zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 29, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 29, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Mom’s Meals Data Breach Affects 1.2 Million People
  • Flax Typhoon Using LOLBins to Evade Detection
  • MalDoc in PDF: Detection Bypass by Embedding a Malicious Word File into a PDF File
  • Data broker / initial-access broker / hacktivist group: Exploit user KimData and GhostSec
  • Exploits: CVE-2021-29337 and CVE-2021-26708
  • Vulnerabilities: CVE-2023-4558 and CVE-2023-41360
  • Credit Card Data Breach and Combolist

Mom’s Meals Data Breach Affects 1.2 Million People

A ransomware attack in early 2023 compromised the personal information—including details of driver’s license, financial and medical information, and even Social Security numbers in some cases—of 1.2 million clients, past/present employees, and independent contractors of Mom’s Meals (PurFoods). As the exposed data is extremely sensitive, affected people should remain vigilant against phishing and social-engineering attacks and be cautious when responding to potentially malicious communications (via call, email, or text).

Malicious Rust Libraries Caught Transmitting OS Info to Telegram

Malicious packages were discovered (and subsequently removed) in Rust programming language's crate registry. The malicious packages were uploaded by user "amaperf" between August 14 and 16, 2023 and affected postgress, if-cfg, xrvrv, serd, oncecell, lazystatic, and envlogger. They aimed at capturing OS data and sending it to a Telegram channel. Researchers noted the similarity of the attack to an earlier campaign targeting the Rust crate registry as well as another attack targeting npm packages.

MalDoc in PDF: Detection Bypass by Embedding a Malicious Word File into a PDF File

Japanese cybersecurity officials have disclosed a novel attack technique, "MalDoc in PDF,” that bypasses detection via polyglot (files which contain two different formats) technique. A file using “MalDoc in PDF” appears as a PDF but opens in Word, triggering harmful VBS macros. Though the file is recognized as a PDF, simpler analysis tools like pdfid struggle to identify its threat while multi-layered tools like OLEVBA can detect the embedded macros. The attack does not bypass settings that disable auto-execution of macros.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

EXPLOITS

VULNERABILITIES

  • CVE-2023-4558 - A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0.
  • CVE-2023-41360 - An issue was discovered in FRRouting FRR through 9.0.

BREACHES

Tags: DIB, tlp:green