ZeroFox Daily Intelligence Brief - September 15, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 15, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Actual Cisco Webex URL Redirecting to Malware-Deploying Site in Google Ads Abuse
- U.S.-Canada Water Rights Management Organization Struck by Ransomware Group
- Cyberattack at Caesars Casino Leads to Customer-Data Theft, Ransom Paid
- Data broker / initial-access broker / hacktivist group: Exploit user klk005 and Cyber Av3ngers
- Vulnerabilities: CVE-2023-41081 and CVE-2023-29306
- Exploits: CVE-2020-14321 and CVE-2020-7961
- BreachForums: Surplus Motos Data Breach and BreachForums/LeakBase: Winamax Data Breach
Actual Cisco Webex URL Redirecting to Malware-Deploying Site in Google Ads Abuse
Suspected Mexico-based threat actors distributed the BatLoader malware via malicious pages masquerading as the official Webex download portal. The campaign used the legitimate URL, "webex.com," as the click destination—using a loophole in Google Ads tracking templates that allowed them to redirect to the malicious site. Google has reportedly reviewed the malicious ads and “taken appropriate action against the associated accounts.”
U.S.-Canada Water Rights Management Organization Struck by Ransomware Group
The International Joint Commission (IJC), responsible for managing water rights along the U.S.-Canada border, confirmed a cyberattack after a ransomware gang, NoEscape, claimed to have stolen 80 GB of its data. While the IJC is working to investigate and resolve the incident, specific details remain undisclosed; IJC has declined to comment on the ransom demand or on its response strategy.
Cyberattack at Caesars Casino Leads to Customer-Data Theft, Ransom Paid
Caesars Entertainment, one of the largest casino chains in the United States, has reportedly ceded to ransom demands to prevent leaks of customer data stolen in a recent attack. The attackers accessed the loyalty-program database, which contained customers’ driver licenses and Social Security numbers. The company noted that non-loyalty program members remain unaffected by the breach. The cyberattack comes after MGM Resorts International recently faced a similar incident.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user klk005 : Auctioning RDP access to Canadian a building-materials manufacturer.
- Cyber Av3ngers: Pro-Iran group claims to have disrupted railway, electrical, and petrochemical infrastructure in Israel.
VULNERABILITIES
- CVE-2023-41081: A bug could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd.
- CVE-2023-29306: Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability.
EXPLOITS
- CVE-2020-14321: Moodle Teacher Enrollment Privilege Escalation / Remote Code Execution.
- CVE-2020-7961: Liferay Portal Java Unmarshalling Remote Code Execution
BREACHES
- BreachForums: Surplus Motos Data Breach: (71,907 Records) | Email address, username, and password.
- BreachForums/LeakBase: Winamax Data Breach:: (40,047 Records)| Email address, name, and physical address.
Tags: DIB, tlp:green