ZeroFox Daily Intelligence Brief - December 02, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - December 02, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Treasury Targets DPRK’s International Agents and Illicit Cyber Intrusion Group
- Zyxel Addresses Three Critical and Three High-Severity Bugs in NAS Systems
- Gh0st RAT Malware Hitting Global Cyber Targets
Treasury Targets DPRK’s International Agents and Illicit Cyber Intrusion Group
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC), in collaboration with foreign partners, sanctioned eight agents that support the Democratic People’s Republic of Korea (DPRK) in building weapons of mass destruction (WMD), as well as the cyber espionage group Kimsuky. Kimsuky collects information to assist DPRK in its strategic and nuclear goals. Employing spear-phishing techniques, it targets individuals in government, research, academia, and media across Europe, Japan, Russia, South Korea, and the United States. Kimsuky leverages social engineering to illicitly access private documents, research, and communications, aiming to gather intelligence on geopolitical events, foreign policies, and diplomatic efforts that impact North Korea's interests.
Zyxel Addresses Three Critical and Three High-Severity Bugs in NAS Systems
Zyxel has acknowledged several vulnerabilities in network-attached storage (NAS) systems, three of which are critical and can let threat actors with unauthenticated access to execute operating system (OS) commands. These bugs affect NAS326 devices operating on versions V5.21(AAZF.14)C0 and earlier and NAS542 devices working on versions V5.21(ABAG.11)C0 and earlier. To mitigate the risk of exploits and deploy patches for the bugs, Zyxel advises users with NAS326 devices to upgrade to V5.21(AAZF.15)C0 and those with NAS542 to upgrade to version V5.21(ABAG.12)C0.
Gh0st RAT Malware Hitting Global Cyber Targets
The newly discovered SugarGh0st trojan is reportedly targeting the Uzbekistan Ministry of Foreign Affairs as well as users in South Korea. SugarGh0st, which security researchers suspect to be a new version of Gh0st RAT, comes with new features in its reconnaissance capability, targeting specific Open Database Connectivity (ODBC) registry keys and employing tailored commands for remote administration tasks. To evade detection, it loads library files with specific extensions and function names, while modifying the C2 communication protocol.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user iotseek: Actor Claims to Have Leaked Data From the Database of Smart Schools in Egypt
- BreachForums user ZinPin: Actor Claims to Have Access to The Ministry of Defense in The Republic of Indonesia
VULNERABILITIES
- CVE-2023-6033: Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
- CVE-2023-5915: A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation.
EXPLOITS
CVE-2023-40044: In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
CVE-2023-4911: A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
BREACHES
- BreachForums: lapostemobile.fr Breach (534290 Records): Name, Email Address, Physical Address, Phone Number
- Combolist: 'X102 Hits Netflix By @Combosvip (4).txt' (101 Records): Email Address, Password
Tags: DIB, tlp:green