ZeroFox Daily Intelligence Brief - November 4, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 4, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Assessment - 2023 APEC Economic Leaders' Summit
- Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign
- Ace Hardware says 1,202 Devices Hit During Cyberattack
- Data broker / initial-access broker / hacktivist group: Exploit user sandocan and Cyber Army of Russia
- Vulnerabilities: CVE-2023-45018 and CVE-2023-2979
- Exploits: CVE-2022-27226
- Breaches: Credit Card Data Breach: Leakbase: Alsannat Data Breach (32,061 Records) and Leakbase: Au fil des Couleurs Data Breach (68,812 Records)
ZeroFox Intelligence Assessment - 2023 APEC Economic Leaders' Summit
The 2023 Asia-Pacific Economic Cooperation (APEC) Economic Leaders’ Summit will take place in San Francisco from November 11 to 17. The summit has been classified as a National Special Security Event by the U.S. Secret Service because of the number of U.S. and foreign dignitaries attending the event, as well as its size and significance. The event has the potential to see criminal and security issues, particularly in light of the current geopolitical tensions throughout the world. Moreover, politically motivated hacktivists could attempt to disrupt the event, as hacktivists often target high-profile events that garner a global audience to gain notoriety and maximum exposure (“clout”).
Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign
A threat actor group variously tracked as MuddyWater, Mango Sandstorm, and Static Kitten is luring Israeli entities using a file purporting to be an official memo from the Israeli Civil Service Commission—to deploy a legitimate remote administration tool called Advanced Monitoring Agent. The threat group has been active since at least 2017 and is linked to Iran’s Ministry of Intelligence and Security (MOIS), to which other threat clusters like OilRig, Lyceum, Agrius, and Scarred Manticore are also affiliated.
Ace Hardware says 1,202 Devices Hit During Cyberattack
Global retailer-owned cooperative Ace Hardware has disclosed that a cybersecurity incident affected the majority of its IT systems, leading to the interruption or suspension of several services. While in-store POS systems and credit card processing are unaffected, the outage has disrupted scheduled deliveries; the company is reportedly unable to process new orders from retailers at the moment. Meanwhile, not letting a good crisis go to waste, scammers are trying to dupe Ace Hardware retailers and steal their network credentials—by posing as IT troubleshooters or offering “alternative” electronic payment addresses to redirect payments.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user sandocan: Advertising remote desktop access to an Australian electronics manufacturing company
- Cyber Army of Russia: Declared a cyberwar against Poland and started targeting the government and critical infrastructure
VULNERABILITIES
- CVE-2023-45018: The “username” parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.
- CVE-2023-2979: A critical vulnerability in Abstrium Pydio Cells 4.2.0 affects an unknown part of the component User Creation Handler.
EXPLOITS
- CVE-2022-27226: iRZ Mobile Router Cross Site Request Forgery / Remote Code Execution
BREACHES
- Leakbase: Alsannat Data Breach (32,061 Records) Email address, date of birth, gender, name, phone number, and physical address
- Leakbase: Au fil des Couleurs Data Breach (68,812 Records) Email address, name, company name, and user activity
Tags: DIB, tlp:green