zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 14, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 14, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ducktail Malware Targets the Fashion Industry
  • FBI and CISA Reveal Additional Details on Royal Ransomware
  • DP World Cyberattack Blocks Thousands of Containers in Ports
  • Data broker / initial-access broker / hacktivist group: Exploit users blink and mrbin228
  • Vulnerabilities: CVE-2023-21389
  • Exploits: CVE-2022-30781 and CVE-2022-2639
  • Breaches: Combolist: 'Taobao.com 75k mix.txt' and Credit Card Data Breach: 2023-11-12

Ducktail Malware Targets the Fashion Industry

A Vietnam-linked threat actor group has been targeting marketing professionals in the fashion industry who are trying to shift companies. Victims across the world are lured with documents purportedly related to projects associated with prominent fashion brands, usually containing images relating to those clothing companies. However, the package also contains the Delphi-written Ducktail malware, which steals cookies and account details after accessing the victims’ ads and business accounts.

FBI and CISA Reveal Additional Details on Royal Ransomware

The FBI has revealed that the Royal ransomware gang has targeted over 350 known victims worldwide since September 2022, and overall ransomware demands have exceeded 275 million USD. In an updated #StopRansomware advisory jointly released by CISA and FBI, new IOCs (indicators of compromise) identified through FBI investigations are provided to help defenders guard their networks. The cybersecurity advisory also highlights Royal’s efforts to rebrand or create a spinoff, with the Blacksuit ransomware possessing coding characteristics similar to Royal.

DP World Cyberattack Blocks Thousands of Containers in Ports

International logistics firm DP World Australia has reportedly disclosed that a cyberattack is affecting normal operations in several Australian ports. The company is currently collaborating with cybersecurity professionals to re-establish landside freight operations at its ports. DP World has engaged the Office of the Australian Information Commissioner in response to the incident and is investigating the nature of data access, exfiltration, and possibility of personal-information compromise.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit user blink: Claims network access to unnamed lighting manufacturer with operations in U.S. and China
  • Exploit user mrbin228: Allegedly in possession of network access to a Brazilian charitable organization

VULNERABILITIES

  • CVE-2023-21389: There is a possible bypass of profile owner restrictions due to a missing permission check.

EXPLOITS

BREACHES

Tags: DIB, tlp:green