ZeroFox Cyber Intelligence Daily Brief - December 6, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 6, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Threat Actors Exploit Adobe ColdFusion CVE-2023-26360 for Initial Access to Government Servers
- ZeroFox Intelligence Brief - Ransomware & Digital Extortion - ALPHV Targeting
- AI-Driven Operation Doppelganger Propagates Disinformation to the U.S., Ukranian, and German Audience
Threat Actors Exploit Adobe ColdFusion CVE-2023-26360 for Initial Access to Government Servers
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports the exploitation of an Adobe bug (CVE-2023-26360) at a Federal Civilian Executive Branch (FCEB) agency. This vulnerability is reported to be exploited by unidentified threat actors in Adobe ColdFusion versions 2018 Update 15 and 2021 Update 5. Successful exploitation of the bug leads to an access control issue that results in an arbitrary code execution in servers running on outdated versions. FCEB agencies had been mandated to patch this vulnerability by May 4, 2023.
ZeroFox Intelligence Brief - Ransomware & Digital Extortion - ALPHV Targeting
ZeroFox reports in an intelligence brief that ALPHV, a ransomware and digital extortion (R&DE) threat, is one of the major threats to many industries globally. Its continued presence and prominence in malicious marketplaces is likely contributed to by affiliate payout rates of up to 90 percent, which is significantly higher than many other ransomware services. The threat from ALPHV will almost certainly remain significant over the next two quarters, as affiliates continue a high attack tempo. Security teams should also monitor for an increasingly diverse spectrum of R&DE operations.
AI-Driven Operation Doppelganger Propagates Disinformation to U.S., Ukrainian, and German Audience
Russia-origin AI-powered Doppelganger is disseminating disinformation among audiences in Ukraine, the United States, and Germany through an extensive network of fraudulent websites and social media, including approximately 800 inauthentic social media accounts. Reportedly, the operation has been crafted to curate content that propagates anti-LGBTQ+ sentiments and subverts Ukraine’s military and international relations. In a recent campaign, Doppelganger created genuine-looking fake news articles, likely with the help of generative AI. Despite the vastness of the operation, researchers have not observed significant audience engagement. However, they have stated the importance of monitoring Doppelganger for further enhancements of tools and tactics.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Ddarknotevil: Actor Selling Alleged Web Shell Access to QPay Electronic Money and Payment Services
VULNERABILITIES
- CVE-2023-6360: The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability.
- CVE-2023-5803: Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress.
BREACHES
- Combolist: 'YAHOO.COM @mr_comboo.txt' (784,791 Records): Email Address, Password
- Combolist: '10K_FULL_HITS_MAIL_ACCESS.txt' (10,973 Records): Email Address, Password
Tags: DIB, tlp:green