zerofox logo
Advisories

ZeroFox Weekly Threat Bulletin: 09/22/2023 - 09/28/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 09/22/2023 - 09/28/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - September 28, 2023

Brief Highlights

  • Sony Investigates Hacking Claims
  • U.K. Information Commissioner Warns About Risks to Domestic Abuse Victims from Data Breaches
  • Multinational Automation Giant Johnson Controls Struck by Ransomware Attack
  • Data broker / initial-access broker / hacktivist group: Killmilk & 𝐈𝐍𝐃𝐈𝐀𝐍 𝐂𝐘𝐁𝐄𝐑 𝐅𝐎𝐑𝐂𝐄
  • Vulnerabilities: CVE-2023-23958 and CVE-2023-5244
  • Exploits: CVE-2021-29627
  • Breaches: Combolist: '3.2k NordVPN.txt'

Report: https://zerofox.com/advisories/21939


ZeroFox Daily Intelligence Brief - September 27, 2023

Brief Highlights

  • Sony Investigates Hacking Claims
  • U.K. Information Commissioner Warns About Risks to Domestic Abuse Victims from Data Breaches
  • Hackers Lure Organizations through Fake Red Cross Blood Drive Emails
  • Data broker / initial-access broker / hacktivist group: BreachForums user boole3an & XSS user zetaboy
  • Vulnerabilities: CVE-2023-4259 and CVE-2022-4318
  • Exploits: CVE-2021-3129 and CVE-2021-40865
  • Breaches: Combolist: 'PRIVATE DOMAIN COMBO'

Report: https://zerofox.com/advisories/21923


ZeroFox Daily Intelligence Brief - September 26, 2023

Brief Highlights

  • Xenomorph Android Malware Targets Customers of 30 U.S. Banks
  • EvilBamboo Targets Tibetan, Uyghur, and Taiwanese Communities for Exploitation
  • Phishing Campaign Targets Ukrainian Military Entities with Drone Manuals
  • Data broker / initial-access broker / hacktivist group: Exploit user comedy_club & Exploit user levieux100
  • Vulnerabilities: CVE-2023-31445 and CVE-2023-20588
  • Breaches: BreachForums: Combolist: '130K COMBOLIST EDU.txt' and Credit Card Data Breach

Report: https://zerofox.com/advisories/21914


ZeroFox Daily Intelligence Brief - September 25, 2023

Brief Highlights

  • Stealthy Threat Actor observed Targeting Southeast Asian government
  • National Student Clearinghouse Data Breach Affects 890 schools
  • CISA Collaborates with NFL to Enhance Cyber Defenses Against Attacks
  • Data broker / initial-access broker / hacktivist group: Exploit users: 1337sh[.]com & memeos
  • Vulnerabilities: CVE-2023-41872 and CVE-2023-41949
  • Exploits: CVE-2021-27342 and CVE-2021-35616
  • Breaches: LeakBase: tecnovagroup.com Breach and Credit Card Data Breach

Report: https://zerofox.com/advisories/21907


ZeroFox Daily Intelligence Brief - September 22, 2023

Brief Highlights

  • ZeroFox Intelligence Assessment – 2023 Phishing Trends
  • Apple Emergency Updates Fix 3 New Zero Days Exploited in Attacks
  • Critical Cache Poisoning Flaw in Drupal’s JSON:API Module
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan & SkyNet & BreachForums user Seize
  • Vulnerabilities: CVE-2020-35357 and CVE-2023-42482
  • Exploits: CVE-2020-36179 and CVE-2020-15148
  • Breaches: BreachForums: Blockchain.com Data Breach and The Forge Forums Data Breach

Report: https://zerofox.com/advisories/21898


Breach Disclosures:


Gamon

An alleged data breach at Gamon – a Taiwan-based game development company – exposed 4,512,869 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21945


Glotelho Cameroun

An alleged data breach at Glotelho Cameroun – an Africa-based e-commerce shop that offers electronics, smartphones, tablets, groceries, fashion apparels, and other accessories – exposed 55,506 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21944


Outlet Accessori

An alleged data breach at Outlet Accessori – an Italy-based hardware and software assistance center for mobile phones and computers – exposed 16,731 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21943


CasualSport

An alleged data breach at CasualSport – a U.S.-based online sports apparels and fashion store – exposed 19,045 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21942


Central Restaurants Group

An alleged data breach at Central Restaurants Group – a Thailand-based company that operates the restaurant business – exposed 15,463 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21941


The Forge Forums

An alleged data breach at The Forge Forums – a U.S.-based gaming discussion forum – exposed 15,531 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21897


Blockchain.com

An alleged data breach at Blockchain.com – a U.K.-based cryptocurrency financial services company – exposed 287,426 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21896


Breaking News:


Brazil Is The World's Second Most Vulnerable Country To Cyberattacks

Brazil is the second country in the world most vulnerable to cyberattacks, according to a new report released by researchers. The Latin nation is only surpassed by the United States in the number of blocked threats in the first half of 2023. Brazil is targeted by more than 1,500 malware infection attempts every minute, according to a separate report. While there has been a slight decrease in malware attacks in Latin America between June 2022 and the same month in 2023, with a 3% drop in the 12-month comparison between 2022 and 2021, Brazil still leads the region's cyber threats landscape.

See the full report here: https://www.forbes.com/sites/angelicamarideoliveira/2023/09/27/brazil-is-the-worlds-second-most-vulnerable-country-to-cyberattacks/?sh=77392bba27a4


GitHub repos bombarded by info-stealing commits masked as Dependabot

Hackers are breaching GitHub accounts and inserting malicious code disguised as Dependabot contributions to steal authentication secrets and passwords from developers. The campaign unfolded in July 2023, when researchers discovered unusual commits on hundreds of public and private repositories forged to appear as Dependabot commits.

See the full report here: https://www.bleepingcomputer.com/news/security/github-repos-bombarded-by-info-stealing-commits-masked-as-dependabot/?&web_view=true


China APT Cracks Cisco Firmware in Attacks Against the US and Japan

An old Chinese state-linked threat actor has been quietly manipulating Cisco routers to breach multinational organizations in the US and Japan. "BlackTech" (aka Palmerworm, Temp.Overboard, Circuit Panda, and Radio Panda) has been replacing device firmware with its own malicious version, in order to establish persistence and pivot from smaller, international subsidiaries to headquarters of affected organizations.

See the full report here: https://www.darkreading.com/threat-intelligence/china-apt-cracks-cisco-firmware-attacks-against-us-japan


Fake Bitwarden sites push new ZenRAT password-stealing malware

Fake Bitwarden sites are pushing installers purportedly for the open-source password manager that carry a new password-stealing malware that security researchers call ZenRAT.

See the full report here: https://www.bleepingcomputer.com/news/security/fake-bitwarden-sites-push-new-zenrat-password-stealing-malware/


Researchers Release Details of New RCE Exploit Chain for SharePoint

Researchers who discovered two critical vulnerabilities (CVE-2023-24955, CVE-2023-29357) in Microsoft SharePoint Server have released details of an exploit they developed that chains the two vulnerabilities together to enable remote code execution on affected servers. Separately, another security researcher this week posted proof-of-concept code on GitHub for one of the SharePoint vulnerabilities that shows how an attacker could exploit the flaw to gain admin privileges on vulnerable systems.

See the full report here: https://www.darkreading.com/vulnerabilities-threats/reseachers-release-details-of-new-rce-exploit-chain-for-sharepoint


SSH keys stolen by stream of malicious PyPI and npm packages

A stream of malicious npm and PyPi packages have been found stealing a wide range of sensitive data from software developers on the platforms. The campaign started on September 12, 2023 and researchers unearthed 14 malicious packages on npm.

See the full report here: https://www.bleepingcomputer.com/news/security/ssh-keys-stolen-by-stream-of-malicious-pypi-and-npm-packages/


Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability

Google rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance for Open Media (AOMedia).

See the full report here: https://thehackernews.com/2023/09/update-chrome-now-google-releases-patch.html


China's national security minister rates fake news among most pressing cyber threats

The Chinese minister for national security has penned an article rating the digital risks his country faces and rated network security incidents as the most realistic source of harm to the Chinese internet – both in terms of attacks and the dissemination of fake news.

See the full report here: https://www.theregister.com/2023/09/28/chen_yixin_china_digital_threats/


New ZeroFont Phishing Tricks Outlook Into Showing Fake AV-Scans

Hackers are utilizing a new trick of using zero-point fonts in emails to make malicious emails appear as safely scanned by security tools in Microsoft Outlook.The ZeroFont phishing technique exploits flaws in AI and natural language processing systems to insert hidden words or characters in emails, evading security filters and tricking recipients.

See the full report here: https://www.bleepingcomputer.com/news/security/new-zerofont-phishing-tricks-outlook-into-showing-fake-av-scans/?&web_view=true


DarkBeam Leaks Billions of Credentials via Unsecured Elasticsearch and Kibana Interface

DarkBeam, a digital risk protection firm, left an Elasticsearch and Kibana interface unprotected, exposing records with user emails and passwords from previously reported and non-reported data breaches. The now-closed instance contained over 3.8 billion records. The incident will most likely affect more than DarkBeam users alone.

See the full report here: https://securityaffairs.com/151566/security/darkbeam-data-leak.html?&web_view=true


ROBOT crypto attack on RSA is back as Marvin arrives

An engineer has identified longstanding undetected flaws in a 25-year-old method for encrypting data using RSA public-key cryptography. In a paper titled, "Everlasting ROBOT: the Marvin Attack," engineers elaborate that many software implementations of the PKCS#1 v1.5 padding scheme for RSA key exchange that were previously deemed immune to Daniel Bleichenbacher's widely known attack are, in fact, vulnerable.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/26/robot_marvin_rsa/


CommonSpirit Details Financial Fallout of USD 160M Cyberattack

The cyberattack on the healthcare entity on October 2, 2022, resulted in about USD 160 million in damages, including lost revenue, remediation costs, and related expenses, not counting insurance recoveries, according to CommonSpirit.

See the full report here: https://www.bankinfosecurity.com/commonspirit-details-financial-fallout-160m-cyberattack-a-23158?&web_view=true


Researchers find Bently Nevada 3500 Machine Monitoring vulnerabilities allowing authentication bypass

Researchers have identified the presence of three flaws in Bently Nevada 3500 Machinery Monitoring rack model that allow attackers to bypass authentication. One of these vulnerabilities may allow an attacker to bypass the authentication process and obtain complete access to the device by crafting and sending a malicious request. As the development of a patch is not planned due to legacy limitations, technical details have voluntarily been omitted.

See the full report here: https://industrialcyber.co/news/nozomi-researchers-find-bently-nevada-3500-rack-model-vulnerabilities-allowing-authentication-bypass-by-hackers/


Ukraine Cyber Defenders Prepare for Winter

Ukrainian cyber defenders are girding for an onslaught of cyberattacks against energy and other critical infrastructure sectors as cold weather returns to the country, currently in its second year of fending off a Russian war of conquest.

See the full report here: https://www.bankinfosecurity.com/ukraine-cyber-defenders-prepare-for-winter-a-23173?&web_view=true


New AtlasCross Hackers Use American Red Cross as Phishing Lure

The group's malware includes trojans named DangerAds and AtlasAgent, with AtlasAgent being a custom C++ trojan that can execute various commands and evade detection by security tools.

See the full report here: https://www.bleepingcomputer.com/news/security/new-atlascross-hackers-use-american-red-cross-as-phishing-lure/?&web_view=true


Critical JetBrains TeamCity Flaw Could Expose Source Code and Build Pipelines to Attackers

A critical security vulnerability in the JetBrains TeamCity continuous integration and continuous deployment (CI/CD) software could be exploited by unauthenticated attackers to achieve remote code execution on affected systems. The flaw, tracked as CVE-2023-42793, carries a CVSS score of 9.8 and has been addressed in TeamCity version 2023.05.4 following responsible disclosure on September 6 2023.

See the full report here: https://thehackernews.com/2023/09/critical-jetbrains-teamcity-flaw-could.html


Ukraine accuses Russian spies of hunting for war-crime info on its servers

The Ukrainian State Service of Special Communications and Information Protection (SSSCIP) has claimed that Russian cyberspies are targeting its servers looking for data about alleged Kremlin-backed war crimes.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/26/ukraine_russian_war_crimes_report/


All Of Sony Systems’ Allegedly Hacked By New Ransomware Group

A new gang on the dark web, known as Ransomed.vc, claims to have breached all of Sony's systems in a ransomware attack. The hackers allegedly uncovered screenshots, internal documents, and thousands of files, some of which are in Japanese.

See the full report here: https://kotaku.com/sony-playstation-hack-breach-ransomware-ransomed-vc-1850870993?&web_view=true


Fake Celebrity Photo Leak Videos Flood TikTok With Temu Referral Codes

Scammers have started creating videos implying leaked sensitive photos of celebrities and urging viewers to download the Temu app and enter their referral number to view the content. These scams have been targeting multiple celebrities.

See the full report here: https://www.bleepingcomputer.com/news/security/fake-celebrity-photo-leak-videos-flood-tiktok-with-temu-referral-codes/?&web_view=true


Xenomorph Android malware now targets U.S. banks and crypto wallets

Security researchers discovered a new campaign that distributes a new version of the Xenomorph malware to Android users in the United States, Canada, Spain, Italy, Portugal, and Belgium.

See the full report here: https://www.bleepingcomputer.com/news/security/xenomorph-android-malware-now-targets-us-banks-and-crypto-wallets/


ShadowSyndicate hackers linked to multiple ransomware ops, 85 servers

Security researchers have identified infrastructure belonging to a threat actor now tracked as ShadowSyndicate, who likely deployed seven different ransomware families in attacks over the past year. The researchers base their conclusions on a distinct SSH fingerprint they discovered on 85 IP servers, most of them tagged as Cobalt Strike command and control machines.

See the full report here: https://www.bleepingcomputer.com/news/security/shadowsyndicate-hackers-linked-to-multiple-ransomware-ops-85-servers/


SickKids impacted by BORN Ontario data breach that hit 3.4 million

The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. The top Canadian pediatric hospital disclosed that as a part of its operations, it shares personal health information with BORN Ontario "related to pregnancy, birth and newborn care." The BORN Ontario data breach that impacted 3.4 million people was caused by the exploitation of well-known zero-day vulnerability (CVE-2023-34362) in Progress MOVEIt Transfer software.

See the full report here: https://www.bleepingcomputer.com/news/security/sickkids-impacted-by-born-ontario-data-breach-that-hit-34-million/


Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign

A "multi-year" Chinese state-sponsored cyber espionage campaign has been observed targeting South Korean academic, political, and government organizations. Researchers tracking the activity under the moniker TAG-74, stated that the adversary has been linked to "Chinese military intelligence and poses a significant threat to academic, aerospace and defense, government sectors.

See the full report here: https://thehackernews.com/2023/09/chinese-hackers-tag-74-targets-south.html


Hackers Let Loose on Voting Gear Ahead of US Election Season

Ethical hackers were given voluntary access to digital scanners, ballot markers, and electronic pollbooks, all in the name of making the voting process more resilient to cyber threats ahead of next year's US Presidential Election.

See the full report here: https://www.darkreading.com/ics-ot/hackers-let-loose-voting-gear-us-election-season


NFL, CISA Look to Intercept Cyber Threats to Super Bowl LVIII

The NFL is working with more than 100 partners to workshop responses to a host of hypothetical cyberattacks on the upcoming Big Game in Las Vegas.

See the full report here: https://www.darkreading.com/ics-ot/nfl-cisa-intercept-cyber-threats-super-bowl-lviii


New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware

Apple recently addressed three zero-day vulnerabilities that were used as part of an iPhone exploit chain in an attempt to deliver spyware called Predator to a former Egyptian member of parliament.

See the full report here: https://thehackernews.com/2023/09/latest-apple-zero-days-used-to-hack.html?&web_view=true


Gelsemium APT Suspected Behind an Attack on Southeast Asian Government

A recent report by researchers reveals that a stealthy APT group known as Gelsemium likely targeted a Southeast Asian government between 2022 and 2023.

See the full report here: https://securityaffairs.com/151381/apt/gelsemium-apt-attack-southeast-asian-govt.html?&web_view=true


In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover

A critical vulnerability (CVE-2023-42793) in the TeamCity CI/CD server could allow unauthenticated attackers to execute code and take over vulnerable servers.

See the full report here: https://www.securityweek.com/in-the-wild-exploitation-expected-for-critical-teamcity-flaw-allowing-server-takeover/


From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese

Tibetan, Uyghur, and Taiwanese individuals and organizations are the targets of a persistent campaign orchestrated by a threat actor codenamed EvilBamboo to gather sensitive information. The attacker has created fake Tibetan websites, along with social media profiles, likely used to deploy browser-based exploits against targeted users.

See the full report here: https://thehackernews.com/2023/09/from-watering-hole-to-spyware.html


Gold Melody' Access Broker Plays on Unpatched Servers' Strings

Gold Melody performs reconnaissance on the victim environment, using Windows or Linux commands to display information about the host machine, user, directories and other details. It attempts to harvest credentials by using the Mimikatz pen-testing tool. Besides Mimikatz, Gold Melody has a suite of other open source tools at its disposal — like Wget, for retrieving files from a remote server — as well as those from the cybercrime underground — like "GOTROJ," a Golang-based remote access Trojan (RAT) useful in establishing persistence, performing reconnaissance, and executing arbitrary commands on a host machine.

See the full report here: https://www.darkreading.com/threat-intelligence/-gold-melody-access-broker-unpatched-servers


Mysterious "Sandman" APT Targets Telecom Sector With Novel Backdoor

Telecom companies can add one more sophisticated adversary to the already long list of advanced persistent threat (APT) actors they need to protect their data and networks against. The new threat is "Sandman," a group of unknown origin that surfaced mirage-like in August 2023 and has been deploying a novel backdoor using LuaJIT, a high-performance, just-in-time compiler for the Lua programming language.

See the full report here: https://www.darkreading.com/attacks-breaches/mysterious-sandman-apt-targets-telecom-sector-with-novel-backdoor


US govt IT help desk techie '"leaked top secrets" to foreign nation

A US government worker has been arrested and charged with spying for Ethiopia, according to court documents. The individual was detained on August 24 2023 after allegedly sending classified US national defense information to an Ethiopian intelligence agent. He has worked in various American government agencies since 2019.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/21/it_help_desk_guy_arrested/


High-Severity Flaws Uncovered in ISC BIND Server

ISC has released fixes for two high-severity bugs CVE-2023-28709 (CVSS 7.5) affecting the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could pave the way for a DoS condition.

See the full report here: https://thehackernews.com/2023/09/high-severity-flaws-uncovered-in.html?&web_view=true


Iranian Nation-State Actor OilRig Targets Israeli Organizations

Israeli organizations were targeted as part of two different campaigns orchestrated by the Iranian nation-state actor known as OilRig in 2021 and 2022. The campaigns, dubbed Outer Space and Juicy Mix, entailed the use of two previously documented first-stage backdoors called Solar and Mango, which were deployed to collect sensitive information from major browsers and the Windows Credential.

See the full report here: https://thehackernews.com/2023/09/iranian-nation-state-actor-oilrig.html


Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones

Apple announced that its latest operating system updates patch three new zero-day vulnerabilities. The zero-days are tracked as CVE-2023-41991, which allows a malicious app to bypass signature verification, CVE-2023-41992, a kernel flaw that allows a local attacker to elevate privileges, and CVE-2023-41993, a WebKit bug that can be exploited for arbitrary code execution by luring the targeted user to a malicious webpage.

See the full report here: https://www.securityweek.com/apple-patches-3-zero-days-likely-exploited-by-spyware-vendor-to-hack-iphones/


ZeroFox Intelligence Reports:


ZeroFox Intelligence Brief - India-Canada Tensions

In this intelligence brief, ZeroFox Geopolitical Working Group researchers provide an overview of recent tensions between India and Canada, in addition to possible short and long-term impacts of the tensions.

Report: https://zerofox.com/advisories/21946


Tags: tlp:clear,  all industries,  global, weekly bulletin