zerofox logo
Advisories

ZeroFox Cyber Daily Intelligence Brief - December 4, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - December 4, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief: Lazarus Group Exploitation of MagicLine4NX Vulnerability
  • ZeroFox Intelligence Brief: LockBit Targeting of the United Kingdom (2022-2023)
  • Agent Raccoon Backdoor Targets Organizations in Middle East, Africa, and the United States
  • Data broker / initial-access broker / hacktivist group: ALPHV Ransomware
  • Vulnerabilities: CVE-2021-39537
  • Breaches: Combolist: '366k Ultra HQ Combolist.txt' (364,314 Records)

ZeroFox Intelligence Brief: Lazarus Group Exploitation of MagicLine4NX Vulnerability

ZeroFox has released an intelligence brief covering a joint cybersecurity advisory published by the UK National Cyber Security Centre (NCSC) and South Korea’s National Intelligence Service (NIS) that highlights Lazarus’ recent supply chain attacks utilizing a zero-day vulnerability (CVE-2023-45797) in security authentication tool MagicLine4NX. North Korean-linked Advanced Persistent Threat (APT) group Lazarus exploited this buffer overflow vulnerability that allows the attacker to remotely execute arbitrary code on a target system. As NCSC and NIS assess that the level of supply chain attacks is likely to increase, the advisory recommends conducting regular vulnerability scans and assessing software supply-chain risks, among other suggestions.

ZeroFox Intelligence Brief: LockBit Targeting of the United Kingdom (2022-2023)

Between January 2022 and November 2023, LockBit has been the primary ransomware and digital extortion (R&DE) threat to U.K.-based organizations. The United Kingdom consistently accounts for approximately 20 percent of total European R&DE attacks. LockBit’s Europe-focused targeting has decreased, whereas its attacks against the United Kingdom have remained broadly consistent—meaning U.K. organizations represent an increasing proportion of LockBit’s Europe-focused targeting. This likely indicates that while LockBit affiliates focused on targeting wider Europe have reduced activity or pivoted to other strains, U.K.-focused affiliates continue to leverage LockBit and maintain their operational tempo.

Agent Raccoon Backdoor Targets Organizations in Middle East, Africa, and the United States

Cybersecurity researchers have observed an unknown threat actor distributing a new backdoor called Agent Raccoon. Agent Raccoon conducts backdoor attacks through scheduled tasks in the form of Google Updates, allowing command executions like file downloads and uploads. This threat actor is reportedly targeting education, real estate, retail, non-profit, telecom, and government organizations in the United States, the Middle East, and Africa. Researchers are yet to zero in on how these entities were breached, but have identified certain tools used—such as a version of Mimikatz called Mimilite and Ntospy.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

ALPHV Ransomware: Ransomware attack against Tipalti with attempted “triple extortion” against Roblox.

VULNERABILITIES

CVE-2021-39537: An issue in ncurses through v6.2-1. _ nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

BREACHES

Combolist: '366k Ultra HQ Combolist.txt' (364,314 Records) Email address and password

Tags: DIB, tlp:green