ZeroFox Daily Intelligence Brief - November 30, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 30, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Dollar Tree Targeted in a Third-Party Data Breach Affecting Almost 2 Million People
- U.S. Treasury Sanctions Mixer Used by Lazarus Group to Launder Virtual Currency
- SIM Swapper to Serve Eight Years in Prison For Cyber Crimes
- Data broker / initial-access broker / hacktivist group: BreachForums user threatbear and Telegram account BlackSec
- Vulnerabilities: CVE-2023-45377 and CVE-2023-43887
- Exploits: CVE-2023-37629
- Breaches: Credit Card Data Breach: 2023-11-29 (3106bb | 3551)
Dollar Tree Targeted in a Third-Party Data Breach Affecting Almost 2 Million People
Discount variety stores Dollar Tree and Family Dollar were subjected to a third-party data breach that exposed the personal information of 1,977,486 employees. An August 2023 cyberattack targeting Zeroed-In, a service provider of Dollar Tree, led to threat actors stealing names, dates of birth, and Social Security numbers of the victims. Zeroed-In has issued a notice alerting all those affected by the incident and is providing the victims identity protection and credit monitoring services for a year.
U.S. Treasury Sanctions Mixer Used by Lazarus Group to Launder Virtual Currency
The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has announced the sanctioning of Sinbad, a cryptocurrency mixing service, as well as the seizure of the Sinbad website’s domain. The sanctions on Sinbad implicate those in contact with this service as well and can lead to sanctions placed on them. Sinbad is a virtual currency mixer that threat actors, including the Democratic People’s Republic of Korea’s (DPRK’s) Lazarus, are known to use as a money-laundering tool. Sinbad has reportedly assisted in laundering millions of dollars by practically obscuring transactions on the bitcoin blockchain.
SIM Swapper to Serve Eight Years in Prison For Cyber Crimes
A Los Angeles District Court has sentenced a person to eight years in prison and ordered them to pay USD 1,218,526 in restitution for committing various cyber crimes, including SIM swapping, Instagram account hijacking, Zelle merchant fraud, Apple support fraud, and cryptocurrency theft. The SIM-swapping and account takeovers targeted the account owners and their online friends, deceiving them to send money to the perpetrator. From at least April 2019 to February 2023, the convict scammed hundreds of people via multiple fraudulent schemes that resulted in losses of approximately USD 740,000 for the victims.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user threatbear: Claims to Sell Data from HLL Lifecare
- Telegram account BlackSec: Claims to Take Over WeedSec
VULNERABILITIES
- CVE-2023-45377: In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection.
- CVE-2023-43887: Libde265 v1.0.12 was discovered to contain multiple buffer overflows.
EXPLOITS
- CVE-2023-37629: Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
BREACHES
Tags: DIB, tlp:green