zerofox logo
Advisories

ZeroFox Weekly Threat Bulletin: 08/25/2023 - 08/31/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 08/25/2023 - 08/31/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - August 31, 2023

Brief Highlights

  • Breach Hits Forever 21 Employees Enrolled in Firm’s Health Plan
  • Stealthy Threat Actor Steals Data from Governments and International Organizations
  • Cybercriminals Employ Various Tactics to Compromise Airbnb Accounts
  • Data broker / initial-access broker / hacktivist group: Exploit user “Invisables” and Mysterious Team Bangladesh, Team_insane_pk official, and Cyb3r Drag0nz
  • Vulnerabilities: CVE-2023-40901 and CVE-2023-41163
  • Exploits: CVE-2021-26084 and CVE-2017-9101
  • Combolist: '50x NordVpn.txt' (66 Records) and BreachForums/XSS: BitcoinSecurity Data Leak (9,401,440 Records)

Report: https://zerofox.com/advisories/21667


ZeroFox Daily Intelligence Brief - August 30, 2023

Brief Highlights

  • Qakbot Malware Disrupted in International Cyber Takedown
  • Barracuda Zero-Day Used to Spy on Government, Military, and Telecom Bodies
  • Potential Cyberattack Disrupts Operations at the University of Michigan
  • Data broker / initial-access broker / hacktivist group: Exploit user “yesdaddy” and “The Five Families”
  • Vulnerabilities: CVE-2021-41803 and CVE-2022-3064
  • Exploits: CVE-2017-7529 and CVE-2017-9841
  • Breaches: BreachForums: Dex Forum Data Breach (68,002 Records) and Truecaller Data Breach (66,692,746 Records)

Report: https://zerofox.com/advisories/21657


ZeroFox Daily Intelligence Brief - August 29, 2023

Brief Highlights

  • Mom’s Meals Data Breach Affects 1.2 Million People
  • Flax Typhoon Using LOLBins to Evade Detection
  • MalDoc in PDF: Detection Bypass by Embedding a Malicious Word File into a PDF File
  • Data broker / initial-access broker / hacktivist group: Exploit user KimData and GhostSec
  • Exploits: CVE-2021-29337 and CVE-2021-26708
  • Vulnerabilities: CVE-2023-4558 and CVE-2023-41360
  • Credit Card Data Breach and Combolist

Report: https://zerofox.com/advisories/21650


ZeroFox Daily Intelligence Brief - August 28, 2023

Brief Highlights

  • Metropolitan Police on High Alert After Supplier IT Security Breach
  • Flax Typhoon Using LOLBins to Evade Detection
  • Cloud and Hosting Provider Leaseweb Took Down Critical Systems After a Cyberattack
  • Data broker / initial-access broker / hacktivist group: Explot user: Roblette and maveboy
  • Exploits: CVE-2020-8840
  • Vulnerabilities: CVE-2023-38026 and CVE-2023-20197
  • Leakbase: Ethnigo Data Breach and BreachForums: David Fischman Data Breach

Report: https://zerofox.com/advisories/21638


ZeroFox Daily Intelligence Brief - August 25, 2023

Brief Highlights

  • Suspected Chinese Hackers Continue to Exploit Barracuda ESG Zero-Day
  • Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
  • “Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
  • Data broker / initial-access broker / hacktivist group: Cyb3r Drag0nz and BreachForums user AMLO
  • Exploits: CVE-2020-1958 and CVE-2020-5902
  • Vulnerabilities: CVE-2023-40530 and CVE-2023-39801
  • Combolist: '170K COMBOLIST ITALY.txt' and Telegram: 18.07 google.rar'

Report: https://zerofox.com/advisories/21634


ZeroFox Daily Intelligence Brief - August 25, 2023

Brief Highlights

  • WinRAR Zero-Day Exploited to Target Crypto Accounts
  • Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
  • “Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
  • Data broker / initial-access broker / hacktivist group: Cyb3r Drag0nz and BreachForums user AMLO
  • Exploits: CVE-2020-1958 and CVE-2020-5902
  • Vulnerabilities: CVE-2023-40530 and CVE-2023-39801
  • Combolist: '170K COMBOLIST ITALY.txt' and Telegram: 18.07 google.rar'

Report: https://zerofox.com/advisories/21633


Breach Disclosures:


Ethnigo

An alleged data breach at Ethnigo – an India-based online shopping platform – exposed 42,673 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21641


David Fischman

An alleged data breach at David Fischman – a Peru-based author's website – exposed 33,151 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21640


DCGpac

An alleged data breach at DCGpac – an India-based online retail store for packaging materials and office stationery supplies – exposed 44,261 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21639


Bureau van Dijk

An alleged data breach at Bureau van Dijk – a Belgium-based publisher of business information – exposed 11,677 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21637


JD Group

An alleged data breach at JD Group – a South Africa-based retailer and consumer finance company – exposed 465,888 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21636


Breaking News:


Chinese Group Spreads Android Spyware Via Trojan Signal, Telegram Apps

Thousands of devices have become infected with "BadBazaar," malware previously used to spy on Uyghur and Turkic ethnic minorities in China and which is spread through duplictious messaging apps.

See the full report here: https://www.darkreading.com/attacks-breaches/china-group-spreads-android-spyware-via-trojan-signal-telegram-apps


Paramount discloses data breach following security incident

American entertainment giant Paramount Global disclosed a data breach after its systems got hacked and attackers gained access to personally identifiable information (PII).

See the full report here: https://www.bleepingcomputer.com/news/security/paramount-discloses-data-breach-following-security-incident/


Crooks Using Stealers and Stolen Cookies to Hack Airbnb Accounts

Researchers warned that cybercriminals are using a variety of methods, including stealers and stolen cookies, to gain unauthorized access to Airbnb accounts and carry out fraudulent activities.

See the full report here: https://www.hackread.com/cybercrooks-hack-airbnb-accounts-stealers-cookies/?&web_view=true


Abusing Windows Container Isolation Framework to avoid detection by security products

Researchers demonstrated how attackers can abuse the Windows Container Isolation Framework to bypass endpoint security solutions. Researchers at the recent DEF CON hacking conference demonstrated how attackers can abuse the Windows Container Isolation Framework to bypass endpoint security solutions. The expert explained that Windows OS separates the file system from each container to the host and avoids duplication of system files.

See the full report here: https://securityaffairs.com/150111/hacking/windows-container-isolation-framework-abuse.html


National Safety Council data leak: Credentials of NASA, Tesla, DoJ, Verizon, and 2K others leaked by workplace safety organization

The National Safety Council leaked thousands of emails and passwords of their members, including companies such as NASA and Tesla. The National Safety Council has leaked nearly 10,000 emails and passwords of their members, exposing 2000 companies, including governmental organizations and big corporations.

See the full report here: https://securityaffairs.com/150138/security/nasa-tesla-doj-verizon-2k-leaks.html


Hacking Campaign Brute-Forces Cisco VPNs to Breach Networks

Hackers are targeting Cisco Adaptive Security Appliance (ASA) SSL VPNs in credential stuffing and brute-force attacks that take advantage of lapses in security defenses, such as not enforcing multi-factor authentication (MFA).

See the full report here: https://www.bleepingcomputer.com/news/security/hacking-campaign-bruteforces-cisco-vpns-to-breach-networks/?&web_view=true


Earth Estries' Espionage Campaign Targets Governments and Tech Titans Across Continents

A hacking outfit nicknamed Earth Estries has been attributed to a new, ongoing cyber espionage campaign targeting government and technology industries based in the Philippines, Taiwan, Malaysia, South Africa, Germany, and the U.S. The threat actors behind Earth Estries are working with high-level resources and functioning with sophisticated skills and experience in cyber espionage and illicit.

See the full report here: https://thehackernews.com/2023/08/earth-estries-espionage-campaign.html


Gangs Forcing Hundreds of Thousands of People Into Cybercrime in South-East Asia, Says UN

Hundreds of thousands of people have been trafficked and forced to work for online scamming operations in south-east Asia run by criminal gangs, according to a UN report.

See the full report here: https://www.theguardian.com/global-development/2023/aug/30/gangs-forcing-hundreds-of-thousands-of-people-into-cybercrime-in-south-east-asia-says-un?&web_view=true


Hackers can Exploit Windows Container Isolation Framework to Bypass Endpoint Security

New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.

See the full report here: https://thehackernews.com/2023/08/hackers-can-exploit-windows-container.html?&web_view=true


Hackers exploit critical Juniper RCE bug chain after PoC release

Hackers are using a critical exploit chain to target Juniper EX switches and SRX firewalls via their Internet-exposed J-Web configuration interface. Successful exploitation enables unauthenticated attackers to remotely execute code on unpatched devices. Admins are advised to apply patches or upgrade JunOS to the latest release immediately or, at least, disable Internet access to the J-Web interface to remove the attack vector.

See the full report here: <bleepingcomputer.com/news/security/hackers-exploit-critical-juniper-rce-bug-chain-after-poc-release/>


New Android MMRat malware uses Protobuf protocol to steal your data

A novel Android banking malware named MMRat uses a rarely used communication method, protobuf data serialization, to more efficiently steal data from compromised devices. Security researchers observed that MMRat is distributed via websites disguised as official app stores. MMRat uses a unique command and control (C2) server protocol based on protocol buffers (Protobuf) for efficient data transfer, which is uncommon among Android trojans. MMRat shows the evolving sophistication of Android banking trojans, adeptly blending stealth with efficient data extraction.

See the full report here: https://www.bleepingcomputer.com/news/security/new-android-mmrat-malware-uses-protobuf-protocol-to-steal-your-data/


DreamBus malware exploits RocketMQ flaw to infect servers

A new version of the DreamBus botnet malware exploits a critical-severity remote code execution vulnerability (CVE-2023-33246) in RocketMQ servers to infect devices. The exploited flaw is a permission verification issue that impacts RocketMQ version 5.1.0 and older, allowing attackers to perform remote command execution under certain conditions. RockerMQ administrators upgrade to version 5.1.1 or later stop the latest DreamBus attacks.

See the full report here: https://www.bleepingcomputer.com/news/security/dreambus-malware-exploits-rocketmq-flaw-to-infect-servers/


University of Michigan shuts down network after cyberattack

The University of Michigan (U-M) has disconnected its network from the internet to deal with a cybersecurity-related technical issue on the eve of the new academic year. The university had not yet restored wiFi and internet access in the campus at the time of writing. Because of the challenges posed by the connectivity outage, students will not incur late registration or disenrollment fees through the month of August. U-M stated that financial aid refunds may be delayed due to the system outage.

See the full report here: https://www.bleepingcomputer.com/news/security/university-of-michigan-shuts-down-network-after-cyberattack/


Qakbot botnet dismantled after infecting over 700,000 computers

A multinational operation has disrupted operations of Qakbot botnet and malware, dismantled its infrastructure, and confiscated illicit profits worth over USD 8.6 million. Law-enforcement officials also launched an aggressive campaign to uninstall the malware from over 700,000 victim computers (with the United States alone accounting for over 200,000). Qakbot was used by ransomware groups such as Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta as an initial means of infection to target businesses, healthcare providers, and government agencies across the world.

See the full report here: https://www.bleepingcomputer.com/news/security/qakbot-botnet-dismantled-after-infecting-over-700-000-computers/


Phishing-as-a-Service Gets Smarter: Security Researchers Sound Alarm on AiTM Attacks

Threat intelligence researchers are warning of an increase in adversary-in-the-middle phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model. The ultimate goal of such attacks is to siphon session cookies, enabling threat actors to access privileged systems without reauthentication.

See the full report here: https://thehackernews.com/2023/08/phishing-as-service-gets-smarter.html


Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom

A China-linked hacking group exploited a zero-day flaw (CVE-2023-2868) in Barracuda Networks Email Security Gateway (ESG) appliances to spy on government, military, defense and aerospace, high-tech industry, and telecom firms. Barracuda recommends that impacted customers replace their compromised appliances, and is providing the replacement product to impacted customers at no cost. CISA has released additional indicators of compromise (IOCs) associated with the exploitation of this remote command injection vulnerability.

See the full report here: https://thehackernews.com/2023/08/chinese-hacking-group-exploits.html


DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates

A new malspam campaign has been observed deploying an off-the-shelf malware called DarkGate. DarkGate, sold mainly on underground forums by an actor named RastaFarEye, comes with capabilities to evade detection by security software, set up persistence using Windows Registry changes, escalate privileges, and steal data from web browsers and other software such as Discord and FileZilla.

See the full report here: https://thehackernews.com/2023/08/darkgate-malware-activity-spikes-as.html


Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks

VMware has released software updates to correct two security vulnerabilities — CVE-2023-34039 (CVSS score: 9.8) and CVE-2023-20890 (CVSS score: 7.2) — in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution. The company said that version 6.11.0 comes with fixes for the two flaws.

See the full report here: https://thehackernews.com/2023/08/critical-vulnerability-alert-vmware.html


Attackers can Discover IP Addresses by Sending Links Over the Skype Mobile App

A security researcher discovered that it's possible to discover a target’s IP address by sending a link over the Skype mobile app. The researcher pointed out that the attack only requires the target to open the message.

See the full report here: https://securityaffairs.com/150000/hacking/grabbing-ip-addr-via-skype-mobile-app.html?web_view=true


Japan's JPCERT Warns of New "MalDoc in PDF" Attack Technique

Japan’s computer emergency response team (JPCERT) has recently observed a new attack technique, called "MalDoc in PDF", that bypasses detection by embedding a malicious Word file into a PDF file.

See the full report here: https://securityaffairs.com/150012/hacking/maldoc-in-pdf-attack.html?&web_view=true


FIN8-linked actor targets Citrix NetScaler systems

A financially motivated actor linked to the FIN8 group exploits the CVE-2023-3519 RCE in attacks on Citrix NetScaler systems in massive attacks.The hackers are exploiting the remote code execution, tracked as CVE-2023-3519, in a large-scale campaign.

See the full report here: https://securityaffairs.com/150028/hacking/fin8-citrix-netscaler.html


Researchers Sounds Alarm on AiTM Attacks

Researchers are warning of an increase in adversary-in-the-middle (AiTM) phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model.

See the full report here: https://thehackernews.com/2023/08/phishing-as-service-gets-smarter.html?&web_view=true


Spainish Police Warns of LockBit Locker Ransomware Phishing Attacks

Spanish Police warned about the wave of attacker-sent phishing emails to architecture companies, although it is not ruled out that they extend their action to other sectors.

See the full report here: https://www.bleepingcomputer.com/news/security/spain-warns-of-lockbit-locker-ransomware-phishing-attacks/?&web_view=true


Meta: Pro-Chinese influence operation was the largest in history

Meta stated that the company had taken down what officials at the firm describe as the largest ever “cross-platform covert influence operation in the world,” which featured thousands of accounts pushing pro-Chinese messages across online platforms. The operation in question targeted audiences in Taiwan, the United States, Australia, the United Kingdom, Japan and the global Chinese-speaking population with messages across more than 50 platforms.

See the full report here: https://cyberscoop.com/meta-china-influence-operation-facebook/


Cloud and hosting provider Leaseweb took down critical systems after a cyber attack

Global hosting and cloud services provider Leaseweb has disabled some “critical” systems following a recent security breach. The company informed its customers that is now working on restoring these systems. According to a notice of incident sent to customers, on August 22 2023, the company discovered “unusual” activity in some of its systems while investigating Customer Portal downtime issues.

See the full report here: https://securityaffairs.com/149897/hacking/leaseweb-cyber-attack.html


IT Contractor Data Breach Affects 47,000 Met Police Personnel

The Metropolitan Police Force is currently dealing with an extensive data breach involving the personal information of its officers and staff. The breach has exposed the details of all 47,000 personnel, raising concerns about their safety and operational integrity. The data breach was discovered after cybercriminals penetrated the IT systems of a contractor responsible for printing warrant cards and staff passes, and has left the Metropolitan Police Force on high alert.

See the full report here: https://www.hackread.com/it-contractor-data-breach-met-police-personnel/


Rhysida claims ransomware attack on Prospect Medical, threatens to sell data

The Rhysida ransomware gang has claimed responsibility for the massive cyberattack on Prospect Medical Holdings, claiming to have stolen 500,000 social security numbers, corporate documents, and patient records.

See the full report here: https://www.bleepingcomputer.com/news/security/rhysida-claims-ransomware-attack-on-prospect-medical-threatens-to-sell-data/


Leaked LockBit 3.0 Ransomware Builder Used by Multiple Actors

Lockbit v3, aka Lockbit Black, was detected in June 2022, but in September 2022 a builder for this variant was leaked online. The availability of the builder allowed anyone to create their own customized version of the ransomware.

See the full report here: https://securityaffairs.com/149941/hacking/lockbit-3-leaked-code-usage.html?&web_view=true


Microsoft detects Flax Typhoon hackers using legitimate software to snoop on Taiwanese organizations

Researchers have identified a nation-state activity group tracked as Flax Typhoon, based in China, that is targeting dozens of organizations in Taiwan with the likely intention of performing espionage. Flax Typhoon gains and maintains long-term access to Taiwanese organizations’ networks with minimal use of malware, relying on tools built into the operating system

See the full report here: https://industrialcyber.co/critical-infrastructure/microsoft-detects-flax-typhoon-hackers-using-legitimate-software-to-snoop-on-taiwanese-organizations/


Polish Authorities Investigate Hacking Attack on Local Railways

Threat actors transmitted a signal triggering an emergency status that stopped the trains near the city of Szczecin in Poland. According to the media, the attack stopped at least 20 trains and paralyzed the traffic for hours.

See the full report here: https://securityaffairs.com/149952/hacking/hacking-attack-polan-railways.html?&web_view=true


Updated Kmsdx botnet version targets IoT devices

Researchers spotted an updated version of the KmsdBot botnet that is now targeting Internet of Things (IoT) devices. The malicious code was used in attacks targeting multiple sectors including the gaming industry, technology industry, and luxury car manufacturers

See the full report here: https://securityaffairs.com/149970/cyber-crime/kmsdbot-botnet-new-version.html


Researchers Discover Reply URL Takeover Flaw in Azure

Security researchers are urging Azure Active Directory (AD) users to monitor for abandoned reply URLs after revealing a critical vulnerability in the Microsoft Power Platform. Attackers could use the URL to redirect authorization codes to themselves, exchanging these for access tokens. The threat actor could then call the Power Platform API via a middle-tier service and obtain elevated privileges.

See the full report here: https://www.infosecurity-magazine.com/news/reply-url-takeover-issue-azure/?&web_view=true


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report - Political Instability in West Africa

In this flash report, ZeroFox geopolitical researchers provide updates on the recent political instability occurring throughout West Africa, including an overview of what led to these developments and potential outcomes.

Report: https://zerofox.com/advisories/21677


Tags: tlp:clear, weekly bulletin, all industries, global