ZeroFox Daily Intelligence Brief - November 25, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 25, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Play Ransomware Increases Activity
- North Korea-Based Threat Actor Exploits CyberLink Software in Global Cyberattack
- China’s Cybersecurity Legal Rules and Regulations See Further Enhancements in 2023
- Data broker / initial-access broker / hacktivist group: BreachForums user IntelBroker
ZeroFox Intelligence Flash Report: Play Ransomware Increases Activity
Ransomware collective Play has expanded its operational activity in Q4 2023, having been responsible for approximately 14 percent of all ransomware and digital extortion (R&DE) activity observed by ZeroFox. Play operators leverage various initial intrusion vectors to gain network access, including illicitly obtained credentials, exploitation of internet-facing applications, exploitation of external remote services, and phishing emails with malicious attachments. There is a roughly even chance that this increased operational tempo is due in part to a recent shift by Play to an as-a-service model, whereby affiliates can purchase or lease the software via a subscription-based model.
North Korea-Based Threat Actor Exploits CyberLink Software in Global Cyberattack
Cybersecurity agents have exposed a supply chain attack orchestrated by the North Korea-based threat actor Diamond Sleet (ZINC/Labyrinth Chollima / Lazarus). The attack involves a malicious variant of an application developed by CyberLink Corp., a multimedia software developer. This corrupted file disguises itself as a genuine CyberLink application installer, but it carries concealed malicious code. When executed, the code downloads, decrypts, and deploys a second-stage payload. The file was signed with the help of a valid certificate held by CyberLink Corp. and is hosted on the company's legitimate update infrastructure. Researchers are reporting that the attack has already affected more than 100 devices across various countries, including Japan, Taiwan, Canada, and the United States.
China’s Cybersecurity Legal Rules and Regulations See Further Enhancements in 2023
In 2023, China fortified its cybersecurity and data protection laws, refining regulations on personal information (PI) export responsibilities, thereby impacting companies and foreign investment. Stringent regulations enforced on cross-border data transfer (CBDT) pose a challenge to multinational companies and foreign-invested enterprises (FIEs), likely posing a barrier for any further foreign investment. China's cybersecurity authorities have proposed relaxing CBDT requirements to foster international business relations. The Cyberspace Administration of China (CAC) introduced draft measures for regular compliance audits, while the China’s Ministry of Industry and Information Technology (MIIT) finalized data protection measures for industrial and telecom companies.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user IntelBroker: Claims Data Breach of Software Creation and Delivery Company
VULNERABILITIES
- CVE-2023-47688: Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions.
- CVE-2023-6176: A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality.
EXPLOITS
- CVE-2022-25148: WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection
BREACHES
- Combolist: 'combolist_000016(4).txt' (9,965 Records) Email address and password
- Telegram: 'ArtHouseCloud Free.zip' Botnet Breach (32,177 Records) Email address and password
Tags: DIB, tlp:green