ZeroFox Daily Intelligence Brief - September 29, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 29, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - India-Canada Tensions
- Progress Software Releases Patches for WS_FTP Server
- FBI: Multiple Ransomware Variants Impacting the Same Victims and Data Destruction Trends
- Data broker / initial-access broker / hacktivist group: Exploit user Hexlite & Exploit user l29
- Vulnerabilities: CVE-2023-43868 and CVE-2023-40441
- Breaches: Leakbase: CasualSport Data Breach and BreachForums: Central Restaurants Group Data Breach
ZeroFox Intelligence Brief - India-Canada Tensions
ZeroFox has published a report highlighting deteriorating relations between India and Canada after allegations of India’s possible involvement in the assassination of a Canadian citizen. India had previously declared the individual a terrorist, alleged that he is tied to "Khalistan'' advocacy groups, and accused him of running a terrorist camp. Indian hacktivist groups are now targeting Canadian agencies, with the Canadian Armed Forces website among its victims. The Communications Security Establishment of Canada had previously issued warnings for vigilance, noting that “ geopolitical events often result in an increase in disruptive cyber campaigns."
Progress Software Releases Patches for WS_FTP Server
Progress Software, the company behind MOVEit Transfer, urges users to patch critical vulnerabilities in its WS_FTP Server. The flaws, including two critical flaws CVE-2023-40044 and CVE-2023-42657, pose risks including remote commands execution and unauthorized file operations. Progress recommends upgrading to version 8.8.2 to mitigate these issues, acknowledging potential system downtime during the process. In the aftermath of the MOVEit Transfer zero-day exploit by the Clop ransomware group, over 2,100 organizations and 62 million individuals were affected, with an estimated USD 75-100 million in ransom payments.
FBI: Multiple Ransomware Variants Impacting the Same Victims and Data Destruction Trends
The Federal Bureau of Investigation (FBI) has published a Private Industry Notification to highlight two emerging ransomware trends: multiple ransomware attacks on the same victim within a few days gap and new data-destruction tactics in attacks. A second ransomware attack against an already compromised system could significantly harm victim entities, the FBI noted. AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum, and Royal were some of the variants deployed in this new attack strategy. Moreover, an increased use of custom data theft, wiper tools, and malware has been observed, with the goal to pressure victims to negotiate.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Hexlite: Advertising alleged privately held exploit for unpatched vulnerability in WinRAR.
- Exploit user l29: Selling alleged RDP access to a U.S.-based healthcare institution.
VULNERABILITIES
- CVE-2023-43868: D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.
- CVE-2023-40441: A resource exhaustion issue was addressed with improved input validation.
BREACHES
- Leakbase: CasualSport Data Breach: (19,045 Records)
- BreachForums: Central Restaurants Group Data Breach: (15,463 Records)
Tags: DIB, tlp:green