zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 6, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 6, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Okta Shares Details on Unauthorized Access to Support Case Management System
  • Apple “Find My” Network Can Be Abused to Steal Keylogged Passwords
  • StripedFly Malware Operated Unnoticed for 5 Years, Infecting 1 Million Devices
  • Data broker / initial-access broker / hacktivist group: Exploit user Expl0it_777 and XSS user Blackod
  • Vulnerabilities: CVE-2023-1073 and CVE-2023-47258
  • Exploits: CVE-2022-25765 and CVE-2022-23967
  • Breaches: BreachForums: PadSplit Data Breach (229,125 Records) and Combolist: 'Poland...txt' (161,816 Records)

Apple “Find My” Network Can Be Abused to Steal Keylogged Passwords

Identity and access management company Okta has revealed details of the October 2023 data breach in which a threat actor gained access to files inside Okta’s customer support system relating to 134 customers (which the company stated is less than 1% of its customer base). The attacker was ultimately able to steal some session tokens to hijack the legitimate Okta sessions of five unnamed customers. To combat the threat of session token theft, Okta has released session token binding based on network location. Okta administrators are now forced to re-authenticate if a network change is detected.

Okta Shares Details on Unauthorized Access to Support Case Management System

Security researchers have discovered a loophole that allows attackers to transmit arbitrary data over Apple’s “Find My” location tracking feature. The “Find My” network and application, which helps owners of Apple products recover misplaced devices, can be abused to exfiltrate sensitive data collected by threat actors via keyloggers. While there is no evidence of exploitation of this bug in the wild, Apple has reportedly fixed this vulnerability.

StripedFly Malware Operated Unnoticed for 5 Years, Infecting 1 Million Devices

Security researchers have identified an evasive and sophisticated malware strain that pretends to be just a cryptocurrency miner and has infected over a million devices around the world. The payload features a built-in TOR network tunnel for communication with command servers, update and delivery functionality through trusted services, as well as the ability to gather credentials every two hours, capture screenshots on the victim's device without detection, record microphone input, and start a reverse proxy to execute remote actions. It also comes with a Monero cryptocurrency miner that acts as a decoy to prevent security software from detecting the malware’s actual capabilities.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-1073: A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device.
  • CVE-2023-47258: Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

EXPLOITS

BREACHES

Tags: DIB, tlp:green