ZeroFox Weekly Threat Bulletin: 08/25/2023 - 08/31/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 08/25/2023 - 08/31/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - August 31, 2023
Brief Highlights
- Breach Hits Forever 21 Employees Enrolled in Firm’s Health Plan
- Stealthy Threat Actor Steals Data from Governments and International Organizations
- Cybercriminals Employ Various Tactics to Compromise Airbnb Accounts
- Data broker / initial-access broker / hacktivist group: Exploit user “Invisables” and Mysterious Team Bangladesh, Team_insane_pk official, and Cyb3r Drag0nz
- Vulnerabilities: CVE-2023-40901 and CVE-2023-41163
- Exploits: CVE-2021-26084 and CVE-2017-9101
- Combolist: '50x NordVpn.txt' (66 Records) and BreachForums/XSS: BitcoinSecurity Data Leak (9,401,440 Records)
Report: https://zerofox.com/advisories/21667
ZeroFox Daily Intelligence Brief - August 30, 2023
Brief Highlights
- Qakbot Malware Disrupted in International Cyber Takedown
- Barracuda Zero-Day Used to Spy on Government, Military, and Telecom Bodies
- Potential Cyberattack Disrupts Operations at the University of Michigan
- Data broker / initial-access broker / hacktivist group: Exploit user “yesdaddy” and “The Five Families”
- Vulnerabilities: CVE-2021-41803 and CVE-2022-3064
- Exploits: CVE-2017-7529 and CVE-2017-9841
- Breaches: BreachForums: Dex Forum Data Breach (68,002 Records) and Truecaller Data Breach (66,692,746 Records)
Report: https://zerofox.com/advisories/21657
ZeroFox Daily Intelligence Brief - August 29, 2023
Brief Highlights
- Mom’s Meals Data Breach Affects 1.2 Million People
- Flax Typhoon Using LOLBins to Evade Detection
- MalDoc in PDF: Detection Bypass by Embedding a Malicious Word File into a PDF File
- Data broker / initial-access broker / hacktivist group: Exploit user KimData and GhostSec
- Exploits: CVE-2021-29337 and CVE-2021-26708
- Vulnerabilities: CVE-2023-4558 and CVE-2023-41360
- Credit Card Data Breach and Combolist
Report: https://zerofox.com/advisories/21650
ZeroFox Daily Intelligence Brief - August 28, 2023
Brief Highlights
- Metropolitan Police on High Alert After Supplier IT Security Breach
- Flax Typhoon Using LOLBins to Evade Detection
- Cloud and Hosting Provider Leaseweb Took Down Critical Systems After a Cyberattack
- Data broker / initial-access broker / hacktivist group: Explot user: Roblette and maveboy
- Exploits: CVE-2020-8840
- Vulnerabilities: CVE-2023-38026 and CVE-2023-20197
- Leakbase: Ethnigo Data Breach and BreachForums: David Fischman Data Breach
Report: https://zerofox.com/advisories/21638
ZeroFox Daily Intelligence Brief - August 25, 2023
Brief Highlights
- Suspected Chinese Hackers Continue to Exploit Barracuda ESG Zero-Day
- Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
- “Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
- Data broker / initial-access broker / hacktivist group: Cyb3r Drag0nz and BreachForums user AMLO
- Exploits: CVE-2020-1958 and CVE-2020-5902
- Vulnerabilities: CVE-2023-40530 and CVE-2023-39801
- Combolist: '170K COMBOLIST ITALY.txt' and Telegram: 18.07 google.rar'
Report: https://zerofox.com/advisories/21634
ZeroFox Daily Intelligence Brief - August 25, 2023
Brief Highlights
- WinRAR Zero-Day Exploited to Target Crypto Accounts
- Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
- “Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
- Data broker / initial-access broker / hacktivist group: Cyb3r Drag0nz and BreachForums user AMLO
- Exploits: CVE-2020-1958 and CVE-2020-5902
- Vulnerabilities: CVE-2023-40530 and CVE-2023-39801
- Combolist: '170K COMBOLIST ITALY.txt' and Telegram: 18.07 google.rar'
Report: https://zerofox.com/advisories/21633
Breach Disclosures:
Ethnigo
An alleged data breach at Ethnigo – an India-based online shopping platform – exposed 42,673 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21641
David Fischman
An alleged data breach at David Fischman – a Peru-based author's website – exposed 33,151 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21640
DCGpac
An alleged data breach at DCGpac – an India-based online retail store for packaging materials and office stationery supplies – exposed 44,261 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21639
Bureau van Dijk
An alleged data breach at Bureau van Dijk – a Belgium-based publisher of business information – exposed 11,677 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21637
JD Group
An alleged data breach at JD Group – a South Africa-based retailer and consumer finance company – exposed 465,888 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21636
Breaking News:
Chinese Group Spreads Android Spyware Via Trojan Signal, Telegram Apps
Thousands of devices have become infected with "BadBazaar," malware previously used to spy on Uyghur and Turkic ethnic minorities in China and which is spread through duplictious messaging apps.
See the full report here: https://www.darkreading.com/attacks-breaches/china-group-spreads-android-spyware-via-trojan-signal-telegram-apps
Paramount discloses data breach following security incident
American entertainment giant Paramount Global disclosed a data breach after its systems got hacked and attackers gained access to personally identifiable information (PII).
See the full report here: https://www.bleepingcomputer.com/news/security/paramount-discloses-data-breach-following-security-incident/
Crooks Using Stealers and Stolen Cookies to Hack Airbnb Accounts
Researchers warned that cybercriminals are using a variety of methods, including stealers and stolen cookies, to gain unauthorized access to Airbnb accounts and carry out fraudulent activities.
See the full report here: https://www.hackread.com/cybercrooks-hack-airbnb-accounts-stealers-cookies/?&web_view=true
Abusing Windows Container Isolation Framework to avoid detection by security products
Researchers demonstrated how attackers can abuse the Windows Container Isolation Framework to bypass endpoint security solutions. Researchers at the recent DEF CON hacking conference demonstrated how attackers can abuse the Windows Container Isolation Framework to bypass endpoint security solutions. The expert explained that Windows OS separates the file system from each container to the host and avoids duplication of system files.
See the full report here: https://securityaffairs.com/150111/hacking/windows-container-isolation-framework-abuse.html
National Safety Council data leak: Credentials of NASA, Tesla, DoJ, Verizon, and 2K others leaked by workplace safety organization
The National Safety Council leaked thousands of emails and passwords of their members, including companies such as NASA and Tesla. The National Safety Council has leaked nearly 10,000 emails and passwords of their members, exposing 2000 companies, including governmental organizations and big corporations.
See the full report here: https://securityaffairs.com/150138/security/nasa-tesla-doj-verizon-2k-leaks.html
Hacking Campaign Brute-Forces Cisco VPNs to Breach Networks
Hackers are targeting Cisco Adaptive Security Appliance (ASA) SSL VPNs in credential stuffing and brute-force attacks that take advantage of lapses in security defenses, such as not enforcing multi-factor authentication (MFA).
See the full report here: https://www.bleepingcomputer.com/news/security/hacking-campaign-bruteforces-cisco-vpns-to-breach-networks/?&web_view=true
Earth Estries' Espionage Campaign Targets Governments and Tech Titans Across Continents
A hacking outfit nicknamed Earth Estries has been attributed to a new, ongoing cyber espionage campaign targeting government and technology industries based in the Philippines, Taiwan, Malaysia, South Africa, Germany, and the U.S. The threat actors behind Earth Estries are working with high-level resources and functioning with sophisticated skills and experience in cyber espionage and illicit.
See the full report here: https://thehackernews.com/2023/08/earth-estries-espionage-campaign.html
Gangs Forcing Hundreds of Thousands of People Into Cybercrime in South-East Asia, Says UN
Hundreds of thousands of people have been trafficked and forced to work for online scamming operations in south-east Asia run by criminal gangs, according to a UN report.
See the full report here: https://www.theguardian.com/global-development/2023/aug/30/gangs-forcing-hundreds-of-thousands-of-people-into-cybercrime-in-south-east-asia-says-un?&web_view=true
Hackers can Exploit Windows Container Isolation Framework to Bypass Endpoint Security
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.
See the full report here: https://thehackernews.com/2023/08/hackers-can-exploit-windows-container.html?&web_view=true
Hackers exploit critical Juniper RCE bug chain after PoC release
Hackers are using a critical exploit chain to target Juniper EX switches and SRX firewalls via their Internet-exposed J-Web configuration interface. Successful exploitation enables unauthenticated attackers to remotely execute code on unpatched devices. Admins are advised to apply patches or upgrade JunOS to the latest release immediately or, at least, disable Internet access to the J-Web interface to remove the attack vector.
See the full report here: <bleepingcomputer.com/news/security/hackers-exploit-critical-juniper-rce-bug-chain-after-poc-release/>
New Android MMRat malware uses Protobuf protocol to steal your data
A novel Android banking malware named MMRat uses a rarely used communication method, protobuf data serialization, to more efficiently steal data from compromised devices. Security researchers observed that MMRat is distributed via websites disguised as official app stores. MMRat uses a unique command and control (C2) server protocol based on protocol buffers (Protobuf) for efficient data transfer, which is uncommon among Android trojans. MMRat shows the evolving sophistication of Android banking trojans, adeptly blending stealth with efficient data extraction.
See the full report here: https://www.bleepingcomputer.com/news/security/new-android-mmrat-malware-uses-protobuf-protocol-to-steal-your-data/
DreamBus malware exploits RocketMQ flaw to infect servers
A new version of the DreamBus botnet malware exploits a critical-severity remote code execution vulnerability (CVE-2023-33246) in RocketMQ servers to infect devices. The exploited flaw is a permission verification issue that impacts RocketMQ version 5.1.0 and older, allowing attackers to perform remote command execution under certain conditions. RockerMQ administrators upgrade to version 5.1.1 or later stop the latest DreamBus attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/dreambus-malware-exploits-rocketmq-flaw-to-infect-servers/
University of Michigan shuts down network after cyberattack
The University of Michigan (U-M) has disconnected its network from the internet to deal with a cybersecurity-related technical issue on the eve of the new academic year. The university had not yet restored wiFi and internet access in the campus at the time of writing. Because of the challenges posed by the connectivity outage, students will not incur late registration or disenrollment fees through the month of August. U-M stated that financial aid refunds may be delayed due to the system outage.
See the full report here: https://www.bleepingcomputer.com/news/security/university-of-michigan-shuts-down-network-after-cyberattack/
Qakbot botnet dismantled after infecting over 700,000 computers
A multinational operation has disrupted operations of Qakbot botnet and malware, dismantled its infrastructure, and confiscated illicit profits worth over USD 8.6 million. Law-enforcement officials also launched an aggressive campaign to uninstall the malware from over 700,000 victim computers (with the United States alone accounting for over 200,000). Qakbot was used by ransomware groups such as Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta as an initial means of infection to target businesses, healthcare providers, and government agencies across the world.
See the full report here: https://www.bleepingcomputer.com/news/security/qakbot-botnet-dismantled-after-infecting-over-700-000-computers/
Phishing-as-a-Service Gets Smarter: Security Researchers Sound Alarm on AiTM Attacks
Threat intelligence researchers are warning of an increase in adversary-in-the-middle phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model. The ultimate goal of such attacks is to siphon session cookies, enabling threat actors to access privileged systems without reauthentication.
See the full report here: https://thehackernews.com/2023/08/phishing-as-service-gets-smarter.html
Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom
A China-linked hacking group exploited a zero-day flaw (CVE-2023-2868) in Barracuda Networks Email Security Gateway (ESG) appliances to spy on government, military, defense and aerospace, high-tech industry, and telecom firms. Barracuda recommends that impacted customers replace their compromised appliances, and is providing the replacement product to impacted customers at no cost. CISA has released additional indicators of compromise (IOCs) associated with the exploitation of this remote command injection vulnerability.
See the full report here: https://thehackernews.com/2023/08/chinese-hacking-group-exploits.html
DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates
A new malspam campaign has been observed deploying an off-the-shelf malware called DarkGate. DarkGate, sold mainly on underground forums by an actor named RastaFarEye, comes with capabilities to evade detection by security software, set up persistence using Windows Registry changes, escalate privileges, and steal data from web browsers and other software such as Discord and FileZilla.
See the full report here: https://thehackernews.com/2023/08/darkgate-malware-activity-spikes-as.html
Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks
VMware has released software updates to correct two security vulnerabilities — CVE-2023-34039 (CVSS score: 9.8) and CVE-2023-20890 (CVSS score: 7.2) — in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution. The company said that version 6.11.0 comes with fixes for the two flaws.
See the full report here: https://thehackernews.com/2023/08/critical-vulnerability-alert-vmware.html
Attackers can Discover IP Addresses by Sending Links Over the Skype Mobile App
A security researcher discovered that it's possible to discover a target’s IP address by sending a link over the Skype mobile app. The researcher pointed out that the attack only requires the target to open the message.
See the full report here: https://securityaffairs.com/150000/hacking/grabbing-ip-addr-via-skype-mobile-app.html?web_view=true
Japan's JPCERT Warns of New "MalDoc in PDF" Attack Technique
Japan’s computer emergency response team (JPCERT) has recently observed a new attack technique, called "MalDoc in PDF", that bypasses detection by embedding a malicious Word file into a PDF file.
See the full report here: https://securityaffairs.com/150012/hacking/maldoc-in-pdf-attack.html?&web_view=true
FIN8-linked actor targets Citrix NetScaler systems
A financially motivated actor linked to the FIN8 group exploits the CVE-2023-3519 RCE in attacks on Citrix NetScaler systems in massive attacks.The hackers are exploiting the remote code execution, tracked as CVE-2023-3519, in a large-scale campaign.
See the full report here: https://securityaffairs.com/150028/hacking/fin8-citrix-netscaler.html
Researchers Sounds Alarm on AiTM Attacks
Researchers are warning of an increase in adversary-in-the-middle (AiTM) phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model.
See the full report here: https://thehackernews.com/2023/08/phishing-as-service-gets-smarter.html?&web_view=true
Spainish Police Warns of LockBit Locker Ransomware Phishing Attacks
Spanish Police warned about the wave of attacker-sent phishing emails to architecture companies, although it is not ruled out that they extend their action to other sectors.
See the full report here: https://www.bleepingcomputer.com/news/security/spain-warns-of-lockbit-locker-ransomware-phishing-attacks/?&web_view=true
Meta: Pro-Chinese influence operation was the largest in history
Meta stated that the company had taken down what officials at the firm describe as the largest ever “cross-platform covert influence operation in the world,” which featured thousands of accounts pushing pro-Chinese messages across online platforms. The operation in question targeted audiences in Taiwan, the United States, Australia, the United Kingdom, Japan and the global Chinese-speaking population with messages across more than 50 platforms.
See the full report here: https://cyberscoop.com/meta-china-influence-operation-facebook/
Cloud and hosting provider Leaseweb took down critical systems after a cyber attack
Global hosting and cloud services provider Leaseweb has disabled some “critical” systems following a recent security breach. The company informed its customers that is now working on restoring these systems. According to a notice of incident sent to customers, on August 22 2023, the company discovered “unusual” activity in some of its systems while investigating Customer Portal downtime issues.
See the full report here: https://securityaffairs.com/149897/hacking/leaseweb-cyber-attack.html
IT Contractor Data Breach Affects 47,000 Met Police Personnel
The Metropolitan Police Force is currently dealing with an extensive data breach involving the personal information of its officers and staff. The breach has exposed the details of all 47,000 personnel, raising concerns about their safety and operational integrity. The data breach was discovered after cybercriminals penetrated the IT systems of a contractor responsible for printing warrant cards and staff passes, and has left the Metropolitan Police Force on high alert.
See the full report here: https://www.hackread.com/it-contractor-data-breach-met-police-personnel/
Rhysida claims ransomware attack on Prospect Medical, threatens to sell data
The Rhysida ransomware gang has claimed responsibility for the massive cyberattack on Prospect Medical Holdings, claiming to have stolen 500,000 social security numbers, corporate documents, and patient records.
See the full report here: https://www.bleepingcomputer.com/news/security/rhysida-claims-ransomware-attack-on-prospect-medical-threatens-to-sell-data/
Leaked LockBit 3.0 Ransomware Builder Used by Multiple Actors
Lockbit v3, aka Lockbit Black, was detected in June 2022, but in September 2022 a builder for this variant was leaked online. The availability of the builder allowed anyone to create their own customized version of the ransomware.
See the full report here: https://securityaffairs.com/149941/hacking/lockbit-3-leaked-code-usage.html?&web_view=true
Microsoft detects Flax Typhoon hackers using legitimate software to snoop on Taiwanese organizations
Researchers have identified a nation-state activity group tracked as Flax Typhoon, based in China, that is targeting dozens of organizations in Taiwan with the likely intention of performing espionage. Flax Typhoon gains and maintains long-term access to Taiwanese organizations’ networks with minimal use of malware, relying on tools built into the operating system
See the full report here: https://industrialcyber.co/critical-infrastructure/microsoft-detects-flax-typhoon-hackers-using-legitimate-software-to-snoop-on-taiwanese-organizations/
Polish Authorities Investigate Hacking Attack on Local Railways
Threat actors transmitted a signal triggering an emergency status that stopped the trains near the city of Szczecin in Poland. According to the media, the attack stopped at least 20 trains and paralyzed the traffic for hours.
See the full report here: https://securityaffairs.com/149952/hacking/hacking-attack-polan-railways.html?&web_view=true
Updated Kmsdx botnet version targets IoT devices
Researchers spotted an updated version of the KmsdBot botnet that is now targeting Internet of Things (IoT) devices. The malicious code was used in attacks targeting multiple sectors including the gaming industry, technology industry, and luxury car manufacturers
See the full report here: https://securityaffairs.com/149970/cyber-crime/kmsdbot-botnet-new-version.html
Researchers Discover Reply URL Takeover Flaw in Azure
Security researchers are urging Azure Active Directory (AD) users to monitor for abandoned reply URLs after revealing a critical vulnerability in the Microsoft Power Platform. Attackers could use the URL to redirect authorization codes to themselves, exchanging these for access tokens. The threat actor could then call the Power Platform API via a middle-tier service and obtain elevated privileges.
See the full report here: https://www.infosecurity-magazine.com/news/reply-url-takeover-issue-azure/?&web_view=true
ZeroFox Intelligence Reports:
ZeroFox Intelligence Flash Report - Political Instability in West Africa
In this flash report, ZeroFox geopolitical researchers provide updates on the recent political instability occurring throughout West Africa, including an overview of what led to these developments and potential outcomes.
Report: https://zerofox.com/advisories/21677
Tags: tlp:clear, weekly bulletin, all industries, global