zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 1, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 1, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • National Student Clearinghouse Data Breach Affects 890 Schools
  • United States and Japan Release Advisory on China-Linked Cyber Actors
  • Hackers Lure Organizations through Fake Red Cross Blood Drive Emails

National Student Clearinghouse Data Breach Affects 890 Schools

The National Student Clearinghouse (degree verification and student enrollment verification service across North America) has disclosed that it received a notice about a cybersecurity issue with MOVEit Transfer. Unauthorized access to certain files occurred around May 30, 2023. These files contained personal data, including names, dates of birth, Social Security numbers, contact information, student ID numbers, and certain school records such as enrollment, degrees, and course-related data. The organization claimed that it was working with experts and law-enforcement officials and that affected individuals will receive two years of free identity-monitoring services.

United States and Japan Release Advisory on China-Linked Cyber Actors

American and Japanese cybersecurity authorities have released a joint advisory on China-linked threat group BlackTech modifying router firmware without detection and exploiting routers’ domain-trust relationships. The threat actors use custom malware, dual-use tools, and living off the land tactics, such as disabling logging on routers, to conceal their operations. The advisory highlights the need for multinational corporations to review all subsidiary connections, verify access, and consider implementing Zero Trust models to limit the extent of a potential BlackTech compromise.

Hackers Lure Organizations through Fake Red Cross Blood Drive Emails

A new APT group named "AtlasCross" has surfaced, targeting organizations via phishing lures pretending to be from the American Red Cross to distribute backdoor malware. The attacks involve fake emails relating to a "September 2023 Blood Drive," using macro-enabled Word documents to deliver the malware. Two previously undocumented trojans, DangerAds and AtlasAgent, have been linked to this group. The attackers are highly sophisticated and elusive and employ custom trojans with narrow targeting and discreet infection methods, making it challenging to ascertain their origin.

Tags: DIB, tlp:green