zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 10, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 10, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Pro-Hamas Hackers Abuse Alert Service to Send Fake Missile Alerts
  • Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS
  • Linux Distributions Running Gnome Affected by Audio Metadata Exploit
  • Data broker / initial-access broker / hacktivist group: Exploit user mute and Exploit user Th1nkAb0ut
  • Vulnerabilities: CVE-2023-44826 and CVE-2020-18336
  • Breaches: Credit Card Data Breach and Combolist: 'THEBIG_3.txt'

Pro-Hamas Hackers Abuse Alert Service to Send Fake Missile Alerts

Pro-Palestinian hacker group AnonGhost is targeting the "Red Alert" app, designed to deliver missile alerts to Israelis by exploiting an API vulnerability. The group intercepted requests and sent false spam missile alerts to users. AnonGhost also sent fabricated messages about a "nuclear bomb" attack. While the group claimed to disconnect users' phones from the internet, these claims are unverified. The Android version of the Red Alert app has been removed for unknown reasons while the iOS version remains available for download.

Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS

The ad fraud botnet "PEACHPIT" utilized hundreds of thousands of Android and iOS devices to generate illicit profits for its operators. Part of the China-based BADBOX operation, it involved selling off-brand mobile and CTV devices infected with the Triada malware. The botnet's apps were found in 227 countries, with an estimated peak of 121,000 daily Android and 159,000 iOS devices. The campaign altogether delivered over four billion ads a day – all invisible to users. It infected devices through 39 apps that have been installed over 15 million times, enabling data theft, residential proxy creation, and ad fraud.

Linux Distributions Running Gnome Affected by Audio Metadata Exploit

A memory corruption vulnerability in the libcue library exposes GNOME Linux systems to arbitrary code execution. The library is integrated into the Tracker Miners file indexer in GNOME, affecting widely used Linux distributions. Attackers exploit the flaw (CVE-2023-43641) by tricking users into downloading a malicious .CUE file, which triggers the vulnerability during automatic parsing by Tracker Miners. A proof-of-concept exploit has been created but will be delayed to allow developers to release fixes and for users to secure their systems. Successful exploitation poses risks to the latest major Linux releases, including Debian, Fedora, and Ubuntu.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-44826 :: Cross Site Scripting vulnerability in ZenTaoPMS v.18.6
  • CVE-2020-18336:: Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information

BREACHES

Tags: DIB, tlp:green