zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 20, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 20, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Active Exploitation of Juniper RCE Vulnerabilities
  • ZeroFox Intelligence Brief - Ransomware & Digital Extortion - LockBit Targeting
  • Russian Hacker Group APT29 Exploits a WinRAR Bug to Target Embassies
  • Data broker / initial-access broker / hacktivist group: Exploit user resetmyname
  • Vulnerabilities: CVE-2023-6174 and CVE-2023-46700
  • Breaches: Credit Card Data Breach: 2023-11-18 (d8cb5d | 2640) and Combolist: 'Morele.net 614k.txt' (611,885 Records)

ZeroFox Intelligence Flash Report - Active Exploitation of Juniper RCE Vulnerabilities

Last week, CISA added five Juniper Junos operating system vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. A recent Proof-of-Concept (PoC) for four of the vulnerabilities demonstrated how an unauthenticated, network-based threat actor may be able to remotely execute malware on unpatched assets by chaining exploitation of these bugs. With the available PoCs lowering the barrier to entry, ZeroFox assesses these vulnerabilities to be critical as a collective because threat actors are likely to exploit them on unpatched assets in the long term. Threat actors are very likely to create their own customized PoC exploits and sell them on darknet forums. You can read the full report here: https://zf-dashboard-media.s3.amazonaws.com/intel/71bb532b-cfa7-4bae-90a5-197540f3c9e1

ZeroFox Intelligence Brief - Ransomware & Digital Extortion - LockBit Targeting

ZeroFox has published an intelligence brief which discusses the LockBit ransomware strain, its targeting, intrusion vectors, and initial access brokers, based on its primary role in ransomware and digital extortion (R&DE). Between 2022 and 2023, LockBit’s most frequently-targeted industries across the globe include manufacturing, retail, and constructing. Despite being a prominent player in R&DE, the proportion of total attacks that LockBit accounts for is on a downward trajectory. To ward off LockBit attacks, ZeroFox Intelligence recommends deploying a holistic patch management process, and ensuring all IT assets are updated with the latest software updates as quickly as possible, amongst other suggestions. Read the full report here: https://zf-dashboard-media.s3.amazonaws.com/intel/08e7f509-4a57-4a52-a63f-79b4a8f3b068

Russian Hacker Group APT29 Exploits a WinRAR Bug to Target Embassies

APT29, a Russian state-linked hacker gang also known as Cozy Bear, SolarStorm, and NOBELIUM, is exploiting a WinRAR vulnerability (CVE-2023-38831) to target embassies. The flaw affects WinRAR versions before 6.23, allowing execution of malicious code. The group uses a deceptive ZIP archive, "DIPLOMATIC-CAR-FOR-SALE-BMW.pdf," to lure unsuspecting victims with a PDF containing enticing photos and details of a fake BMW car sale. APT29 employs static domains provided by Ngrok, typically in the form of a subdomain under "ngrok-free.app," discreetly to communicate with compromised systems. CVE-2023-38831 has already been the target of several zero-day exploits since April by threat actors, including by Sandworm and APT28.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit user resetmyname: Selling a bundle that contains 25,000 compromised accounts impacting various Hong Kong banks

VULNERABILITIES

  • CVE-2023-6174: SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
  • CVE-2023-46700: SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L.

BREACHES

Tags: DIB, tlp:green