zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 24, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 24, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • “Grandoreiro” Trojan Expands Global Reach
  • ZeroFox: Russia-Ukraine Conflict Update (October 23, 2023)
  • 1Password Reports Suspicious Activity Tied to Okta Security Incident, Confirms no Data Breach
  • Data broker / initial-access broker / hacktivist group: Anonymous Algeria and BreachForums user r57
  • Vulnerabilities: CVE-2023-45966 and CVE-2023-27152
  • Exploits: CVE-2023-34039 and CVE-2023-32243
  • Data Breach: Combolist: 'blockchain.com12.txt' and Telegram: 'ArtHouse Cloud Free Logs 20.zip' Botnet Breach

“Grandoreiro” Trojan Expands Global Reach

Banking trojan, "Grandoreiro," previously known for targeting financial institutions in Brazil and Mexico, has expanded its reach to Spain. Operators of the trojan (a group tracked as "TA2725”) deploy bank-account and credit-card sniffing malware via phishing emails that mimic documents, utility bills, or tax forms from reputable institutions. Grandoreiro can steal data through keyloggers, screen grabbers, or overlay attacks on banking pages. The trend of malware originating in Brazil and expanding across continents was previously observed in campaigns such as "Operation Magalenha" in Portugal. The attack follows an uptick in cybercrime in Latin America, with 360 billion attempted attacks recorded across the past two years, primarily in Mexico and Brazil.

ZeroFox: Russia-Ukraine Conflict Update (October 23, 2023)

In its conflict update, ZeroFox notes that Ukraine has achieved mixed successes across the three axes of advance. However, Ukrainian forces are unlikely to reach the Sea of Azov in the short term. Historical trends indicate that the war risks developing into a frozen conflict. Russia likely favors freezing the current frontlines while it rebuilds its forces and military industrial complex. Western support for Ukraine shows signs of dwindling. Additionally, the Israel-Hamas war will likely draw Western focus away from Ukraine.

1Password Reports Suspicious Activity Tied to Okta Security Incident, Confirms no Data Breach

Password-management platform 1Password, used by over 100,000 businesses worldwide, has disclosed that it observed suspicious activity in its Okta instance on September 29, 2023. A joint investigation with Okta revealed that the attack resembled campaigns where attackers use compromised admin credentials to conduct reconnaissance and impersonation of legitimate users for further attacks. 1Password took several measures to secure its systems and confirmed that no user data was accessed.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Anonymous Algeria:: Claims to have accessed the control system of the Knesset (Israel's house of representatives)
  • BreachForums user r57:: Selling a database allegedly stolen from the Ministry of Health of Lebanon

VULNERABILITIES

  • CVE-2023-45966:: mputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.
  • CVE-2023-27152:: OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

EXPLOITS

  • CVE-2023-34039:: VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE
  • CVE-2023-32243:: Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

BREACHES

Tags: DIB, tlp:green