zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 11, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 11, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA, NSA, and Partners Release New Guidance on Securing the Software Supply Chain
  • ZeroFox Intelligence Regional Assessment: Sub-Saharan Africa
  • Malvertiser Disguised as Legitimate Windows News Portal Delivering Malicious Installer
  • Data broker / initial-access broker / hacktivist group: Exploit user mrbin228
  • Vulnerabilities: CVE-2023-21396 and CVE-2023-21331
  • Exploit: CVE-2022-24706
  • Breach: Combolist: '57k_canada.txt' (56,634 Records)

CISA, NSA, and Partners Release New Guidance on Securing the Software Supply Chain

U.S. cybersecurity authorities have published an advisory to provide software developers and suppliers with industry best practices and principles, including managing open-source software and software bills of materials (SBOM). The guidelines can help organizations assess and measure their security practices relative to the software lifecycle and can be applied across the acquisition, deployment, and operational phases of a software supply chain. CISA urges defenders to speak to their software vendors about implementing the provided recommendations.

ZeroFox Intelligence Regional Assessment: Sub-Saharan Africa

ZeroFox Intelligence notes that Africa’s youthful and growing population will likely be targeted by sectors that have maximized their growth elsewhere. A continent-wide free trade agreement from 2021 could alleviate many of Africa’s supply chain challenges, if fully implemented. Cyber protections have not developed alongside mobile money and online banking advancements. Sub-Saharan Africa has some of the highest usage of mobile money transfers in the world but also some of highest rates of cyberattacks on those platforms. Similar risks will threaten nascent energy and mining companies.

Malvertiser Disguised as Legitimate Windows News Portal Delivering Malicious Installer

A new malvertising campaign distributes a malicious installer for a popular system profiling tool called CPU-Z by employing fake sites purporting to be a legitimate Windows news portal. The campaign lures unsuspecting users searching for CPU-Z on search engines via a clickable ad. The ad redirects the victim to a download page masquerading as the legitimate site. On clicking the “Download Now” button, the user receives a digitally-signed CPU-Z installer (MSI file) containing a malicious PowerShell script identified as the “FakeBat” malware loader, which serves as a medium to deploy a powerful stealer called RedLine on the user’s compromised device.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-21396: A possible background activity launch due to a logic error in the code in Activity Manager could lead to local escalation of privilege.
  • CVE-2023-21331: In InputMethod, there is a possible way to determine whether an app is installed, without query permissions.

EXPLOITS

BREACHES

Tags: DIB, tlp:green