zerofox logo
Advisories

ZeroFox Weekly Threat Bulletin: 10/20/2023 - 10/26/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 10/20/2023 - 10/26/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - October 26, 2023

Brief Highlights

  • ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity
  • ZeroFox Intelligence Flash Report - Israel-Hamas War: Increased Risk to Brands From Doxxing
  • Winter Vivern Exploits Roundcube Web-mail Servers to Steal Government Emails
  • Data broker / initial-access broker / hacktivist group: KillNet and Team_insane_Pakistan
  • Vulnerabilities: CVE-2023-43615 and CVE-2023-0003
  • Exploits: CVE-2023-21839 and CVE-2023-32315
  • Data Breach: Credit Card Data Breach

Report: https://zerofox.com/advisories/22168


ZeroFox Daily Intelligence Brief - October 25, 2023

Brief Highlights

  • Flaws in Certain Implementations of Industry-Standard OAuth
  • South-Western Ontario Hospitals Reschedule Appointments After Cyberattack
  • Scammers Exploit Israel-Hamas War for Donation Scams
  • Data broker / initial-access broker / hacktivist group: Exploit user SHERIFF and Exploit user Howell
  • Vulnerabilities: CVE-2023-46006 and CVE-2023-45602
  • Exploits: CVE-2023-36844 and CVE-2023-2982
  • Data Breach: Combolist: '200K+ MIXED COMBOLIST.txt'

Report: https://zerofox.com/advisories/22159


ZeroFox Daily Intelligence Brief - October 24, 2023

Brief Highlights

  • “Grandoreiro” Trojan Expands Global Reach
  • ZeroFox: Russia-Ukraine Conflict Update (October 23, 2023)
  • 1Password Reports Suspicious Activity Tied to Okta Security Incident, Confirms no Data Breach
  • Data broker / initial-access broker / hacktivist group: Anonymous Algeria and BreachForums user r57
  • Vulnerabilities: CVE-2023-45966 and CVE-2023-27152
  • Exploits: CVE-2023-34039 and CVE-2023-32243
  • Data Breach: Combolist: 'blockchain.com12.txt' and Telegram: 'ArtHouse Cloud Free Logs 20.zip' Botnet Breach

Report: https://zerofox.com/advisories/22149


ZeroFox Daily Intelligence Brief - October 23, 2023

Brief Highlights

  • ZeroFox Intelligence Flash Report - Governments Worldwide Issue Caution Alerts for Travel
  • American Family Insurance Takes Down IT Systems Following Cyberattacks
  • Okta Releases Advisory on Breach of Support System
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan and BlackDragonSec
  • Vulnerabilities: CVE-2023-44488 and CVE-2023-37536
  • Exploits: CVE-2023-27350 and CVE-2023-28121
  • Data Breach: BreachForums: NORRIQ Data Breach and Airtel Data Breach

Report: https://zerofox.com/advisories/22137


ZeroFox Daily Intelligence Brief - October 21, 2023

Brief Highlights

  • Europol Strike Wounds RagnarLocker Ransomware Group
  • Telegram Exploit Allows Hackers to Leak IP Addresses Through Calls
  • India targets Microsoft, Amazon tech support scammers in nationwide crackdown
  • Data broker / initial-access broker / hacktivist group: Exploit users: maveboy and nixploiter
  • Vulnerabilities: CVE-2023-3389 and CVE-2023-2124
  • Data Breach: Telegram: 'фб.zip' Botnet Breach and 'Erernity&Team [FREE LOGS].rar' Botnet Breach

Report: https://zerofox.com/advisories/22123


ZeroFox Daily Intelligence Brief - October 20, 2023

Brief Highlights

  • Casio Confirms Data Breach of Customers Across 149 Countries
  • Five Eyes intelligence Chiefs Warn on China's “Theft” of Intellectual Property
  • CISA, NSA, FBI, and MS-ISAC Release Update to #StopRansomware Guide
  • Data broker / initial-access broker / hacktivist group: Exploit users: maveboy and Roblette
  • Vulnerabilities: CVE-2023-45822 and CVE-2023-27795
  • Exploits: CVE-2023-3460 and CVE-2023-23488
  • Data Breach: Telegram: '1000 LOGS 2022 #1q16.rar' Botnet Breach

Report: https://zerofox.com/advisories/22121


Breach Disclosures:


Ongab

An alleged data breach at Ongab – a Russia-based gaming website – exposed 147,159 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/22177


Airtel

An alleged data breach at Airtel – a global mobile operator company – exposed 7,847 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/22127


Exodus

An alleged data breach at Exodus – a U.S.-based crypto and bitcoin wallet software provider – exposed 2,937,867 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/22125


NORRIQ

An alleged data breach at NORRIQ – a Belgium-based IT service management company – exposed 53,529 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/22124


Geometry Dash Forum

An alleged data breach at Geometry Dash Forum – a U.S.-based gaming discussion forum – exposed 7,366 email addresses which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/22122


Breaking News:


Over 9,500 Bank of Canton Customers May Have had Personal Information Exposed Due to Vendor Breach

The breach was caused by a vulnerability in Fiserv's MOVEit managed file transfer application. Fiserv has patched the vulnerability, and the bank is monitoring its networks for unusual activity.

See the full report here: https://news.yahoo.com/over-9-500-bank-canton-194312091.html?&web_view=true


Flipper Zero can now spam Android, Windows users with Bluetooth alerts

A custom Flipper Zero firmware called "Xtreme" has added a new feature to perform Bluetooth spam attacks on Android and Windows devices.

See the full report here: https://www.bleepingcomputer.com/news/security/flipper-zero-can-now-spam-android-windows-users-with-bluetooth-alerts/


CISA budget cuts would be “catastrophic,” official says

A top Cybersecurity and Infrastructure Security Agency official stated that potential budget cuts to the nation’s threat advisor agency would be “catastrophic.” The official further stated that U.S. adversaries “would unequivocally exploit” security gaps created by proposed 25% cut to cyber agency.

See the full report here: https://cyberscoop.com/cisa-budget-cuts-catastrophic/


Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacks

Russia-linked threat actor Winter Vivern has been observed exploiting a zero-day flaw (CVE-2023-5631) in Roundcube webmail software to steal government emails.

See the full report here: https://securityaffairs.com/153030/apt/winter-vivern-0day-roundcube.html


YoroTrooper: Researchers Warn of Kazakhstan's Stealthy Cyber Espionage Group

A relatively new threat actor known as YoroTrooper is likely made of operators originating from Kazakhstan. The assessment, is based on their fluency in Kazakh and Russian, use of Tenge to pay for operating infrastructure, and very limited targeting of Kazakhstani entities, barring the government's Anti-Corruption Agency.

See the full report here: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html


Critical Flaw in NextGen's Mirth Connect Could Expose Healthcare Data

Users of Mirth Connect, an open-source data integration platform from NextGen HealthCare, are being urged to update to the latest version following the discovery of an unauthenticated remote code execution vulnerability. Tracked as CVE-2023-43208, the vulnerability has been addressed in version 4.4.1 released on October 6, 2023

See the full report here: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html


Iranian Group Tortoiseshell Launches New Wave of IMAPLoader Malware Attacks

The Iranian threat actor known as Tortoiseshell has been attributed to a new wave of watering hole attacks that are designed to deploy a malware dubbed IMAPLoader. IMAPLoader is a .NET malware that has the ability to fingerprint victim systems using native Windows utilities and acts as a downloader for further payloads.

See the full report here: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html


Hunters International leaks pre-op plastic surgery pics

A newly emerged ransomware gang claims to have successfully gained access to the systems of a US plastic surgeon's clinic, leaking patients' pre-operation pictures in an attempt to hurry a ransom payment. The group, calling itself Hunters International, has claimed attacks on only two victims so far, with the first – a UK primary school – appearing earlier in October 2023.

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/25/rebuilt_hive_ransomware_gang_stings/


Malvertising Campaign Targets Brazil's PIX Payment System with GoPIX Malware

The popularity of Brazil's PIX instant payment system has made it a lucrative target for threat actors looking to generate illicit profits using a new malware called GoPIX. Kaspersky, which has been tracking the active campaign since December 2022, said the attacks are pulled off using malicious ads that are served when potential victims search for "WhatsApp web" on search engines.

See the full report here: https://thehackernews.com/2023/10/malvertising-campaign-targets-brazils.html


Samsung Galaxy S23 Hacked Twice on First Day of Pwn2Own 2023 in Toronto

Security researchers hacked the Samsung Galaxy S23 twice during the first day of the consumer-focused Pwn2Own 2023 hacking contest in Toronto, Canada. They also demoed exploits and vulnerability chains targeting zero-days in Xiaomi's 13 Pro smartphone, as well as printers, smart speakers, Network Attached Storage (NAS) devices, and surveillance cameras from Western Digital, QNAP, Synology, Canon, Lexmark, and Sonos.

See the full report here: https://www.bleepingcomputer.com/news/security/samsung-galaxy-s23-hacked-twice-on-first-day-of-pwn2own-toronto/?&web_view=true


Act Now: VMware Releases Patch for Critical vCenter Server RCE Vulnerability

VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems. The issue, tracked as CVE-2023-34048 (CVSS score: 9.8), has been described as an out-of-bounds write vulnerability in the implementation of the DCE/RPC protocol.

See the full report here: https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXqKwLhbe0od6IDn2CoDpP_cNFZ5qSvZrPKlPaeUdOdm598VFLh9OaMU2_MGTT6WCDpN87vBavgGVpEzNxHLaL2oAjvbZqK6Awt_Ia7MTsvKRFcB3pCJL38ZgTyiSn5a9hhn5G3vX3tmjzksWGcfLHBOZ-7_i_vPi3OLpfwOeGtjSQOoe9bTxC5BUx_BkI/s1600/hacking.jpg


Hackers Backdoor Russian State, Industrial Organizations for Data Theft

Russian state organizations and industrial sectors have been targeted with a custom Go-based backdoor. The backdoor, distributed through phishing emails, steals data, including passwords from popular web browsers and the Thunderbird email client.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-backdoor-russian-state-industrial-orgs-for-data-theft/?&web_view=true


French Basketball Team ASVEL Confirms Data Breach After Ransomware Attack

French professional basketball team LDLC ASVEL (ASVEL) has confirmed that data was stolen after the NoEscape ransomware gang claimed to have attacked the club. ASVEL's says that they were alerted to a potential breach on October 12 via the press, following their addition to NoEscape ransomware's extortion portal on October 9, 2023.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-backdoor-russian-state-industrial-orgs-for-data-theft/?&web_view=true


Five Southwestern Ontario Hospitals Hit by Cyberattack, Patient Appointments to be Rescheduled

The attacks occurred through an initial compromise of a hospital supply-chain and IT services provider, who stated that it is investigating the "cause and scope of incident, including whether any patient information was affected." All of the impacted hospitals released a joint statement on 23 October 2023, noting that they might not be able to directly reach all patients ahead of time and might have to reschedule appointments for people in person.

See the full report here: https://www.cbc.ca/news/canada/windsor/windsor-hospital-system-1.7005158?&web_view=true


Palestine crypto donation scams emerge amid Israel-Hamas war

As thousands of civilians die amid the deadly Israel-Hamas war, scammers are capitalizing on the horrific events to collect donations by pretending to be legitimate charities.

See the full report here: https://www.bleepingcomputer.com/news/security/palestine-crypto-donation-scams-emerge-amid-israel-hamas-war/


City of Philadelphia Releases Cyber-Breach Notice

In a privacy incident notice, the city of Philadelphia wrote that "the types of information impacted vary by individual. However, the types of information impacted could include: demographic information, such as name, address, date of birth, social security number, and other contact information; medical information, such as diagnosis and other treatment related information; and limited financial information, such as claims information."

See the full report here: https://eu-images.contentstack.com/v3/assets/blt66983808af36a8ef/blt783351c79ebf9d41/6536c4f39adb372cac5bbb82/philadelphia_Sean_Pavone_alamy.jpg


China Crackdown on Cyber Scams in Southeast Asia Nets Thousands but Leaves Networks Intact

Chinese authorities have netted thousands of people in a crackdown on cyber scams, but the criminal networks remain intact. These individuals, mostly operated across Southeast Asia along with local scamsters to lure Chinese and international individuals to various kinds of scams. In total, China has detained some 4,000 suspects and returned them back to China.

See the full report here: https://www.securityweek.com/china-crackdown-on-cyber-scams-in-southeast-asia-nets-thousands-but-leaves-networks-intact/


Scammers use India’s real-time payment system to siphon off money, send it to China

China-based scammers are using a combination of fake loan apps and India's real-time mobile payment system, Unified Payments Interface (UPI), to separate victims from their cash,

See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/24/scammers_use_indias_realtime_payment/


PII Belonging to Indian Citizens, Offered for Sale on the Dark Web

Hundreds of millions of PII records belonging to Indian residents, including Aadhaar cards (national identification documentation), are being offered for sale on the Dark Web.

See the full report here: https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


34 Cybercriminals Arrested in Spain for Multi-Million Dollar Online Scams

Spanish law enforcement officials have announced the arrest of 34 members of a criminal group that carried out various online scams, netting the gang about EUR 3 million (USD 3.2 million) in illegal profits.

See the full report here: https://thehackernews.com/2023/10/34-cybercriminals-arrested-in-spain-for.html


iOS Zero-Day Attacks: Experts Uncover Deeper Insights into Operation Triangulation

The TriangleDB implant was used to target Apple iOS devices packs in at least four different modules to record microphone, extract iCloud Keychain, steal data from SQLite databases used by various apps, and estimate the victim's location.

See the full report here: https://thehackernews.com/2023/10/operation-triangulation-experts-uncover.html


Backdoor Implant on Hacked Cisco Devices Modified to Evade Detection

Further investigation revealed that the backdoor implanted on Cisco devices by exploiting a pair of zero-day flaws in IOS XE software has been modified by the threat actor so as to escape visibility via previous fingerprinting methods. Investigated network traffic to a compromised device has shown that the threat actor has upgraded the implant to do an extra header check, so that devices only responds if the correct Authorization HTTP header is set.

See the full report here: https://thehackernews.com/2023/10/backdoor-implant-on-hacked-cisco.html?&web_view=true


Okta Says Hackers Breached its Support System and Viewed Customer Files

Hackers gained access to Okta's customer support management system, allowing them to view private customer information, including sensitive data such as cookies and session tokens.

See the full report here: https://arstechnica.com/security/2023/10/okta-says-hackers-breached-its-support-system-and-viewed-customer-files/?&web_view=true


D.C. Board of Elections: Hackers may have breached entire voter roll

The District of Columbia Board of Elections (DCBOE) says that a threat actor who breached a web server operated by the DataNet Systems hosting provider in early October 2023, may have obtained access to the personal information of all registered voters.

See the full report here: https://www.bleepingcomputer.com/news/security/dc-board-of-elections-hackers-may-have-breached-entire-voter-roll/


Thousands of drivers have sensitive data exposed to hackers in major IT breach

The driving licences of thousands of Irish motorists who had vehicles towed on behalf of the state police were exposed in a major data breach. More than half a million documents exposed include details of insurance investigations, vehicle registration certs, notices of car seizures and payment card details. The breach was caused by a software error at a Limerick-based IT services firm, which is retained by tow-truck companies working for An Garda Síochána.

See the full report here: https://www.independent.ie/irish-news/thousands-of-drivers-have-sensitive-data-exposed-to-hackers-in-major-it-breach/a1379036136.html


SIM Card Ownership Slashed in Burkina Faso to Prevent Spam

Burkina Faso aims to increase mobile security in the African country with a new bill that says users can only hold two SIM cards (i.e., lines of service) from a mobile provider, while the sale of SIM cards can only be made in approved agencies and points of sale.

See the full report here: https://www.darkreading.com/dr-global/sim-card-ownership-slashed-in-burkina-faso


AI Chatbots Can Guess Your Personal Information From What You Type

Researchers found that the large language models that power advanced chatbots can accurately infer an alarming amount of personal information about users—including their race, location, occupation, and more—from conversations that appear innocuous. The phenomenon appears to stem from the way the models’ algorithms are trained with broad swathes of web content, a key part of what makes them work, likely making it hard to prevent.

See the full report here: https://www.wired.com/story/ai-chatbots-can-guess-your-personal-information/


Threat actor is selling access to Facebook and Instagram's Police Portal

A threat actor is selling access to Facebook and Instagram’s Police Portal used by law enforcement agencies to request data relating to users under investigation. The portal allows law enforcement agencies to request data relating to users (IP, phones, DMs, device info) or request the removal of posts and the ban of accounts.

See the full report here: https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html


New TetrisPhantom hackers steal data from secure USB drives on govt systems

The attack involves the deployment of a trojanized version of the UTetris application, which acts as a loader for malware and facilitates the spread of the attack to potentially air-gapped systems.

See the full report here: https://www.bleepingcomputer.com/news/security/new-tetrisphantom-hackers-steal-data-from-secure-usb-drives-on-govt-systems/


Fraudulent KeePass Site Uses Google Ads and Punycode to Transfer Malware

A Google Ads campaign was discovered promoting a phoney KeePass download site that transferred malware by posing as the real KeePass domain, making it difficult for even the most vigilant and security-conscious consumers to identify the problem.

See the full report here: https://www.cysecurity.news/2023/10/fraudulent-keepass-site-uses-google-ads.html


Don't use AI-based apps, Philippine defense ordered its personnel

The Philippine defense warned of the risks of using AI-based applications to generate personal portraits and ordered its personnel to stop using them. At this time, it remains unclear whether the order was issued in response to a specific event or to address potential attacks aimed at exploiting the data collected by these applications. The order remarks that these AI-based applications pose significant privacy and security risks.

See the full report here: https://securityaffairs.com/152866/intelligence/philippine-defense-ai-based-apps.html


City of Philadelphia discloses data breach after five months

The City of Philadelphia is investigating a data breach after attackers "may have gained access" to City email accounts containing personal and protected health information five months ago, in May 2023.

See the full report here: https://www.bleepingcomputer.com/news/security/city-of-philadelphia-discloses-data-breach-after-five-months/


BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks

The BlackCat/ALPHV ransomware operation has begun to use a new tool named "Munchkin" that utilizes virtual machines to deploy encryptors on network devices stealthily. Manchkin enables BlackCat to run on remote systems or encrypt remote Server Message Block (SMB) or Common Internet File (CIFS) network shares.

See the full report here: https://www.bleepingcomputer.com/news/security/blackcat-ransomware-uses-new-munchkin-linux-vm-in-stealthy-attacks/


E-Root admin faces 20 years for selling stolen RDP, SSH accounts

The operator of the E-Root marketplace, has been extradited to the U.S. to face a maximum imprisonment penalty of 20 years for selling access to compromised computers. The Moldovan defendant was arrested in the U.K. in May 2021 while attempting to flee the country following the authorities' seizure of E-Root's domains in late 2020. The individual consented to be extradited to the United States for wire fraud, money laundering, computer fraud, and access device fraud.

See the full report here: https://www.bleepingcomputer.com/news/security/e-root-admin-faces-20-years-for-selling-stolen-rdp-ssh-accounts/


NSA delivers recommendations for maturing devices using zero trust device pillar within security framework

The U.S. National Security Agency (NSA) published a Cybersecurity Information Sheet (CSI) covering zero trust security framework that enables federal agencies, partners, and organizations to assess devices in their systems and be better poised to respond to risks associated with critical resources. The document provides recommendations for maturing devices using the zero trust device pillar to ensure that devices seeking access earn trust based on device metadata and continual checks to determine if the device meets the organization’s minimum bar for access.

See the full report here: https://industrialcyber.co/zero-trust/nsa-delivers-recommendations-for-maturing-devices-using-zero-trust-device-pillar-within-security-framework/


Casio Discloses Data Breach Impacting Customers in 149 Countries

Japanese electronics manufacturer Casio disclosed a data breach impacting customers from 149 countries after hackers gained to the servers of its ClassPad education platform. Casio detected the incident on October 11, 2023 following the failure of a ClassPad database within the company's development environment. Evidence suggests that the attacker accessed customers' personal information a day later, on October 12, 2023.

See the full report here: https://www.bleepingcomputer.com/news/security/casio-discloses-data-breach-impacting-customers-in-149-countries/?&web_view=true


RagnarLocker Ransoms Its Last Victim as Law Enforcement Takes Down its Leak Site

Law enforcement agencies have taken over RagnarLocker ransomware group's leak site in an internationally coordinated takedown. Among the agencies involved are Europol's European Cybercrime Centre (EC3), the US's Federal Bureau of Investigation (FBI), and Germany's Bundeskriminalamt (BKA), among many others.The takedown follows a concerted effort from law enforcement in recent years to shutter ransomware groups as their success continues to exceed previous records.

See the full report here: https://regmedia.co.uk/2019/02/04/shutterstock_keyboard_cops.jpg


Fake Corsair job offers on LinkedIn push DarkGate malware

A threat actor is using fake LinkedIn posts and direct messages about a Facebook Ads specialist position at hardware maker Corsair to lure people into downloading info-stealing malware like DarkGate and RedLine. Cybersecurity researchers detected the activity and tracked the activity of the group, showing in a report today that it is linked to Vietnamese cybercriminal groups responsible for the "Ducktail" campaigns first spotted in 2022.

See the full report here: https://www.bleepingcomputer.com/news/security/fake-corsair-job-offers-on-linkedin-push-darkgate-malware/


ZeroFox Intelligence Reports:


ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity

In this Intelligence Brief, ZeroFox researchers provide updates on Iranian APT activity observed in the last few months, as well as expected activity in the wake of the Israel-Hamas War.

Report: https://zerofox.com/advisories/22167


ZeroFox Intelligence Flash Report - Israel-Hamas War: Increased Risk to Brands From Doxxing

In this Intelligence Flash Report, ZeroFox researchers report on a trend they have identified around an increase in doxxing incidents tied to an individual or company’s perceived stance on the Israel-Hamas war.

Report: https://zerofox.com/advisories/22166


ZeroFox Intelligence Assessment - Russia-Ukraine Conflict Update

In this ZeroFox Intelligence Assessment, ZeroFox researchers provide updates on the ongoing conflict in Ukraine, including the current state of the counteroffensive, risks to businesses operating in Russia and Ukraine, and a forward look towards the winter, Western aid, and the risk of a frozen conflict.

Report: https://zerofox.com/advisories/22148


ZeroFox Intelligence Flash Report - Governments Worldwide Issue Caution Alerts for Travel

In this flash report, ZeroFox researchers provide updates on recent travel alerts released by governments worldwide in the wake of the Israel-Hamas War and subsequent protests and terrorist activities.

Report: https://zerofox.com/advisories/22135


Tags: tlp:clear, all industries, global