ZeroFox Daily Intelligence Brief - August 22, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 22, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- HiatusRAT Malware Resurfaces with Attacks on Taiwanese Firms and U.S. Military
- CISA Pushes Agencies Toward “Quantum-Readiness” to Safeguard Critical Infrastructure
- Foreign Intelligence Agencies Continuously Targeting U.S. Space Industry
- Data broker / initial-access broker / hacktivist group: RAWRZ KittenSec and Exploit user “1337sh.com”
- Exploit: CVE-2019-17570
- Vulnerabilities: CVE-2023-4347 and CVE-2023-40518
- Combolist: '210k Fresh MiXeD HQ Combolist.txt' and Telegram: 'Texture Cloud PRIVATE.zip'
HiatusRAT Malware Resurfaces with Attacks on Taiwanese Firms and U.S. Military
The creators behind the HiatusRAT malware have resumed operations by launching new reconnaissance initiatives against Taiwan-based semiconductor manufacturers and a U.S. military procurement system. The malware was recompiled for various architectures and placed on fresh virtual private servers (VPSs). The attackers, of unknown origin, were known to target Latin America and Europe in an earlier campaign to install spyware on business-grade routers in July 2022. Their motives remain uncertain, possibly related to military contracts.
CISA Pushes Agencies Toward “Quantum-Readiness” to Safeguard Critical Infrastructure
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and National Institute of Standards and Technology (NIST), have released a joint fact sheet promoting better cryptographic standards. The factsheet advises organizations to develop quantum-readiness roadmaps, conduct inventory risk assessments, and engage vendors. NIST plans to publish initial post-quantum cryptographic standards in 2024 in alignment with President Biden's goal of achieving quantum-resilient cybersecurity standards by 2035.
Foreign Intelligence Agencies Continuously Targeting U.S. Space Industry
U.S. authorities have cautioned Americans of foreign intelligence agencies using cyberattacks, strategic investment (including joint ventures and acquisitions), the targeting of key supply chain nodes, and other measures to gain access to the U.S. space industry. The advisory explains how such tactics can compromise economic and national security, highlighted indicators (both cyber, economic, and physical), and recommended mitigation strategies organizations should adopt.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RAWRZ KittenSec: : Posted data allegedly stolen from fintech firm ZaPay
- Exploit user “1337sh.com”:: Auctioning Citrix access to a U.S.-based appliance manufacturer
EXPLOITS
- CVE-2019-17570 - xmlrpc-common untrusted deserialization
VULNERABILITIES
- CVE-2023-4347 - Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
- CVE-2023-40518 - LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
BREACHES
- Combolist:: '210k Fresh MiXeD HQ Combolist.txt' (209,997 Records) | Email address and password
- Telegram:: 'Texture Cloud PRIVATE.zip' Botnet Breach (58,062 Records) | Email address and password
Tags: DIB, tlp:green