zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 30, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 30, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Qakbot Malware Disrupted in International Cyber Takedown
  • Barracuda Zero-Day Used to Spy on Government, Military, and Telecom Bodies
  • Potential Cyberattack Disrupts Operations at the University of Michigan
  • Data broker / initial-access broker / hacktivist group: Exploit user “yesdaddy” and “The Five Families”
  • Vulnerabilities: CVE-2021-41803 and CVE-2022-3064
  • Exploits: CVE-2017-7529 and CVE-2017-9841
  • Breaches: BreachForums: Dex Forum Data Breach (68,002 Records) and Truecaller Data Breach (66,692,746 Records)

Qakbot Malware Disrupted in International Cyber Takedown

A multinational operation has disrupted operations of Qakbot botnet and malware, dismantled its infrastructure, and confiscated illicit profits worth over USD 8.6 million. Law-enforcement officials also launched an aggressive campaign to uninstall the malware from over 700,000 victim computers (with the United States alone accounting for over 200,000). Qakbot was used by ransomware groups such as Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta as an initial means of infection to target businesses, healthcare providers, and government agencies across the world.

Barracuda Zero-Day Used to Spy on Government, Military, and Telecom Bodies

A China-linked hacking group exploited a zero-day flaw (CVE-2023-2868) in Barracuda Networks Email Security Gateway (ESG) appliances to spy on government, military, defense and aerospace, high-tech industry, and telecom firms. Barracuda recommends that impacted customers replace their compromised appliances, and is providing the replacement product to impacted customers at no cost. CISA has released additional indicators of compromise (IOCs) associated with the exploitation of this remote command injection vulnerability.

Potential Cyberattack Disrupts Operations at the University of Michigan

The University of Michigan (U-M) has disconnected its network from the internet to deal with a cybersecurity-related technical issue on the eve of the new academic year. The university had not yet restored wiFi and internet access in the campus at the time of writing. Because of the challenges posed by the connectivity outage, students will not incur late registration or disenrollment fees through the month of August. U-M stated that financial aid refunds may be delayed due to the system outage.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2021-41803: HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC.
  • CVE-2022-3064: Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

EXPLOITS

BREACHES

Tags: DIB, tlp:green