zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 2, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 2, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hackers Use Citrix Bleed Flaw in Attacks on Government Networks Worldwide
  • North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware
  • Boeing Confirms Cyberattack and System Compromise
  • Data broker / initial-access broker / hacktivist group: Exploit user yesdaddy and Garuda Security
  • Vulnerabilities: CVE-2022-41249 and CVE-2023-46428
  • Exploits: CVE-2022-22963
  • Breaches: BreachForums: ORNII Innovation Data Breach and Clarahair Data Breach

Hackers Use Citrix Bleed Flaw in Attacks on Government Networks Worldwide

Security researchers have observed at least four ongoing campaigns exploiting “Citrix Bleed,” a critical severity flaw (CVE-2023-4966) affecting Citrix NetScaler ADC and NetScaler Gateway (which was disclosed on October 10, 2023). While these attacks have been significantly stealthy and left behind sparse forensic evidence, researchers have observed post-exploitation activity that indicates credential theft and lateral movement. Tens of thousands of exploited servers have been reportedly observed, with attacks originating from over a hundred individual IP addresses. Moreover, ongoing attacks would require a full incident response, as deploying the available patches will not secure already breached systems.

North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware

Threat actors are attempting to compromise systems of blockchain engineers working for a cryptocurrency exchange using a supposed “arbitrage bot” as a lure. The campaign—which has been linked to North Korean state-sponsored group Lazarus—involves the attackers masquerading as blockchain developers on a public Discord server. The attackers use social-engineering tricks to convince the victims to download and execute a ZIP archive, which infects their systems with an advanced and hard-to-detect macOS implant KANDYKORN.

Boeing Confirms Cyberattack and System Compromise

Boeing has reportedly confirmed that it is aware of a cyber incident impacting elements of its parts and distribution business. This follows Russia-linked ransomware group LockBit’s addition—and subsequent removal—of Boeing on its leak site. While LockBit had not disclosed details of the systems or data it allegedly compromised, it claimed to have stolen “a tremendous amount of sensitive data'' from the company. Boeing stated that it is currently notifying customers and suppliers about the incident and asserted that flight safety was not affected. Removal of a victim’s name from a ransomware leak site often indicates ongoing negotiations; meanwhile, the admins of a well-known online malware library also claim to have been informed by LockBit that Boeing’s name has been removed because negotiations have started.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit user yesdaddy: Advertising network access to a U.S.-based building materials company
  • Garuda Security: Allegedly defaced some American websites under #OpUsa and #OpAmerica and posted anti-Israel messages

VULNERABILITIES

  • CVE-2022-41249: A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier
  • CVE-2023-46428: An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to execute arbitrary code via a crafted file

EXPLOITS

BREACHES

Tags: DIB, tlp:green