilk/Killnet: and RAWRZ KittenSec group
- Vulnerabilities: CVE-2023-38333 and CVE-2023-40224
- Breaches: Telegram: 202305_redline_7386_B_(20230526).zip and GODELESS CLOUD.rar
Report: https://zerofox.com/advisories/21538
Breach Disclosures:
Foodmazone
An alleged data breach at Foodmazone – an India-based online food and grocery store – exposed 46,097 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21560
Lash FX
An alleged data breach at Lash FX – a U.K-based barber shop and beauty salon – exposed 9,007 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21559
Puiki dovana
An alleged data breach at Puiki dovana – a Lithuania-based online gift shop – exposed 5,860 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21558
Billy Hyde Music
An alleged data breach at Billy Hyde Music – an Australia-based music store – exposed 11,350 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21549
Noveo Solutions
An alleged data breach at Noveo Solutions – a France-based company that operates in copiers, backup and, cyber security – exposed 409,611 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21548
Breaking News:
Man arrested in Northern Ireland police data leak as more incidents come to light
A man was arrested in Northern Ireland for suspected Collection of Terrorist Information following an incident where police mistakenly leaked details that identified 10,000 serving officers, but he has now been released on bail. The unnamed man was questioned by detectives who were said to be "investigating criminality linked to last week's freedom of information data breach."
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/17/man_arrested_in_ni_police/
PowerShell Gallery Prone to Typosquatting, Other Supply Chain Attacks
Researchers have warned that active vulnerabilities within the PowerShell Gallery pose a supply chain risk, allowing attackers to upload harmful modules that appear genuine by spoofing Author(s), Copyright, and Description fields, and can lead to unauthorized access to sensitive information meant to be hidden from public view.
See the full report here: https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks
Russian Hackers Use Zulip Chat App for Covert C&C in Diplomatic Phishing Attacks
An ongoing campaign targeting ministries of foreign affairs of NATO-aligned countries points to the involvement of Russian threat actors. The phishing attacks feature PDF documents with diplomatic lures to deliver a variant of a malware called Duke, which has been attributed to APT29 (aka BlueBravo, Cloaked Ursa, Cozy Bear, Iron Hemlock, Midnight Blizzard, and The Dukes). The threat actor used Zulip – an open-source chat application – for command-and-control, to evade and hide its activities behind legitimate web traffic.
See the full report here: https://thehackernews.com/2023/08/russian-hackers-use-zulip-chat-app-for.html
Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning
Exploitation attempts targeting a remote code execution flaw in Citrix’s ShareFile product have spiked just as the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities Catalog. The vulnerability is tracked as CVE-2023-24489 and has been assigned a "critical" severity rating. It could allow an unauthenticated attacker to upload arbitrary files and possibly achieve remote code execution.
See the full report here: https://www.securityweek.com/exploitation-of-citrix-sharefile-vulnerability-spikes-as-cisa-issues-warning/
CISA rolls out Cyber Defense Plan to address systemic remote mangement risks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released the Joint Cyber Defense Collaborative (JCDC) remote monitoring and management (RMM) Cyber Defense Plan that provides a roadmap to address systemic risks. Attackers have increasingly attacked these tools to breach security systems.
See the full report here: https://www.securityweek.com/cisa-releases-cyber-defense-plan-to-reduce-rmm-software-risks/
Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability
Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a large-scale attack. An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing web shells on vulnerable NetScalers to gain persistent access. The adversary can execute arbitrary commands with this webshell, even when a NetScaler is patched and/or rebooted.
See the full report here: https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
OpenNMS Bug Steals Data, Triggers Denial of Service
Maintainers of OpenNMS patched a high-severity vulnerability in both the community-supported and subscription-based versions of the widely used open source network monitoring software. The XML external entity (XXE) injection vulnerability gives attackers a way to exfiltrate data from the OpenNMS file server system, send arbitrary HTTP requests to internal and external services, and trigger denial-of-service conditions on affected systems.
See the full report here: https://www.darkreading.com/application-security/patch-now-opennms-bug-steals-data-triggers-denial-of-service
US congressman says Chinese spies hacked his emails
A Republican U.S. Representative indicated that the FBI had warned him that his emails had been hacked by Chinese spies, with both personal and campaign messages compromised. The individual was told that the Chinese Communist Party had access to his accounts for about a month ending on June 16 2023, he said on X, the social media platform formerly known as Twitter.
See the full report here: https://www.reuters.com/world/us/us-congressman-says-chinese-spies-hacked-his-emails-2023-08-15/#:~:text=WASHINGTON%2C%20Aug%2015%20(Reuters),personal%20and%20campaign%20messages%20compromised
Raccoon Stealer malware returns with new stealthier version
The developers of Raccoon Stealer information-stealing malware have ended their 6-month hiatus from hacker forums to promote a new 2.3.0 version of the malware to cyber criminals. The malware's current authors informed cybercriminal communities that they're back, having spent their time "working tirelessly" to bring them new features that will enrich the user experience.
See the full report here: https://www.bleepingcomputer.com/news/security/raccoon-stealer-malware-returns-with-new-stealthier-version/
Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages
Threat actors' use of Cloudflare R2 to host phishing pages has witnessed a 61-fold increase over the past six months. The majority of the phishing campaigns target Microsoft login credentials, although there are some pages targeting Adobe, Dropbox, and other cloud apps.
See the full report here: https://thehackernews.com/2023/08/cybercriminals-abusing-cloudflare-r2.html
LinkedIn accounts hacked in widespread hijacking campaign
LinkedIn is being targeted in a wave of account hacks resulting in many accounts being locked out for security reasons or ultimately hijacked by attackers.
See the full report here: https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
Clorox deals with security breach that disrupted operations
The Clorox Company had some of its IT systems offline and its operations "temporarily impaired" following a security breach and unauthorized activity in its networks. The intrusion continues to disrupt "parts of the company's business operations," and it is "working diligently to respond to and address this issue, and is also coordinating with law enforcement," according to the Form 8-K submission.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/15/clorox_cleans_up_security_breach/
Two unauthenticated stack buffer overflows found in Ivanti Avalanche EMM
Researchers discovered two stack-based buffer overflows, collectively tracked as CVE-2023-32560 (CVSS v3: 9.8), impacting the Ivanti Avalanche enterprise mobility management (EMM) solution.
See the full report here: https://securityaffairs.com/149561/hacking/ivanti-avalanche-buffer-overflow-bugs.html
FBI warns of increasing cryptocurrency recovery scams
The FBI is warning of an increase in scammers pretending to be recovery companies that can help victims of cryptocurrency investment scams recover lost assets.
See the full report here: https://www.bleepingcomputer.com/news/security/fbi-warns-of-increasing-cryptocurrency-recovery-scams/
Ongoing Xurum attacks target Magento 2 e-stores
Researchers warn of ongoing attacks, dubbed Xurum, targeting e-commerce websites running the Magento 2 CMS. The attackers are actively exploiting a server-side template injection issue, tracked as CVE-2022-24086, (CVSS score: 9.8), in Adobe Commerce and Magento Open Source.
See the full report here: https://securityaffairs.com/149509/cyber-crime/xurum-adobes-magento-2-attacks.html
Discord.io confirms breach after hacker steals data of 760K users
The Discord.io custom invite service has temporarily shut down after suffering a data breach exposing the information of 760,000 members.
See the full report here: https://www.bleepingcomputer.com/news/security/discordio-confirms-breach-after-hacker-steals-data-of-760k-users/
China teases imminent exposé of seismic US spying scheme
China's Global Times, a state-controlled media outlet, has teased an imminent exposé of alleged US attacks on seismic data measurement stations. The Global Times' latest report states that analysis of the attack found "very complex backdoor malware in the victim's network".
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/15/china_seismic_us_spying_expose/
QwixxRAT, a new Windows RAT appears in the threat landscape
QwixxRAT is a new Windows remote access trojan (RAT) that is offered for sale through Telegram and Discord platforms.The RAT is able to collect sensitive data and exfiltrate them by sending the info to the attacker’s Telegram bot. Threat actors remotely control the RAT and manage its operations through a Telegram bot.
See the full report here: https://securityaffairs.com/149525/cyber-crime/qwixxrat-telegramrat.html
Over 120,000 Computers Compromised by Info Stealers Linked to Users of Cybercrime Forums
About 120,000 computers infected by stealer malware have credentials associated with cybercrime forums, many of them belonging to malicious actors. Data retrieved from machines compromised by stealer malware is often expansive and wide-ranging, enabling the real-world identities of hackers to be discovered based on indicators such as credentials, addresses, phone numbers, computer names, and IP addresses.
See the full report here: https://thehackernews.com/2023/08/over-12000-computers-compromised-by.html
Hacking ATMs by exploiting flaws in ScrutisWeb ATM fleet software
Researchers found multiple flaws (CVE-2023-33871, CVE-2023-38257, CVE-2023-35763 and CVE-2023-35189) in the ScrutisWeb ATM fleet monitoring software that can be exploited to remotely hack ATMs. ScrutisWeb software is developed by Lagona, it allows for remote management of ATMs fleets.
See the full report here: https://securityaffairs.com/149533/hacking/scrutisweb-atm-sw-atms.html
UK govt contractor MPD FM leaks employee passport data
MPD FM, a facility management and security company providing services to various UK government departments, left an open instance that exposed employee passports, visas, and other sensitive data.
See the full report here: https://securityaffairs.com/149440/security/mpd-fm-data-leak.html
Zoom ZTP & AudioCodes Phones Flaws Uncovered, Exposing Users to Eavesdropping
Multiple security vulnerabilities have been disclosed in AudioCodes desk phones and Zoom's Zero Touch Provisioning (ZTP) that could be potentially exploited by a malicious attacker to conduct remote attacks. An external attacker who leverages these vulnerabilities could gain full remote control of the devices.
See the full report here: https://thehackernews.com/2023/08/zoom-ztp-audiocodes-phones-flaws.html
LOLEKHosted admin arrested for aiding Netwalker ransomware gang
Police have taken down the Lolek bulletproof hosting provider, arresting five individuals and seizing servers for allegedly facilitating Netwalker ransomware attacks and other malicious activities.
See the full report here: https://www.bleepingcomputer.com/news/security/lolekhosted-admin-arrested-for-aiding-netwalker-ransomware-gang/
Ford says cars with WiFi vulnerability still safe to drive
Ford is warning of a buffer overflow vulnerability (CVE-2023-29468) in its SYNC3 infotainment system used in many Ford and Lincoln vehicles, which could allow remote code execution, but says that vehicle driving safety isn't impacted.
See the full report here: https://www.bleepingcomputer.com/news/security/ford-says-cars-with-wifi-vulnerability-still-safe-to-drive/
Knight ransomware distributed in fake Tripadvisor complaint emails
The Knight ransomware is being distributed in an ongoing spam campaign that pretends to be TripAdvisor complaints.
See the full report here: https://www.bleepingcomputer.com/news/security/knight-ransomware-distributed-in-fake-tripadvisor-complaint-emails/
Multiple flaws in CODESYS V3 SDK could lead to RCE or DoS
16 vulnerabilities in Codesys products could result in remote code execution and DoS attacks exposing OT environments to hacking. Experts pointed out that the exploiting the vulnerabilities requires user authentication, as well as deep knowledge of the proprietary protocol of CODESYS V3 and the structure of the different services that the protocol uses.
See the full report here: https://securityaffairs.com/149474/security/codesys-v3-sdk-rce-dos.html
Hactivitsts attack Japanese government over Fukushima wastewater release
Entities using the name and iconography of Anonymous (EUTNAIOA) claim to have conducted cyberprotests against the Japanese government for actions related to the release of wastewater from the Fukushima Daini Nuclear Power Plant. In an operation dubbed “Tango Down”, The Anonymous Italia Collective claims to have attacked 21 government and other websites associated with the decision to release wastewater from the Fukushima facility.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/14/hactivitsts_claim_japanese_government_attack/
Nine flaws in CyberPower and Dataprobe solutions expose data centers to hacking
Researchers discovered multiple vulnerabilities impacting CyberPower’s PowerPanel Enterprise Data Center Infrastructure Management (DCIM) platform and Dataprobe’s iBoot Power Distribution Unit (PDU).
See the full report here: https://securityaffairs.com/149478/security/cyberpower-dcim-pdu-flaws.html
Statc Stealer, a new sophisticated info-stealing malware
Researchers discovered a new information stealer malware, called Statc Stealer, that can steal a broad range of info from Windows devices. The malware can steal sensitive information from various web browsers, including login data, cookies, web data, and preferences.
See the full report here: https://securityaffairs.com/149405/hacking/statc-stealer-info-stealer.html
TunnelCrack attack may cause vulnerable VPNs to leak traffic
A couple of techniques collectively known as TunnelCrack can, in the right circumstances, be used by snoops to force victims' network traffic to go outside their encrypted VPNs. A team of academics explained how the attacks work, released proof-of-concept exploits, and reckoned "every VPN product is vulnerable on at least one device."
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/10/tunnelcrack_vpn/
NSA: Codebreaker Challenge Helps Drive Cybersecurity Education
According to the US National Security Agency (NSA), its cybersecurity outreach efforts with high school and college and university students has helped shape cyber curriculum in schools, as well as led to more students applying to work for the agency.
See the full report here: https://www.darkreading.com/attacks-breaches/nsa-talks-codebreaker-challenge-success-influence-on-education
New SystemBC Malware Variant Targets Southern African Power Company
An unknown threat actor has been linked to a cyber attack on a power generation company in South Africa with a new variant of the SystemBC malware called DroxiDat as a precursor to a suspected ransomware attack.
See the full report here: https://thehackernews.com/2023/08/new-systembc-malware-variant-targets.html
Researchers Shed Light on APT31's Advanced Backdoors and Data Exfiltration Tactics
The Chinese threat actor known as APT31 (aka Bronze Vinewood, Judgement Panda, or Violet Typhoon) has been linked to a set of advanced backdoors that are capable of exfiltrating harvested sensitive information to Dropbox.
See the full report here: https://thehackernews.com/2023/08/researchers-shed-light-on-apt31s.html
Dell Compellent hardcoded key exposes VMware vCenter admin creds
An unfixed hardcoded encryption key flaw in Dell's Compellent Integration Tools for VMware (CITV) allows attackers to decrypt stored vCenter admin credentials and retrieve the cleartext password.
See the full report here: https://www.bleepingcomputer.com/news/security/dell-compellent-hardcoded-key-exposes-vmware-vcenter-admin-creds/
CISA: New Whirlpool backdoor used in Barracuda ESG hacks
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has discovered a new backdoor malware named "Whirlpool" used in attacks on compromised Barracuda Email Security Gateway (ESG) devices.
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-new-whirlpool-backdoor-used-in-barracuda-esg-hacks/
Gafgyt malware exploits five-years-old flaw in EoL Zyxel router
Fortinet has issued an alert warning that the Gafgyt botnet malware is actively trying to exploit a vulnerability in the end-of-life Zyxel P660HN-T1A router in thousands of daily attacks. The malware targets CVE-2017-18368, a critical severity (CVSS v3: 9.8) unauthenticated command injection vulnerability in the device's Remote System Log forwarding function, which was patched by Zyxel in 2017
See the full report here: https://www.bleepingcomputer.com/news/security/gafgyt-malware-exploits-five-years-old-flaw-in-eol-zyxel-router/
ZeroFox Intelligence Reports:
ZeroFox Intelligence Brief - Overview of the Wagner Group Uprising
The ZeroFox Geopolitical Working Group provides an overview of the June 2023 uprising of the Wagner Group in Russia, as well as possible implications for the group’s locations outside of Russia.
Report: https://zerofox.com/advisories/21578
Tags: tlp:clear, all industries, global, weekly bulletin