ZeroFox Daily Intelligence Brief - October 27, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 27, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ANSSI: APT28 Modus operandi in attack campaigns since 2021
- BIG-IP warns of critical remote code execution vulnerability in BIG-IP
- Octo Tempest: An English-speaking, “dangerous” financial-crime group
- Data broker / initial-access broker / hacktivist group: Exploit user sandocan and Mysterious Team Bangladesh
- Vulnerabilities: CVE-2023-46818
- Exploits: CVE-2022-22954
- Breaches: Credit Card Data Breach: 2023-10-26 (e338f4 | 3271)
ANSSI: APT28 Modus Operandi in Attack Campaigns Since 2021
The National Cybersecurity Agency of France (ANSSI) has published an advisory detailing attacks conducted by Russia-linked APT 28 (Fancy Bear, STRONTIUM, etc.) since the second half of 2021. The group has been known to attack French governmental bodies, businesses, universities, research institutes, and think tanks. ANSSI reported that the attackers attempt to obfuscate their activity and reduce the rate of detection by targeting either poorly monitored systems or those located at the edge of a network. The advisory elaborates the tactics, techniques, and procedures (TTPs) used in these attacks and suggests protective measures.
F5 warns of critical remote code execution vulnerability in BIG-IP
F5 has warned customers of a critical remote code execution bug (CVE-2023-46747) in several versions of Big IP. The vulnerability could allow a remote unauthenticated attacker with network access to the big IP system to execute arbitrary commands. The company has stated that there is no data plane exposure; it is reportedly a ”control plane issue” only.
Octo Tempest: An English-speaking, “dangerous” financial-crime group
Security researchers have reported that an English-speaking hacker group called Octo Tempest conducts data-extortion and ransomware attacks on a wide range of industries. The group started with SIM swap and crypto-currency attacks and moved on to phishing, social-engineering, data theft, and password-reset attacks on breached service providers. The group even used direct physical threats to gain login credentials from victims. Based on its wide range of tactics, techniques and procedures, researchers are calling this one of the most dangerous financial criminal groups.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user sandocan: Selling network access to a German agricultural company
- Mysterious Team Bangladesh: Continues to attack Italian websites #OpItaly, supposedly in support of Palestine
VULNERABILITIES
- CVE-2023-46818: An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
EXPLOITS
- CVE-2022-22954: VMware Workspace ONE Access Template Injection / Command Execution
BREACHES
- Credit Card Data Breach: 2023-10-26 (e338f4 | 3271) Credit card
Tags: DIB, tlp:green