ZeroFox Daily Intelligence Brief - November 8, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 8, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence: Conclusions from 2023 and a Forecast for 2024
- TransForm Says Ransomware Data Breach Affected 267,000 Patients
- North Korea's BlueNoroff APT Debuts “Dumbed Down” macOS Malware
- Data broker / initial-access broker / hacktivist group: Exploit user mrbin22 and Exploit user budda12
- Vulnerabilities: CVE-2023-40101 and CVE-2023-21398
- Exploits: CVE-2022-25262
- Breaches: Combolist: 'NordVPN Premium.txt' (60 Records) and BreachForums: PubMatch Data Breach (25,691 Records)
ZeroFox Intelligence: Conclusions from 2023 and a Forecast for 2024
Key elections taking place in 2024 are expected to drive an increase in threat actor campaigns throughout the year, including an uptick in election-related scams, disruptive threats, and the spread of disinformation. Both malicious and non-malicious actors will likely increase their use of generative AI and synthetic media to create more effective and persuasive content during 2024 elections, exacerbating the threat posed by mis- and disinformation. It is also very likely that geopolitical factors will continue to influence the probability for major cyber events that can have severe or catastrophic physical impacts. Critical infrastructure sectors, such as finance, energy, and healthcare, will likely continue to see the greatest cyber-physical threats.
TransForm Says Ransomware Data Breach Affected 267,000 Patients
Not-for-profit shared service provider TransForm has disclosed details of a ransomware attack that affected operations of five hospitals in Ontario (Canada) last month. ZeroFox Intelligence had observed threat group DAIXIN claim responsibility for the attack. The attackers had claimed that the breach compromised names, dates of birth, medical record numbers, patient account numbers, Social Security numbers, and medical/treatment information and even suggested how the data can be abused (impersonation to create new financial and medical accounts, phishing, intrusions based on specific health data, and providing false information to police during an arrest). However, Bluewater Health—a hospital relying on Transform’s services that had 267,000 unique patients’ data compromised in the attack—reportedly had no clinical records breached in the attack.
North Korea's BlueNoroff APT Debuts “Dumbed Down” macOS Malware
North Korean threat group BlueNoroff, which is an arm of the infamous Lazarus Group, has been observed using a new Mac malware strain targeting users in the United States and Japan in a campaign dubbed “RustBucket.” Security researchers have observed the group use a malicious domain (swissborg[.]blog) that resembles a blog associated with a legitimate cryptocurrency exchange called SwissBorg (swissborg[.]com/blog). A simple reverse shell for Apple computers called ObjCShellz is used in the group’s attack chain for command execution from an attacker's server. BlueNoroff has been observed helping finance the North Korean regime by stealing money from banks, venture capital firms, cryptocurrency exchanges, and startups
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user mrbin22: Advertising remote desktop access to Brazilian food, beverage, and tobacco manufacturer
- Exploit user budda12: Selling network access to a U.S.-based tax services company
VULNERABILITIES
- CVE-2023-40101: There is a possible out of bounds read due to a missing bounds check
- CVE-2023-21398: In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code.
EXPLOITS
- CVE-2022-25262: JetBrains Hub single-click SAML response takeover
BREACHES
- Combolist: 'NordVPN Premium.txt' (60 Records) Email address and password
- BreachForums: PubMatch Data Breach (25,691 Records) Email address, password, name, and physical address
Tags: DIB, tlp:green