zerofox logo
Advisories

Threat Intelligence Bulletin: 08/18/2023 - 08/24/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 08/18/2023 - 08/24/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - August 24, 2023

Brief Highlights

  • WinRAR Zero-Day Exploited to Target Crypto Accounts
  • FBI Identifies Cryptocurrency Funds Stolen by North Korean Hackers
  • Over 3,000 Openfire Servers Vulnerable to Takeover Attacks
  • Data broker / initial-access broker / hacktivist group: Clop and Exploit user LuciferXfiles
  • Exploits: CVE-2020-3956 and CVE-2020-14882
  • Vulnerabilities: CVE-2023-40178 and CVE-2023-40185
  • Leakbase: DCGpac Data Breach and XSS: Bootskram Data Breach Botnet Breach

Report: https://zerofox.com/advisories/21628


ZeroFox Daily Intelligence Brief - August 23, 2023

Brief Highlights

  • Hacker Group Abuses Software Trust Model to Disguise Malware
  • Akira Ransomware Compromise Enterprise VPNs to Backdoor Data Transmission
  • Native Xloader Malware Highlights Increased Targeting of MacOS Devices
  • Data broker / initial-access broker / hacktivist group: Cʏʙᴇʀ Cᴀᴛ and Mysterious team Bangladesh
  • Exploits: CVE-2020-0796 and CVE-2020-11651
  • Vulnerabilities: CVE-2023-4404 and CVE-2023-40144
  • Leakbase: Everyshop Data Breach and Bootskram Data Breach Botnet Breach

Report: https://zerofox.com/advisories/21621


ZeroFox Daily Intelligence Brief - August 22, 2023

Brief Highlights

  • HiatusRAT Malware Resurfaces with Attacks on Taiwanese Firms and U.S. Military
  • CISA Pushes Agencies Toward “Quantum-Readiness” to Safeguard Critical Infrastructure
  • Foreign Intelligence Agencies Continuously Targeting U.S. Space Industry
  • Data broker / initial-access broker / hacktivist group: RAWRZ KittenSec and Exploit user “1337sh.com”
  • Exploit: CVE-2019-17570
  • Vulnerabilities: CVE-2023-4347 and CVE-2023-40518
  • Combolist: '210k Fresh MiXeD HQ Combolist.txt' and Telegram: 'Texture Cloud PRIVATE.zip'

Report: https://zerofox.com/advisories/21608


ZeroFox Daily Intelligence Brief - August 21, 2023

Brief Highlights

  • Interpol Operation Disrupts Thousands of Illicit Cyber Networks in Africa
  • WinRAR Patches Remote Code Execution Flaw
  • Malicious Campaign Targets Victims Through Malware Hidden in Image Files
  • Data broker / initial-access broker / hacktivist group: Exploit user “Roblette”
  • Exploits: CVE-2019-19781 and CVE-2017-11317
  • Vulnerabilities: CVE-2023-30861 and CVE-2022-24989
  • Credit Card Data Breach and Combolist: '260K.txt'

Report: https://zerofox.com/advisories/21599


ZeroFox Daily Intelligence Brief - August 18, 2023

Brief Highlights

  • Criminals Share Malicious Android APKs that Evade Security Measures
  • Russian Threat Actors Target Ministries of Foreign Affairs of NATO-Aligned Countries
  • Researchers Demonstrate Inconspicuous Exploit in iOS devices Through Fake Airplane Mode
  • Data broker / initial-access broker / hacktivist group: BreachForums user “c0wb0y5”and Mysterious Team Bangladesh
  • Vulnerabilities: CCVE-2023-33934 and CVE-2023-4364
  • Leakbase: CompAndSave Data Breach and Mosquiteras Data Breach

Report: https://zerofox.com/advisories/21585


Breach Disclosures:


Everyshop

An alleged data breach at Everyshop – a South Africa-based e-commerce service industry – exposed 67,759 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21610


EVO Banca Inteligente

An alleged data breach at EVO Banca Inteligente – a Spain-based financial institution that manages loans, credit cards, and personal accounts – exposed 58,459 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21609


CompAndSave

An alleged data breach at CompAndSave – a U.S.-based retailer of printer inkjet cartridge, laser toner, and, printer accessories – exposed 1,97,405 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21588


Menominee Industrial Supply

An alleged data breach at Menominee Industrial Supply – a U.S.-based company that operates in industrial machinery and equipment – exposed 1,653 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21587


Mosquiteras

An alleged data breach at Mosquiteras – a Spain-based company that operates in consumer electronics and computers retail – exposed 104,388 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21586


Breaking News:


Lapsus$ member has been convicted of having hacked multiple high-profile companies

An 18-year-old member of the Lapsus$ gang has been convicted of having helped hack multiple high-profile companies including Uber and Revolut Since September 2022, the individual conducted a series of solo attacks, gained access to around 5,000 Revolut customers’ records and hacked Uber causing around USD 3 million of damage. Then he targeted Rockstar Games and threatened to release the source code for an upcoming game.

See the full report here: https://securityaffairs.com/149821/cyber-crime/lapsus-member-convicted.html


More than 3,000 Openfire servers exposed to attacks using a new exploit

Researchers warn that more than 3,000 unpatched Openfire chat servers are exposed to attacks exploiting a recent flaw(CVE-2023-32315). CVE-2023-32315 is a path traversal vulnerability affecting the Openfire admin console. An unauthenticated user can exploit the flaw to access restricted pages in the Openfire Admin Console reserved for administrative users.

See the full report here: https://securityaffairs.com/149811/breaking-news/openfire-servers-exposed-new-exploit.html?&web_view=true


WinRAR Security Flaw Exploited in Zero-Day Attacks to Target Traders

A recently patched security flaw in the popular WinRAR archiving software has been exploited as a zero-day since April 2023. The vulnerability, cataloged as CVE-2023-38831, allows threat actors to spoof file extensions, thereby making it possible to launch malicious scripts contained within an archive that masquerades as seemingly innocuous image or text files.

See the full report here: https://thehackernews.com/2023/08/winrar-security-flaw-exploited-in-zero.html


New "Whiffy Recon" Malware Triangulates Infected Device Location via Wi-Fi Every Minute

The SmokeLoader malware is being used to deliver a new malware strain called Whiffy Recon on compromised Windows machines. The new malware strain has only one operation, every 60 seconds it triangulates the infected systems' positions by scanning nearby Wi-Fi access points as a data point for Google's geolocation API.

See the full report here: https://thehackernews.com/2023/08/new-whiffy-recon-malware-triangulates.html


Akira Ransomware Targets Cisco VPNs to Breach Organizations

There's mounting evidence that Akira ransomware targets Cisco VPN (virtual private network) products as an attack vector to breach corporate networks, steal, and eventually encrypt data.

See the full report here: https://www.bleepingcomputer.com/news/security/akira-ransomware-targets-cisco-vpns-to-breach-organizations/?&web_view=true


Scraped data of 2.6 million Duolingo users released on hacking forum

The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information.

See the full report here: https://www.bleepingcomputer.com/news/security/scraped-data-of-26-million-duolingo-users-released-on-hacking-forum/


Over a Dozen Malicious npm Packages Target Roblox Game Developers

More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token Grabber on systems belonging to Roblox developers.

See the full report here: https://thehackernews.com/2023/08/over-dozen-malicious-npm-packages.html


TP-Link Tapo L530E smart bulb flaws allow hackers to steal user passwords

Researchers from the University of Catania (Italy) and the University of London (UK) have discovered four vulnerabilities impacting the TP-Link Tapo L530E smart bulb and the mobile app TP-Link’s Tapo app, which could allow attackers to steal the users’ WiFi password.

See the full report here: https://securityaffairs.com/149783/hacking/tp-link-tapo-l530e-smart-bulb-flaws.html


Criminals go full Viking on CloudNordic, wipe all servers and customer data

CloudNordic has told customers to consider all of their data lost following a ransomware infection that encrypted the large Danish cloud provider's servers and "paralyzed CloudNordic completely," according to the IT outfit's online confession.

See the full report here: https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/


Spacecolon Toolset Fuels Global Surge in Scarab Ransomware Attacks

A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally. It ia assumed to find its way into victim organizations by its operators compromising vulnerable web servers or via brute forcing RDP credentials.

See the full report here: https://thehackernews.com/2023/08/spacecolon-toolset-fuels-global-surge.html


Snatch gang claims the hack of the Department of Defence South Africa

The Snatch ransomware group added the Department of Defence South Africa to its data leak site. The mission of the Department of Defence is to provide, manage, prepare and employ defence capabilities commensurate with the needs of South Africa, as regulated by the Constitution, national legislation, parliamentary and executive direction. The group claims to have stolen Military contracts, internal call signs and personal data, for a total of 1.6 TB of data.s.

See the full report here: https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html


New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App

A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote."

See the full report here: https://thehackernews.com/2023/08/new-variant-of-xloader-macos-malware.html


Ivanti Warns of New Actively Exploited Sentry Zero-Day Bug

The critical vulnerability enables unauthenticated attackers to gain access to sensitive admin portal configuration APIs exposed over port 8443, used by Ivanti MobileIron Configuration Service (MICS).

See the full report here: https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/?&web_view=true


Police Insider Tipped Off Criminal Friend About EncroChat Bust

An intelligence analyst working for police in the North West of England shared information about a major countrywide operation with a criminal contact, in what has been described as a “disgraceful” betrayal of her colleagues. At Liverpool Crown Court on they pleaded guilty to charges of misconduct in public office, perverting the course of justice and unauthorized access to computer material. NCA officers believe the individual revealed to a criminal not only about the operation but also that police also had intelligence on them.

See the full report here: https://www.infosecurity-magazine.com/news/police-insider-tipped-off/?&web_view=true


CISA, NSA, NIST factsheet addresses migration to post-quantum cryptography, ahead of standards rollout

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and National Institute of Standards and Technology (NIST) published a factsheet on the impacts of quantum capabilities and necessary steps to begin planning for migration to PQC (post-quantum cryptography). Titled "Quantum-Readiness: Migration to Post-Quantum Cryptography," the factsheet provides necessary steps and guidance to help organizations establish their own quantum-readiness roadmap.

See the full report here: https://industrialcyber.co/cisa/cisa-nsa-nist-factsheet-addresses-migration-to-post-quantum-cryptography-ahead-of-standards-rollout/


Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. Researchers are tracking the activity under its insect-themed moniker Carderbee. The attacks leverage a trojanized version of a legitimate software called EsafeNet Cobra DocGuard Client to deliver a known backdoor called PlugX (aka Korplug) on victim networks.

See the full report here: https://thehackernews.com/2023/08/carderbee-attacks-hong-kong.html


TP-Link Smart Bulbs can Let Hackers Steal Your WiFi Password

Researchers from Italy and the UK have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and TP-Link’s Tapo app, which could allow attackers to steal their target’s WiFi password

See the full report here: https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/?&web_view=true


CISA Warns of Another Exploited Adobe ColdFusion Vulnerability

CISA warns that CVE-2023-26359, an Adobe ColdFusion vulnerability patched in March 2034, is still being exploited in the wild. The vulnerability is known to be a critical data deserialization issue that can be exploited for arbitrary code execution.

See the full report here: https://www.securityweek.com/cisa-warns-of-another-exploited-adobe-coldfusion-vulnerability/


Australian Software Provider Energy One Hit by Cyberattack

Wholesale energy software provider Energy One reported that a cyberattack had affected "certain corporate systems" in Australia and the UK. In a statement, the company said analysis is underway to identify which systems have been affected.

See the full report here: https://www.darkreading.com/dr-global/energy-one-investigates-cyberattack?&web_view=true


Cyberattack on UK IT Firm Swan Retail Affects 300 Retailers

Hundreds of impacted retailers in the UK could not process payments, complete orders, or trade online due to the attack on Swan Retail. According to a statement from the company’s representative, its systems were targeted by an unauthorized third party to which the company responded quickly by alerting its internal IT team, affiliated retailers, and law enforcement authorities.

See the full report here: https://www.hackread.com/cyberattack-uk-swan-retail-affects-retailers/


WinRAR flaw enables remote code execution of arbitrary code

A flaw impacting the file archiver utility for Windows WinRAR can allow the execution of commands on a computer by opening an archive. WinRAR is a popular file compression and archival utility for Windows operating systems. The utility is affected by a now-fixed high-severity vulnerability, tracked as CVE-2023-40477 (CVSS score 7.8), that can allow remote execution of arbitrary code on a computer by opening a crafted RAR archive. WinRAR addressed the flaw with the release of version 6.23.

See the full report here: https://securityaffairs.com/149670/hacking/winrar-rce.html


N. Korean Kimsuky APT targets S. Korea-US military exercises

Hackers believed to be linked to a North Korean group dubbed Kimsuky — carried out “continuous malicious email attacks” on South Korean contractors working at the allies’ combined exercise war simulation centre, the Gyeonggi Nambu Provincial Police Agency said in a statement. Police investigation confirms that North Korean hacking group was responsible for the attack,” it said in a statement, adding that military-related information was not stolen.

See the full report here: https://securityaffairs.com/149698/apt/kimsuky-war-simulation-centre.html


US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry

US agencies have indicated that threat actors, may leak intellectual property and steal innovations, collect information on and disrupt US satellite communications and related capabilities, impact the US’s ability to provide critical services, and find and exploit vulnerabilities in US commercial space infrastructure.

See the full report here: https://www.securityweek.com/us-gov-warns-of-foreign-intelligence-cyberattacks-against-us-space-industry/


WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams

Cybersecurity researchers have detailed an updated version of an advanced fingerprinting and redirection toolkit called WoofLocker that's engineered to conduct tech support scams. This redirection mechanism, in turn, makes use of steganographic tricks to conceal the JavaScript code within a PNG image that's served only when the validation phase is successful.

See the full report here: https://thehackernews.com/2023/08/wooflocker-toolkit-hides-malicious.html


Interpol arrest 14 who allegedly scammed USD 40 million from victims

An Interpol-led operation arrested 14 suspects and identified 20,674 "suspicious" networks spanning 25 African countries that international cops have linked to more than USD 40 million in cybercrime losses. Africa Cyber Surge II, a combined police operation which began in April 2023 and lasted four months, was a coordinated effort between Interpol, African law enforcement, and private-sector security firms to disrupt online extortion, phishing, business email compromise (BEC) and other cyber scam

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/20/interpol_africa_arrests/


New Juniper Junos OS Flaws Expose Devices to Remote Attacks

Networking appliances maker Juniper Networks announced patches for four vulnerabilities in the J-Web interface of Junos OS, which could be combined for unauthenticated, remote code execution.

See the full report here: https://thehackernews.com/2023/08/new-juniper-junos-os-flaws-expose.html


Hackers Pocket USD 50,000 for Exploiting US Air Force Defenses

A security exercise was conducted during the annual "Hack-A-Sat" competition within the US Air Force during which hackers managed to successfully compromise a satellite in orbit. MHACKeroni, an Italian team that emerged as the winner of the competition, won a prize of USD 50,000 for the discovery of vulnerabilities within the satellite's network systems which allowed them to reveal the vulnerabilities.

See the full report here: https://www.cysecurity.news/2023/08/satellite-security-breached-hackers.html


Tesla Discloses Data Breach Related to Whistleblower Leak

Tesla has disclosed a data breach impacting roughly 75,000 people, but the incident is the result of a whistleblower leak rather than a malicious cyberattack. Tesla told US authorities that a data breach discovered in May 2023 resulted in the exposure of the personal information, including social security numbers, of more than 75,700 individuals

See the full report here: https://www.securityweek.com/tesla-discloses-data-breach-related-to-whistleblower-leak/


Play' Ransomware Group Targeting MSPs Worldwide in New Campaign

The fast-rising Play ransomware group that targeted the City of Oakland is now hitting managed service providers (MSPs) around the globe in a cyberattack campaign to distribute ransomware to their downstream customers.

See the full report here: https://www.darkreading.com/cloud/-play-ransomware-group-targeting-msps-worldwide-in-new-campaign


Experts devise an exploit for Apple iOS 16 that relies on fake Airplane Mode

Researchers developed a post-exploit persistence technique on iOS 16 that trick victims into believing that the device is in functional Airplane Mode

See the full report here: https://securityaffairs.com/149597/mobile-2/airplane-mode-apple-ios-16-exploit.html


Malicious QR Codes Used in Phishing Attack Targeting US Energy Company

A widespread phishing campaign ongoing since May 2023 has been targeting organizations in various industries, including a major US energy company. Aimed at harvesting the Microsoft account credentials of the targeted organizations’ employees, the attacks rely on malicious QR codes embedded inside PNG images or PDF documents.

See the full report here: https://www.securityweek.com/malicious-qr-codes-used-in-phishing-attack-targeting-us-energy-company/


NoFilter Attack: Sneaky Privilege Escalation Method Bypasses Windows Security

A previously undetected attack method called NoFilter has been found to abuse the Windows Filtering Platform (WFP) to achieve privilege escalation in the Windows operating system.

See the full report here: https://thehackernews.com/2023/08/nofilter-attack-sneaky-privilege.html


White House Orders Federal Agencies to Bolster Cyber Safeguards

The White House has ordered federal agencies to get their cybersecurity safeguards up to date as they lag in their ability to implement President Biden's executive order, issued in 2021. A public memo stated that multiple federal agencies and departments have "failed to fully comply" with the critical security practices that were detailed in the executive order.

See the full report here: https://www.darkreading.com/attacks-breaches/white-house-orders-federal-agencies-to-bolster-cyber-safeguards


Researchers discover new BlackCat ransomware version

Researchers discovered a new version of the BlackCat ransomware that embeds the Impacket networking framework and the Remcom hacking tool, both enabling spreading laterally across a breached network.

See the full report here: https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/


APT29 is targeting Ministries of Foreign Affairs of NATO-aligned countries

Russia-linked APT29 used the Zulip Chat App in attacks aimed at ministries of foreign affairs of NATO-aligned countries. Researchers uncovered an ongoing spear-phishing campaign conducted by Russia-linked threat actors targeting Ministries of Foreign Affairs of NATO-aligned countries

See the full report here: https://securityaffairs.com/149620/apt/apt29-used-zulip-chat-app.html


HC3 white paper cautions about Chinese-based hackers targeting US public, private health sector

The Health Sector Cybersecurity Coordination Center (HC3) in the U.S. Department of Health & Human Services (HHS) published a white paper that outlines Chinese cyber hackers who are known to target the U.S. public health and private health sector entities in cyberspace.

See the full report here: https://industrialcyber.co/medical/hc3-white-paper-cautions-about-chinese-based-hackers-targeting-us-public-private-health-sector/


Bronze Starlight targets the Southeast Asian gambling sector

Experts warn of an ongoing campaign attributed to China-linked Bronze Starlight that is targeting the Southeast Asian gambling sector.

See the full report here: https://securityaffairs.com/149634/apt/bronze-starlight-target-gambling-asia.html


Tags: tlp:clear,  all industries,  global, weekly bulletin