Threat Intelligence Bulletin: 08/18/2023 - 08/24/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 08/18/2023 - 08/24/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - August 24, 2023
Brief Highlights
- WinRAR Zero-Day Exploited to Target Crypto Accounts
- FBI Identifies Cryptocurrency Funds Stolen by North Korean Hackers
- Over 3,000 Openfire Servers Vulnerable to Takeover Attacks
- Data broker / initial-access broker / hacktivist group: Clop and Exploit user LuciferXfiles
- Exploits: CVE-2020-3956 and CVE-2020-14882
- Vulnerabilities: CVE-2023-40178 and CVE-2023-40185
- Leakbase: DCGpac Data Breach and XSS: Bootskram Data Breach Botnet Breach
Report: https://zerofox.com/advisories/21628
ZeroFox Daily Intelligence Brief - August 23, 2023
Brief Highlights
- Hacker Group Abuses Software Trust Model to Disguise Malware
- Akira Ransomware Compromise Enterprise VPNs to Backdoor Data Transmission
- Native Xloader Malware Highlights Increased Targeting of MacOS Devices
- Data broker / initial-access broker / hacktivist group: Cʏʙᴇʀ Cᴀᴛ and Mysterious team Bangladesh
- Exploits: CVE-2020-0796 and CVE-2020-11651
- Vulnerabilities: CVE-2023-4404 and CVE-2023-40144
- Leakbase: Everyshop Data Breach and Bootskram Data Breach Botnet Breach
Report: https://zerofox.com/advisories/21621
ZeroFox Daily Intelligence Brief - August 22, 2023
Brief Highlights
- HiatusRAT Malware Resurfaces with Attacks on Taiwanese Firms and U.S. Military
- CISA Pushes Agencies Toward “Quantum-Readiness” to Safeguard Critical Infrastructure
- Foreign Intelligence Agencies Continuously Targeting U.S. Space Industry
- Data broker / initial-access broker / hacktivist group: RAWRZ KittenSec and Exploit user “1337sh.com”
- Exploit: CVE-2019-17570
- Vulnerabilities: CVE-2023-4347 and CVE-2023-40518
- Combolist: '210k Fresh MiXeD HQ Combolist.txt' and Telegram: 'Texture Cloud PRIVATE.zip'
Report: https://zerofox.com/advisories/21608
ZeroFox Daily Intelligence Brief - August 21, 2023
Brief Highlights
- Interpol Operation Disrupts Thousands of Illicit Cyber Networks in Africa
- WinRAR Patches Remote Code Execution Flaw
- Malicious Campaign Targets Victims Through Malware Hidden in Image Files
- Data broker / initial-access broker / hacktivist group: Exploit user “Roblette”
- Exploits: CVE-2019-19781 and CVE-2017-11317
- Vulnerabilities: CVE-2023-30861 and CVE-2022-24989
- Credit Card Data Breach and Combolist: '260K.txt'
Report: https://zerofox.com/advisories/21599
ZeroFox Daily Intelligence Brief - August 18, 2023
Brief Highlights
- Criminals Share Malicious Android APKs that Evade Security Measures
- Russian Threat Actors Target Ministries of Foreign Affairs of NATO-Aligned Countries
- Researchers Demonstrate Inconspicuous Exploit in iOS devices Through Fake Airplane Mode
- Data broker / initial-access broker / hacktivist group: BreachForums user “c0wb0y5”and Mysterious Team Bangladesh
- Vulnerabilities: CCVE-2023-33934 and CVE-2023-4364
- Leakbase: CompAndSave Data Breach and Mosquiteras Data Breach
Report: https://zerofox.com/advisories/21585
Breach Disclosures:
Everyshop
An alleged data breach at Everyshop – a South Africa-based e-commerce service industry – exposed 67,759 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21610
EVO Banca Inteligente
An alleged data breach at EVO Banca Inteligente – a Spain-based financial institution that manages loans, credit cards, and personal accounts – exposed 58,459 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21609
CompAndSave
An alleged data breach at CompAndSave – a U.S.-based retailer of printer inkjet cartridge, laser toner, and, printer accessories – exposed 1,97,405 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21588
Menominee Industrial Supply
An alleged data breach at Menominee Industrial Supply – a U.S.-based company that operates in industrial machinery and equipment – exposed 1,653 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21587
Mosquiteras
An alleged data breach at Mosquiteras – a Spain-based company that operates in consumer electronics and computers retail – exposed 104,388 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21586
Breaking News:
Lapsus$ member has been convicted of having hacked multiple high-profile companies
An 18-year-old member of the Lapsus$ gang has been convicted of having helped hack multiple high-profile companies including Uber and Revolut Since September 2022, the individual conducted a series of solo attacks, gained access to around 5,000 Revolut customers’ records and hacked Uber causing around USD 3 million of damage. Then he targeted Rockstar Games and threatened to release the source code for an upcoming game.
See the full report here: https://securityaffairs.com/149821/cyber-crime/lapsus-member-convicted.html
More than 3,000 Openfire servers exposed to attacks using a new exploit
Researchers warn that more than 3,000 unpatched Openfire chat servers are exposed to attacks exploiting a recent flaw(CVE-2023-32315). CVE-2023-32315 is a path traversal vulnerability affecting the Openfire admin console. An unauthenticated user can exploit the flaw to access restricted pages in the Openfire Admin Console reserved for administrative users.
See the full report here: https://securityaffairs.com/149811/breaking-news/openfire-servers-exposed-new-exploit.html?&web_view=true
WinRAR Security Flaw Exploited in Zero-Day Attacks to Target Traders
A recently patched security flaw in the popular WinRAR archiving software has been exploited as a zero-day since April 2023. The vulnerability, cataloged as CVE-2023-38831, allows threat actors to spoof file extensions, thereby making it possible to launch malicious scripts contained within an archive that masquerades as seemingly innocuous image or text files.
See the full report here: https://thehackernews.com/2023/08/winrar-security-flaw-exploited-in-zero.html
New "Whiffy Recon" Malware Triangulates Infected Device Location via Wi-Fi Every Minute
The SmokeLoader malware is being used to deliver a new malware strain called Whiffy Recon on compromised Windows machines. The new malware strain has only one operation, every 60 seconds it triangulates the infected systems' positions by scanning nearby Wi-Fi access points as a data point for Google's geolocation API.
See the full report here: https://thehackernews.com/2023/08/new-whiffy-recon-malware-triangulates.html
Akira Ransomware Targets Cisco VPNs to Breach Organizations
There's mounting evidence that Akira ransomware targets Cisco VPN (virtual private network) products as an attack vector to breach corporate networks, steal, and eventually encrypt data.
See the full report here: https://www.bleepingcomputer.com/news/security/akira-ransomware-targets-cisco-vpns-to-breach-organizations/?&web_view=true
Scraped data of 2.6 million Duolingo users released on hacking forum
The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information.
See the full report here: https://www.bleepingcomputer.com/news/security/scraped-data-of-26-million-duolingo-users-released-on-hacking-forum/
Over a Dozen Malicious npm Packages Target Roblox Game Developers
More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token Grabber on systems belonging to Roblox developers.
See the full report here: https://thehackernews.com/2023/08/over-dozen-malicious-npm-packages.html
TP-Link Tapo L530E smart bulb flaws allow hackers to steal user passwords
Researchers from the University of Catania (Italy) and the University of London (UK) have discovered four vulnerabilities impacting the TP-Link Tapo L530E smart bulb and the mobile app TP-Link’s Tapo app, which could allow attackers to steal the users’ WiFi password.
See the full report here: https://securityaffairs.com/149783/hacking/tp-link-tapo-l530e-smart-bulb-flaws.html
Criminals go full Viking on CloudNordic, wipe all servers and customer data
CloudNordic has told customers to consider all of their data lost following a ransomware infection that encrypted the large Danish cloud provider's servers and "paralyzed CloudNordic completely," according to the IT outfit's online confession.
See the full report here: https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/
Spacecolon Toolset Fuels Global Surge in Scarab Ransomware Attacks
A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally. It ia assumed to find its way into victim organizations by its operators compromising vulnerable web servers or via brute forcing RDP credentials.
See the full report here: https://thehackernews.com/2023/08/spacecolon-toolset-fuels-global-surge.html
Snatch gang claims the hack of the Department of Defence South Africa
The Snatch ransomware group added the Department of Defence South Africa to its data leak site. The mission of the Department of Defence is to provide, manage, prepare and employ defence capabilities commensurate with the needs of South Africa, as regulated by the Constitution, national legislation, parliamentary and executive direction. The group claims to have stolen Military contracts, internal call signs and personal data, for a total of 1.6 TB of data.s.
See the full report here: https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html
New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App
A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote."
See the full report here: https://thehackernews.com/2023/08/new-variant-of-xloader-macos-malware.html
Ivanti Warns of New Actively Exploited Sentry Zero-Day Bug
The critical vulnerability enables unauthenticated attackers to gain access to sensitive admin portal configuration APIs exposed over port 8443, used by Ivanti MobileIron Configuration Service (MICS).
See the full report here: https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/?&web_view=true
Police Insider Tipped Off Criminal Friend About EncroChat Bust
An intelligence analyst working for police in the North West of England shared information about a major countrywide operation with a criminal contact, in what has been described as a “disgraceful” betrayal of her colleagues. At Liverpool Crown Court on they pleaded guilty to charges of misconduct in public office, perverting the course of justice and unauthorized access to computer material. NCA officers believe the individual revealed to a criminal not only about the operation but also that police also had intelligence on them.
See the full report here: https://www.infosecurity-magazine.com/news/police-insider-tipped-off/?&web_view=true
CISA, NSA, NIST factsheet addresses migration to post-quantum cryptography, ahead of standards rollout
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and National Institute of Standards and Technology (NIST) published a factsheet on the impacts of quantum capabilities and necessary steps to begin planning for migration to PQC (post-quantum cryptography). Titled "Quantum-Readiness: Migration to Post-Quantum Cryptography," the factsheet provides necessary steps and guidance to help organizations establish their own quantum-readiness roadmap.
See the full report here: https://industrialcyber.co/cisa/cisa-nsa-nist-factsheet-addresses-migration-to-post-quantum-cryptography-ahead-of-standards-rollout/
Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates
A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. Researchers are tracking the activity under its insect-themed moniker Carderbee. The attacks leverage a trojanized version of a legitimate software called EsafeNet Cobra DocGuard Client to deliver a known backdoor called PlugX (aka Korplug) on victim networks.
See the full report here: https://thehackernews.com/2023/08/carderbee-attacks-hong-kong.html
TP-Link Smart Bulbs can Let Hackers Steal Your WiFi Password
Researchers from Italy and the UK have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and TP-Link’s Tapo app, which could allow attackers to steal their target’s WiFi password
See the full report here: https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/?&web_view=true
CISA Warns of Another Exploited Adobe ColdFusion Vulnerability
CISA warns that CVE-2023-26359, an Adobe ColdFusion vulnerability patched in March 2034, is still being exploited in the wild. The vulnerability is known to be a critical data deserialization issue that can be exploited for arbitrary code execution.
See the full report here: https://www.securityweek.com/cisa-warns-of-another-exploited-adobe-coldfusion-vulnerability/
Australian Software Provider Energy One Hit by Cyberattack
Wholesale energy software provider Energy One reported that a cyberattack had affected "certain corporate systems" in Australia and the UK. In a statement, the company said analysis is underway to identify which systems have been affected.
See the full report here: https://www.darkreading.com/dr-global/energy-one-investigates-cyberattack?&web_view=true
Cyberattack on UK IT Firm Swan Retail Affects 300 Retailers
Hundreds of impacted retailers in the UK could not process payments, complete orders, or trade online due to the attack on Swan Retail. According to a statement from the company’s representative, its systems were targeted by an unauthorized third party to which the company responded quickly by alerting its internal IT team, affiliated retailers, and law enforcement authorities.
See the full report here: https://www.hackread.com/cyberattack-uk-swan-retail-affects-retailers/
WinRAR flaw enables remote code execution of arbitrary code
A flaw impacting the file archiver utility for Windows WinRAR can allow the execution of commands on a computer by opening an archive. WinRAR is a popular file compression and archival utility for Windows operating systems. The utility is affected by a now-fixed high-severity vulnerability, tracked as CVE-2023-40477 (CVSS score 7.8), that can allow remote execution of arbitrary code on a computer by opening a crafted RAR archive. WinRAR addressed the flaw with the release of version 6.23.
See the full report here: https://securityaffairs.com/149670/hacking/winrar-rce.html
N. Korean Kimsuky APT targets S. Korea-US military exercises
Hackers believed to be linked to a North Korean group dubbed Kimsuky — carried out “continuous malicious email attacks” on South Korean contractors working at the allies’ combined exercise war simulation centre, the Gyeonggi Nambu Provincial Police Agency said in a statement. Police investigation confirms that North Korean hacking group was responsible for the attack,” it said in a statement, adding that military-related information was not stolen.
See the full report here: https://securityaffairs.com/149698/apt/kimsuky-war-simulation-centre.html
US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry
US agencies have indicated that threat actors, may leak intellectual property and steal innovations, collect information on and disrupt US satellite communications and related capabilities, impact the US’s ability to provide critical services, and find and exploit vulnerabilities in US commercial space infrastructure.
See the full report here: https://www.securityweek.com/us-gov-warns-of-foreign-intelligence-cyberattacks-against-us-space-industry/
WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams
Cybersecurity researchers have detailed an updated version of an advanced fingerprinting and redirection toolkit called WoofLocker that's engineered to conduct tech support scams. This redirection mechanism, in turn, makes use of steganographic tricks to conceal the JavaScript code within a PNG image that's served only when the validation phase is successful.
See the full report here: https://thehackernews.com/2023/08/wooflocker-toolkit-hides-malicious.html
Interpol arrest 14 who allegedly scammed USD 40 million from victims
An Interpol-led operation arrested 14 suspects and identified 20,674 "suspicious" networks spanning 25 African countries that international cops have linked to more than USD 40 million in cybercrime losses. Africa Cyber Surge II, a combined police operation which began in April 2023 and lasted four months, was a coordinated effort between Interpol, African law enforcement, and private-sector security firms to disrupt online extortion, phishing, business email compromise (BEC) and other cyber scam
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/08/20/interpol_africa_arrests/
New Juniper Junos OS Flaws Expose Devices to Remote Attacks
Networking appliances maker Juniper Networks announced patches for four vulnerabilities in the J-Web interface of Junos OS, which could be combined for unauthenticated, remote code execution.
See the full report here: https://thehackernews.com/2023/08/new-juniper-junos-os-flaws-expose.html
Hackers Pocket USD 50,000 for Exploiting US Air Force Defenses
A security exercise was conducted during the annual "Hack-A-Sat" competition within the US Air Force during which hackers managed to successfully compromise a satellite in orbit. MHACKeroni, an Italian team that emerged as the winner of the competition, won a prize of USD 50,000 for the discovery of vulnerabilities within the satellite's network systems which allowed them to reveal the vulnerabilities.
See the full report here: https://www.cysecurity.news/2023/08/satellite-security-breached-hackers.html
Tesla Discloses Data Breach Related to Whistleblower Leak
Tesla has disclosed a data breach impacting roughly 75,000 people, but the incident is the result of a whistleblower leak rather than a malicious cyberattack. Tesla told US authorities that a data breach discovered in May 2023 resulted in the exposure of the personal information, including social security numbers, of more than 75,700 individuals
See the full report here: https://www.securityweek.com/tesla-discloses-data-breach-related-to-whistleblower-leak/
Play' Ransomware Group Targeting MSPs Worldwide in New Campaign
The fast-rising Play ransomware group that targeted the City of Oakland is now hitting managed service providers (MSPs) around the globe in a cyberattack campaign to distribute ransomware to their downstream customers.
See the full report here: https://www.darkreading.com/cloud/-play-ransomware-group-targeting-msps-worldwide-in-new-campaign
Experts devise an exploit for Apple iOS 16 that relies on fake Airplane Mode
Researchers developed a post-exploit persistence technique on iOS 16 that trick victims into believing that the device is in functional Airplane Mode
See the full report here: https://securityaffairs.com/149597/mobile-2/airplane-mode-apple-ios-16-exploit.html
Malicious QR Codes Used in Phishing Attack Targeting US Energy Company
A widespread phishing campaign ongoing since May 2023 has been targeting organizations in various industries, including a major US energy company. Aimed at harvesting the Microsoft account credentials of the targeted organizations’ employees, the attacks rely on malicious QR codes embedded inside PNG images or PDF documents.
See the full report here: https://www.securityweek.com/malicious-qr-codes-used-in-phishing-attack-targeting-us-energy-company/
NoFilter Attack: Sneaky Privilege Escalation Method Bypasses Windows Security
A previously undetected attack method called NoFilter has been found to abuse the Windows Filtering Platform (WFP) to achieve privilege escalation in the Windows operating system.
See the full report here: https://thehackernews.com/2023/08/nofilter-attack-sneaky-privilege.html
White House Orders Federal Agencies to Bolster Cyber Safeguards
The White House has ordered federal agencies to get their cybersecurity safeguards up to date as they lag in their ability to implement President Biden's executive order, issued in 2021. A public memo stated that multiple federal agencies and departments have "failed to fully comply" with the critical security practices that were detailed in the executive order.
See the full report here: https://www.darkreading.com/attacks-breaches/white-house-orders-federal-agencies-to-bolster-cyber-safeguards
Researchers discover new BlackCat ransomware version
Researchers discovered a new version of the BlackCat ransomware that embeds the Impacket networking framework and the Remcom hacking tool, both enabling spreading laterally across a breached network.
See the full report here: https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/
APT29 is targeting Ministries of Foreign Affairs of NATO-aligned countries
Russia-linked APT29 used the Zulip Chat App in attacks aimed at ministries of foreign affairs of NATO-aligned countries. Researchers uncovered an ongoing spear-phishing campaign conducted by Russia-linked threat actors targeting Ministries of Foreign Affairs of NATO-aligned countries
See the full report here: https://securityaffairs.com/149620/apt/apt29-used-zulip-chat-app.html
HC3 white paper cautions about Chinese-based hackers targeting US public, private health sector
The Health Sector Cybersecurity Coordination Center (HC3) in the U.S. Department of Health & Human Services (HHS) published a white paper that outlines Chinese cyber hackers who are known to target the U.S. public health and private health sector entities in cyberspace.
See the full report here: https://industrialcyber.co/medical/hc3-white-paper-cautions-about-chinese-based-hackers-targeting-us-public-private-health-sector/
Bronze Starlight targets the Southeast Asian gambling sector
Experts warn of an ongoing campaign attributed to China-linked Bronze Starlight that is targeting the Southeast Asian gambling sector.
See the full report here: https://securityaffairs.com/149634/apt/bronze-starlight-target-gambling-asia.html
Tags: tlp:clear, all industries, global, weekly bulletin