ZeroFox Daily Intelligence Brief - August 24, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 24, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- WinRAR Zero-Day Exploited to Target Crypto Accounts
- FBI Identifies Cryptocurrency Funds Stolen by North Korean Hackers
- Over 3,000 Openfire Servers Vulnerable to Takeover Attacks
- Data broker / initial-access broker / hacktivist group: Clop and Exploit user LuciferXfiles
- Exploits: CVE-2020-3956 and CVE-2020-14882
- Vulnerabilities: CVE-2023-40178 and CVE-2023-40185
- Leakbase: DCGpac Data Breach and XSS: Bootskram Data Breach Botnet Breach
WinRAR Zero-Day Exploited to Target Crypto Accounts
Threat actors are abusing a now-patched bug (CVE-2023-38831) in WinRAR to hide malware in zip archives purportedly comprising legitimate file formats such as JPG and TXT. The attacks, which go back to at least April 2023, primarily target traders of stocks and cryptocurrency—with the goal to drain funds from trading accounts. WinRAR users should upgrade to the latest version of the software to secure themselves from attacks.
FBI Identifies Cryptocurrency Funds Stolen by North Korean Hackers
The FBI has alerted cryptocurrency exchanges about recent blockchain activity tied to the theft of hundreds of millions of dollars in cryptocurrency. The FBI was able to trace stolen cryptocurrency linked to the DPRK's TraderTraitor (Lazarus Group, APT38). The agency shared the addresses linked to the thefts and urged caution in transactions linked to them. The group was identified to be behind several major heists, including that of USD 60 million from Alphapo, USD 37 million from CoinsPaid, and USD 100 million from Atomic Wallet.
Over 3,000 Openfire Servers Vulnerable to Takeover Attacks
Popular Java-based open-source chat server Openfire is vulnerable to CVE-2023-32315, an actively exploited path traversal flaw that allows unauthorized creation of admin accounts. Disclosed on May 23, 2023, the flaw affects versions since 3.10.0 (April 2015). While security updates (4.6.8, 4.7.5, and 4.8.0) were released, the flaw was still being exploited in June 2023, leading to illegitimate admin user creation and malicious plugin uploads.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Clop:: Publishing data stolen from close to 20 victims in the form of torrent files.
- Exploit user LuciferXfiles:: Posted 50,000 credit cards allegedly from fintech company Jeeves
EXPLOITS
- CVE-2020-3956 - vCloud Director - Remote Code Execution
- CVE-2020-14882 - Oracle WebLogic Server Remote Code Execution
VULNERABILITIES
- CVE-2023-40178 - The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter.
- CVE-2023-40185 - This may impact users that use Shescape on Windows in a threaded context.
BREACHES
- Leakbase: DCGpac Data Breach: Everyshop Data Breach (44,261 Records) | Email address, company name, gender, name, phone number, and physical address
- XSS: Bureau van Dijk Data Breach: Bootskram Data Breach Botnet Breach (11,677 Records) | Email address, name, national ID, nationality, phone number, geographic location
Tags: DIB, tlp:green