zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 24, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 24, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Newly Identified “UBUD” Ransomware Product For Sale
  • Kansas Judicial Branch Releases Official Statement Confirming Data Breach
  • New Botnet Malware Infects NVR Devices and Routers For Profitable DDoS Attacks
  • Data broker / initial-access broker / hacktivist group: BreachForums user admin123
  • Vulnerabilities: CVE-2023-41699 and CVE-2023-28621
  • Exploits: CVE-2020-11060
  • Breaches: Telegram: 'Erernity&Team [FREE LOGS].rar' Botnet Breach (42,413 Records)

ZeroFox Intelligence Flash Report - Newly Identified “UBUD” Ransomware Product For Sale

Threat actor “IsEmptyOrNull” announced the sale of a newly developed ransomware product dubbed “UBUD” on the Dark Web marketplace RAMP demanding USD 90,000. UBUD is designed for solitary use and is a highly customizable product, with each payload build likely adapted for each deployment, making the detection and removal of the malicious code more difficult. UBUD represents a continuation of the general trend whereby less-competent actors are increasingly able to get their hands on highly effective products and services as long as they have sufficient funds.

Kansas Judicial Branch Releases Official Statement Confirming Data Breach

The Kansas Supreme Court has released a statement confirming a data breach that occurred last month, where a “sophisticated foreign cyberattack” impacted several information systems used by the judicial branch. Upon discovering the breach, all external access to the compromised systems were restricted. Several services are still flagged as offline. The statement further reports that threat actors were able to steal sensitive information and have threatened to post it online. The stolen data includes files from the Office of Judicial Administration and other data, some of which may be confidential under law. Meanwhile, it might take weeks to safely restore normal operations, including electronic filing.

New Botnet Malware Infects NVR Devices and Routers For Profitable DDoS Attacks

“InfectedSlurs,” a novel Mirai-based malware botnet, has been observed exploiting two zero-day remote code execution flaws (RCE) flaws to target routers and network video recorder (NVR) devices. One of these flaws is an undocumented RCE vulnerability, while the other one affects a wireless LAN router popular among home users and hotels. Once the targeted devices are compromised, the malware adds them to its distributed denial of services (DDoS) network, likely for monetary gains. Further inspection also reportedly revealed that the malware employs default credentials from vendor manuals, infecting NVRs. Cybersecurity researchers have stated that there are no patches for the vulnerabilities at the time of reporting.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-41699: URL Redirection to Untrusted Site vulnerability in Payara Platform Payara Server, Micro and Embedded allows Redirect Access to Libraries.
  • CVE-2023-28621: Improper Neutralization of Input During Web Page Generation vulnerability in Wishfulthemes Raise Mag, Wishfulthemes Wishful Blog themes allows Reflected XSS.

EXPLOITS

BREACHES

Tags: DIB, tlp:green