zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 31, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 31, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • 815 Million Indians’ Data on the Darknet — Possibly the Largest Data Breach in Indian History
  • FTC: Non-Banking Financial Institutions to Report Data-Security Breaches Within 30 Days
  • Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware
  • Data broker / initial-access broker / hacktivist group: BreachForums user cookiemonster and Exploit user nixploiter
  • Vulnerabilities: CVE-2023-5349 and CVE-2023-43792
  • Breaches: Combolist: 'Usa Dump[.]txt' (474,317 Records)

815 Million Indians’ Data on the Darknet — Possibly the Largest Data Breach in Indian History

A massive database containing sensitive personal information of about 815 million Indian citizens is being offered for sale on an underground hacking forum for USD 80,000. The package—which includes fields such as name, age, father’s name, Aadhaar (India’s national identity program) number, and passport details—has been suspected to be leaked from the Indian Council of Medical Research (ICMR) database. The past year has seen a number of high-profile data breaches relating to the Indian healthcare sector, including one from CoWin (India’s COVID-19 management and tracking platform) and a suspected Chinese ransomware attack on India’s premier medical college and hospital, All India Institute of Medical Sciences (AIIMS).

FTC: Non-Banking Financial Institutions to Report Data-Security Breaches Within 30 Days

An update to the Safeguards Rule will mandate non-banking financial institutions to report security breaches involving the information of at least 500 consumers to the U.S. Federal Trade Commission (FTC) no later than 30 days after discovery. The FTC’s Safeguards Rule seeks to secure customers’ information and thereby requires non-banking financial institutions (mortgage brokers, motor vehicle dealers, payday lenders, etc.) to maintain a detailed security program. The new rule comes into effect in April 2024, that is, 180 days after publication of the rule in the Federal Register.

Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware

Suspected pro-Hamas hackers have been observed deploying a new malware wiper dubbed BiBi-Linux Wiper in attacks on Israeli companies’ Linux systems. Security researchers have noted that this malware is an x64 ELF executable, lacking obfuscation or protective measures. This indicates the threat actor’s motive of causing maximum short-term harm without concerns about discovery or secrecy. If run with root permissions, the wiper can reportedly destroy the entire operating system. Earlier this year, various wipers were deployed by pro-Russian groups on specific Ukrainian systems.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-5349 A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick.
  • CVE-2023-43792 In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS.

BREACHES

Tags: DIB, tlp:green