ZeroFox Daily Intelligence Brief - December 5, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - December 5, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- “AeroBlade” Group Attacks U.S. Aerospace Company
- ALPHV Claims to Breach Tipalti’s Systems; Threatens Twitch and Roblox
- Zero-Click Remote Code Execution Bug Patch in Android
“AeroBlade” Group Attacks U.S. Aerospace Company
Researchers have uncovered a previously unknown threat actor, AeroBlade, in an attack against the U.S. aerospace sector spanning a year-long campaign. This threat actor managed to remain undetected by deploying anti-analysis techniques while phasing out its testing and execution in 2022 and 2023. It is yet to be understood if the threat actor was able to acquire access to data and other specifics. AeroBlade gained a foothold by using phishing emails hidden inside lure documents, clicking which led to executing a malicious Microsoft Word template (DOTM) file.
ALPHV Claims to Breach Tipalti’s Systems; Threatens Twitch and Roblox
Tipalti, an accounting software financial-technology business, has begun investigating claims of a ransomware attack made by ALPHV ransomware gang, which allegedly involves the exfiltration of more than 265 GB of data—including data belonging to Tipalti’s clients Roblox and Twitch. Earlier this week, ZeroFox Intelligence observed ALPHV state that it has been “present, undetected, in multiple Tipalti systems since September 8th 2023” on its leak site. Furthermore, in an attempted “triple extortion,” the group is trying to intimidate Roblox and Twitch to pay the ransom and threatening to publish the stolen data.
Zero-Click Remote Code Execution Bug Patch in Android
Google has patched a critical zero-click bug (CVE-2023-40088) in Android's System component as part of the December 2023 security updates. The bug could allow remote (proximal/adjacent) code execution with no additional execution privileges needed, the Android Security Bulletin disclosed. Android users are urged to update to the latest version of Android at the earliest possible.
VULNERABILITIES
- CVE-2023-47304: An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
- CVE-2023-42580: Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
EXPLOITS
- CVE-2023-32560: An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.
BREACHES
- Combolist: '120k MiX valid [@ScroogeStore].txt' (120,811 Records): Email Address, Password
- Combolist: 'epicgames_passwords (15).txt' (58,831 Records): Email Address, Password
Tags: DIB, tlp:green