zerofox logo
Advisories

ZeroFox Weekly Threat Bulletin: 09/15/2023 - 09/21/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 09/15/2023 - 09/21/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - September 21, 2023

Brief Highlights

  • FBI and CISA Release Advisory on Snatch Ransomware
  • Finnish Customs Service Brings Down Tor Web Server of Narcotics Site
  • T-Mobile Patches Bug that Allowed Users to View Other People’s Account Information
  • Data broker / initial-access broker / hacktivist group: SiegedSec & NoName057(16)
  • Vulnerabilities: CVE-2023-40260 and CVE-2023-42322
  • Exploits: CVE-2020-3992 and CVE-2020-25213
  • Breaches: BreachForums/WWHClub:SberPravo Data Breach and BreachForums: Zurich Insurance Group Data Breach

Report: https://zerofox.com/advisories/21881


ZeroFox Daily Intelligence Brief - September 20, 2023

Brief Highlights

  • International Criminal Court Says It Has Been hacked
  • Trend Micro Releases Fixes For Actively Exploited Flaws
  • ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies
  • Data broker / initial-access broker / hacktivist group: Exploit user sandocan & Infinity Forum
  • Vulnerabilities: CVE-2023-20900 and CVE-2023-5063
  • Exploits: CVE-2020-8193 and CVE-2020-10199
  • Breaches: Combolist: '12b_splitbo_part_41.txt'

Report: https://zerofox.com/advisories/21872


ZeroFox Daily Intelligence Brief - September 19, 2023

Brief Highlights

  • SprySOCKS Linux Malware Employed in Cyber Espionage Campaign
  • Payment Card-Skimming Campaign Expands to Target Websites in North and Latin America
  • Microsoft Mitigates Exposure of Internal Information via Overly-Permissive SAS Token
  • Data broker / initial-access broker / hacktivist group: Exploit user ppfuck & XSS user TOP G
  • Vulnerabilities: CVE-2023-42399 and CVE-2023-41599
  • Exploits: CVE-2020-27950 and CVE-2020-8950
  • Breaches: Combolist: '113.txt'

Report: https://zerofox.com/advisories/21863


ZeroFox Daily Intelligence Brief - September 18, 2023

Brief Highlights

  • DarkGate Popularity Prompts Pause on New User Support
  • Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks
  • CISA Releases Continuous Diagnostics and Mitigation Program: Identity, Credential, and Access Management (ICAM) Reference Architecture
  • Data broker / initial-access broker / hacktivist group: Exploit users opal & soflyaway and Black Hat Forum (BHF) user tonny_gram
  • Vulnerabilities: CVE-2023-2848 and CVE-2023-38557
  • Exploits: CVE-2020-6418 and CVE-2020-11108
  • Breaches: Credit Card Data Breach: Combolist: 'pasteServices.txt' (269,366 Records) and Credit Card Data Breach: 2023-9-16 (399c64 | 2623)

Report: https://zerofox.com/advisories/21856


ZeroFox Daily Intelligence Brief - September 15, 2023

Brief Highlights

  • Actual Cisco Webex URL Redirecting to Malware-Deploying Site in Google Ads Abuse
  • U.S.-Canada Water Rights Management Organization Struck by Ransomware Group
  • Cyberattack at Caesars Casino Leads to Customer-Data Theft, Ransom Paid
  • Data broker / initial-access broker / hacktivist group: Exploit user klk005 and Cyber Av3ngers
  • Vulnerabilities: CVE-2023-41081 and CVE-2023-29306
  • Exploits: CVE-2020-14321 and CVE-2020-7961
  • BreachForums: Surplus Motos Data Breach and BreachForums/LeakBase: Winamax Data Breach

Report: https://zerofox.com/advisories/21845


Breach Disclosures:


СберПраво

An alleged data breach at СберПраво – a Russia-based legal services and consultation – exposed 72,152 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21883


Zurich Insurance Group

An alleged data breach at Zurich Insurance Group – a Switzerland-based insurance company – exposed 757,446 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21882


Breaking News:


Free Download Manager releases script to check for Linux malware

The developers of Free Download Manager (FDM) have published a script to check if a Linux device was infected through a recently reported supply chain attack. Free Download Manager is a popular cross-platform download manager that offers torrenting, proxying, and online video downloads through a user-friendly interface.

See the full report here: https://www.bleepingcomputer.com/news/security/free-download-manager-releases-script-to-check-for-linux-malware/


FBI, CISA Issue Joint Warning on "Snatch" Ransomware-as-a-Service

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) released joint Cybersecurity Advisory (CSA) #StopRansomware: Snatch Ransomware, which provides indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with the Snatch ransomware variant. FBI investigations identified these IOCs and TTPs as recently as June 1, 2023.

See the full report here: https://www.darkreading.com/application-security/fake-winrar-poc-exploit-conceals-venomrat-malware


Fake WinRAR PoC Exploit Conceals VenomRAT Malware

According to researchers a cyberattacker, who goes by "whalersplonk," took advantage of a very real remote code execution (RCE) security bug in WinRAR (CVE-2023-40477) that was made public on August 2023. The attacker quickly pulled together a convincing but fake PoC for the bug, which it pushed out to a GitHub repository the same week.

See the full report here: https://www.darkreading.com/application-security/fake-winrar-poc-exploit-conceals-venomrat-malware


Experts found critical flaws in Nagios XI network monitoring software

Researchers discovered four vulnerabilities (CVE-2023-40931, CVE-2023-40932, CVE-2023-40933, CVE-2023-40934) in the Nagios XI network and IT infrastructure monitoring solution that could lead to information disclosure and privilege escalation. Nagios XI provides monitoring of all mission-critical infrastructure components including applications, services, operating systems, network protocols, systems metrics, and network infrastructure. It is used by thousands of organizations worldwide.

See the full report here: https://securityaffairs.com/151138/security/nagios-xi-flaws.html


P2PInfect botnet activity surges 600x with stealthier malware variants

The P2PInfect botnet worm is going through a period of highly elevated activity volumes starting in late August 2023 and then picking up again in September 2023.

See the full report here: https://www.bleepingcomputer.com/news/security/p2pinfect-botnet-activity-surges-600x-with-stealthier-malware-variants/


T-Mobile App Glitch Let Users See Other People’s Account Info

A technical glitch during an update in T-Mobile's app allowed users to access other's information. According to user reports on social media, the exposed information included customers' names, phone numbers, addresses, account balances, and credit card details like the expiration dates and the last four digits.

See the full report here: https://www.bleepingcomputer.com/news/security/t-mobile-app-glitch-let-users-see-other-peoples-account-info/?&web_view=true


Cyber Group 'Gold Melody' Selling Compromised Access to Ransomware Attackers

A financially motivated threat actor has been outed as an initial access broker (IAB) that sells access to compromised organizations for other adversaries to conduct follow-on attacks such as ransomware. Researchers dubbed the e-crime group Gold Melody, which is also known by the names Prophet Spider and UNC961.

See the full report here: https://thehackernews.com/2023/09/cyber-group-gold-melody-selling.html


China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers

China's Ministry of State Security (MSS) has accused the U.S. of breaking into Huawei's servers, stealing critical data, and implanting backdoors since 2009, amid mounting geopolitical tensions between the two countries. In a message posted on WeChat, the government authority said U.S. intelligence agencies have "done everything possible" to conduct surveillance, secret theft, and intrusions.

See the full report here: https://thehackernews.com/2023/09/china-accuses-us-of-decade-long-cyber.html


UK’s New Online Safety Law Adds to Crackdown on Big Tech Companies

British lawmakers approved an ambitious but controversial new internet safety law with wide-ranging powers to crack down on digital and social media companies.

See the full report here: https://www.securityweek.com/uks-new-online-safety-law-adds-to-crackdown-on-big-tech-companies/


Claimants in Celsius Crypto Bankruptcy Targeted in Phishing Attack

Scammers are impersonating the bankruptcy claim agent for crypto lender Celsius in phishing attacks that attempt to steal funds from cryptocurrency wallets. In July 2022, crypto lender Celsius filed for bankruptcy and froze withdrawals from user accounts. Customers have since filed claims against the company, hoping to recover a portion of the funds. Over the past few days, people have reported receiving phishing emails pretending to be from Stretto, the Claims Agent for the Celsius bankruptcy proceeding. The phishing email claims to offer creditors a 7-day exit window to claim their frozen funds.

See the full report here: https://www.bleepingcomputer.com/news/security/claimants-in-celsius-crypto-bankruptcy-targeted-in-phishing-attack/?&web_view=true


International Criminal Court hit with a cyber attack

The International Criminal Court (ICC) announced that threat actors have breached its systems. The experts at the International Criminal Court discovered the intrusion after having detected anomalous activity affecting its information systems.

See the full report here: https://securityaffairs.com/151115/hacking/international-criminal-court-cyber-attack.html


Chinese Spies Infected Dozens of Networks With Thumb Drive Malware

Cybersecurity researchers revealed that a China-linked hacker group they’re calling UNC53 has managed to hack at least 29 organizations around the world since last year using the old-school approach of tricking their staff into plugging malware-infected USB drives into computers on their networks. The victims span the United States, Europe, and Asia while appearing to originate from multinational organizations’ Africa-based operations, in countries including Egypt, Zimbabwe, Tanzania, Kenya, Ghana, and Madagascar. Researchers say the campaign represents a surprisingly effective revival of thumb drive-based hacking that has largely been replaced by more modern techniques, like phishing and remote exploitation of software vulnerabilities.

See the full report here: https://www.wired.com/story/china-usb-sogu-malware/


Pizza Hut Australia hack: data breach exposes customer information and order details

Pizza Hut’s Australian operations have been hit by a cyber-attack, the company says, with customer data including delivery addresses and order details stolen in the hack. In an email to customers , Pizza Hut Australia’s chief executive, said the company became aware in early September 2023 that there had been “unauthorised third party” access to some of the company’s data.

See the full report here: https://www.theguardian.com/australia-news/2023/sep/20/pizza-hut-hack-australia-data-breach-passwords-information-leak


Trend Micro Releases Urgent Fix for Actively Exploited Critical Security Vulnerability

Cybersecurity company Trend Micro has released patches and hotfixes to address a critical security flaw (CVE-2023-41179) in Apex One and Worry-Free Business Security solutions for Windows that has been actively exploited in real-world attacks.

See the full report here: https://thehackernews.com/2023/09/trend-micro-releases-urgent-fix-for.html?&web_view=true


GitLab addresses critical vulnerability

GitLab has released security patches to address a critical vulnerability, tracked as CVE-2023-5009 (CVSS score: 9.6), that allows an attacker to run pipelines as another user. The issue resides in GitLab EE and affects all versions starting from 13.12 and prior to 16.2.7, all versions starting from 16.3 before 16.3.4.

See the full report here: https://securityaffairs.com/151107/security/gitlab-critical-vulnerability-cve-2023-5009.html


Sophisticated Phishing Campaign Targeting Chinese Users with ValleyRAT and Gh0st RAT

Chinese-language speakers have been increasingly targeted as part of multiple email phishing campaigns that aim to distribute various malware families such as Sainbox RAT, Purple Fox, and a new trojan called ValleyRAT. Campaigns include Chinese-language lures and malware typically associated with Chinese cybercrime activity

See the full report here: https://thehackernews.com/2023/09/sophisticated-phishing-campaign_20.html


Earth Lusca expands its arsenal with SprySOCKS Linux malware

China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign. Researchers, while monitoring the activity of the China-linked threat actor Earth Lusca, discovered an encrypted file hosted on a server under the control of the group. Additional analysis led to the discovery of a previously unknown Linux backdoor tracked as SprySOCKS.

See the full report here: https://securityaffairs.com/151020/apt/sprysocks-backdoor-earth-lusca.html


Retool blames breach on Google Authenticator MFA cloud sync feature

Software company Retool says the accounts of 27 cloud customers were compromised following a targeted and multi-stage social engineering attack. Retool's development platform is used to build business software by companies ranging from startups to Fortune 500 enterprises, including Amazon, Mercedes-Benz, DoorDash, NBC, Stripe, and Lyft. Retool's head of engineering, revealed that all hijacked accounts belong to customers in the cryptocurrency industry. The breach occurred on August 27 2023, after the attackers bypassed multiple security controls using SMS phishing and social engineering to compromise an IT employee's Okta account.

See the full report here: https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/


Bumblebee malware returns in new attacks abusing WebDAV folders

The malware loader "Bumblebee" has broken its two-month vacation with a new campaign that employs new distribution techniques that abuse 4shared WebDAV services. Researchers report that Bumblebee's latest campaign, which started on September 7, 2023, abuses the 4shared WebDAV services to distribute the loader, accommodate the attack chain, and perform several post-infection actions. The abuse of the 4shared platform, a legitimate and well-known file-hosting services provider, helps Bumblebee operators evade blocklists and enjoy high infrastructure availability.

See the full report here: https://www.bleepingcomputer.com/news/security/bumblebee-malware-returns-in-new-attacks-abusing-webdav-folders/


Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

Microsoft said it took steps to correct a glaring security gaffe that led to the exposure of 38 terabytes of private data. The leak was discovered on the company's AI GitHub repository and is said to have been inadvertently made public when publishing a bucket of open-source training data. It also included a disk backup of two former employees' workstations containing secrets

See the full report here: https://thehackernews.com/2023/09/microsoft-ai-researchers-accidentally.html


Transparent Tribe Uses Fake YouTube Android Apps to Spread CapraRAT Malware

The suspected Pakistan-linked threat actor known as Transparent Tribe is using malicious Android apps mimicking YouTube to distribute the CapraRAT mobile remote access trojan (RAT), demonstrating the continued evolution of the activity. CapraRAT is a highly invasive tool that gives the attacker control over much of the data on the Android devices that it infects.

See the full report here: https://thehackernews.com/2023/09/transparent-tribe-uses-fake-youtube.html


Nearly 12,000 Juniper Firewalls Found Vulnerable to Recently Disclosed RCE Vulnerability

New research has found that close to 12,000 internet-exposed Juniper firewall devices are vulnerable to a recently disclosed remote code execution flaw (CVE-2023-36845).

See the full report here: https://thehackernews.com/2023/09/over-12000-juniper-firewalls-found.html


CISA Says Owl Labs Vulnerabilities Requiring Close Physical Range Exploited in Attacks

The US cybersecurity agency CISA says four vulnerabilities found in Owl Labs video conferencing devices — flaws that require the attacker to be in close range of the target — have been actively exploited in attacks.

See the full report here: https://www.securityweek.com/cisa-says-owl-labs-vulnerabilities-requiring-close-physical-range-exploited-in-attacks/


New Hook Android Banking Trojan Expands on ERMAC's Legacy

A new analysis of the Android banking trojan known as Hook has revealed that it's based on its predecessor called ERMAC. All commands (30 in total) that the malware operator can send to a device infected with ERMAC malware, also exist in Hook. The code implementation for these commands is nearly identical.

See the full report here: https://thehackernews.com/2023/09/hook-new-android-banking-trojan-that.html?&web_view=true


Shell says its Australian BG Group business hit by MOVEit breach

Shell has disclosed a cybersecurity incident involving some employees at BG Group in Australia, the latest company to be hit by the MOVEit hack. Shell identified some personal information related to affected individuals that was accessed without authorization and had made attempts to notify them. Although the data is from 2013 and some of it may be out of date, there is a risk to impacted individuals of identity theft and being targeted by phishing campaigns.

See the full report here: https://www.reuters.com/business/energy/shell-says-australian-unit-hit-by-moveit-data-breach-2023-09-14/


ORBCOMM ransomware attack causes trucking fleet management outage

Trucking and fleet management solutions provider ORBCOMM has confirmed that a ransomware attack is behind recent service outages preventing trucking companies from managing their fleets. An email was sent out to all ORBCOMM customers on the evening of September 7 about the ransomware attack. This outage has reportedly impacted some of the United States’s largest freight transportation companies as they cannot track their fleets and inventory.

See the full report here: https://www.bleepingcomputer.com/news/security/orbcomm-ransomware-attack-causes-trucking-fleet-management-outage/


Retool blames breach on Google Authenticator MFA cloud sync feature

Software company Retool says the accounts of 27 cloud customers were compromised following a targeted and multi-stage social engineering attack. The breach occurred on August 27, after the attackers bypassed multiple security controls using SMS phishing and social engineering to compromise an IT employee's Okta account.

See the full report here: https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/


BlackCat ransomware hits Azure Storage with Sphynx encryptor

The BlackCat (ALPHV) ransomware gang has been observed using stolen Microsoft accounts and the Sphynx encryptor to encrypt targets' Azure cloud storage. The new Sphynx encryptor embeds the Remcom hacking tool and the Impacket networking framework for lateral movement across compromised networks.

See the full report here: https://www.bleepingcomputer.com/news/security/blackcat-ransomware-hits-azure-storage-with-sphynx-encryptor/


TikTok flooded by "Elon Musk" cryptocurrency giveaway scams

TikTok is facing a surge of fake cryptocurrency giveaways, with themes based on Elon Musk, Tesla, or SpaceX. The scammers set up hundreds of websites that pretend to be crypto exchanges or giveaway sites that prompt users to register an account to receive free cryptocurrency. However, as expected, these scams simply steal any deposited crypto, with the users receiving nothing in return.

See the full report here: https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/


Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks

Security researchers have observed that financially motivated threat actor UNC3944 (0ktapus, Scatter Swine, and Scattered Spider) is deploying ransomware to enhance the monetization of its operations. The group is working as an affiliate for the ALPHV ransomware crew and works at an “extremely high operational tempo”—primarily targeting business-critical systems and virtual machines across industries.

See the full report here: https://thehackernews.com/2023/09/financially-motivated-unc3944-threat.html


US-Canada water org confirms "cybersecurity incident" after ransomware crew threatens leak

The International Joint Commission, a body that manages water rights along the US-Canada border, has confirmed its IT security was targeted, after a ransomware gang claimed it stole 80GB of data from the organization.

See the full report here: https://www.theregister.com/2023/09/15/ijc_noescape_ransomware/


Auckland transport authority hit by suspected ransomware attack

The Auckland Transport (AT) transportation authority in New Zealand is dealing with a widespread outage caused by a cyber incident, impacting a wide range of customer services.

See the full report here: https://www.bleepingcomputer.com/news/security/auckland-transport-authority-hit-by-suspected-ransomware-attack/


Caesars says cyber-crooks stole customer data as MGM casino outage drags on

Casino giant Caesars Entertainment has confirmed miscreants stole a database containing customer info, including driver license and social security numbers for a "significant number" of its loyalty program members, in a social engineering attack earlier in September 2023.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/14/caesars_mgm_hacks/


Cybercriminals Use Webex Brand to Target Corporate Users

Threat actors are targeting corporate users who are interested in downloading Webex — by buying ad space from Google and impersonating Cisco. Webex, the digital communications giant's Web conference software, has not itself been compromised, to be clear. The effort is a fairly straightforward malvertising campaign: When a user completes a Google search for the software, they are met with a seemingly real advertisement that is being used to distribute malware.

See the full report here: https://www.darkreading.com/endpoint/cybercriminals-webex-brand-corporate-users


Free Download Manager backdoored to serve Linux malware for more than 3 years

Researchers discovered a free download manager site that has been compromised to serve Linux malware. While investigating a set of suspicious domains, the experts identified that the domain in question has a deb.fdmpkg[.]org subdomain.

See the full report here: https://securityaffairs.com/150851/malware/free-download-manager-supply-chain-attack.html


Windows 11 "ThemeBleed" RCE Flaw Gets Proof-of-Concept Exploit

Proof-of-concept exploit code has been published for a Windows Themes vulnerability tracked as CVE-2023-38146 that allows remote attackers to execute code. The vulnerability has a high-severity score of 8.8.

See the full report here: https://www.bleepingcomputer.com/news/security/windows-11-themebleed-rce-bug-gets-proof-of-concept-exploit/?&web_view=true


Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks

A recently introduced Google account sync feature has been blamed after sophisticated hackers attacked 27 cryptocurrency firms via Retool.

See the full report here: https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/


Microsoft Uncovers Flaws in ncurses Library Affecting Linux and macOS Systems

A set of memory corruption flaws( CVE-2023-29491 ) have been discovered in the ncurses (short for new curses) programming library that could be exploited by threat actors to run malicious code on vulnerable Linux and macOS systems.

See the full report here: https://thehackernews.com/2023/09/microsoft-uncovers-flaws-in-ncurses.html?&web_view=true


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report – Nagorno-Karabakh Conflict

In this flash report, the ZeroFox Geopolitical Working Groups provides updates on recent developments with Azerbaijan's military operation in the Nagorno-Karabakh Republic.

Report: https://zerofox.com/advisories/21895


ZeroFox Intelligence Assessment – 2023 Phishing Trends

In this assessment, ZeroFox Intelligence researchers share current phishing trends and recommendations organizations can implement, as well as provide observations on the evolution in the types of phishing tactics most commonly used by increasingly sophisticated cyber attackers.

Report: https://zerofox.com/advisories/21894


ZeroFox Intelligence Flash Report - DarkGate Popularity Prompts Pause on New User Support

In this flash report, ZeroFox researchers provide updates on recent developments around DarkGate malware, as well as analysis on what these developments likely mean.

Report: https://zerofox.com/advisories/21855


Tags: tlp:clear, weekly bulletin, all industries, global