ZeroFox Cyber Intelligence Daily Brief - December 11, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 11, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian Cyber Actor Star Blizzard Continues Worldwide Spear-Phishing Campaigns
- Norton Healthcare Notifies of Data Breach After May Ransomware Attack
- AutoSpill Attack Steals Credentials from Android Password Managers
Russian Cyber Actor Star Blizzard Continues Worldwide Spear-Phishing Campaigns
In a joint advisory, CISA and other international cybersecurity agencies are warning about Russia-based actor Star Blizzard (SEABORGIUM/CallistoGroup/TA446/COLDRIVER/TAG-53/ BlueCharlie) using spear-phishing attacks to academia, defense, and governmental organizations, NGOs, think tanks, and politicians in the United Kingdom and other geographical areas of interest. Star Blizzard engages with its targets through online networking platforms to first establish trust and then deploys phishing links to steal log-in credentials. The group steals emails and attachments from the victim’s inbox and also accesses the victim’s mailing list data and contacts list for follow-on targeting or further phishing activity.
Norton Healthcare Notifies of Data Breach After May Ransomware Attack
Norton Healthcare, a U.S.-based hospital and healthcare chain, has disclosed a confirmed ransomware attack and data breach in May this year that exposed the personal information of patients, employees, and dependents. On May 26, ZeroFox Intelligence observed ransomware group ALPHV claim to have exfiltrated almost 5 TB of "very interesting data" including images and Social Security numbers from Norton. Norton has recommended that impacted individuals sign up for two years of credit monitoring.
AutoSpill Attack Steals Credentials from Android Password Managers
Researchers have developed a new attack tactic called AutoSpill that can access users’ account information during autofill operations. They uncovered this vulnerability in Android devices that can allow potential attackers to gain access to user’s information. Threat actors can gain access to this data by introducing applications and logins that require users to fill their information using autofill. According to the researchers, Android's inability to specify or enforce who is responsible for managing auto-filled data securely may be the root cause of the AutoSpill problem.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user l29: Remote desktop access to Australian amusement parks company
- Exploit user fokonishi: Remote desktop access to U.S.-based resources and business services company
VULNERABILITIES
- CVE-2023-6656: A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulation leads to deserialization. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.
- CVE-2023-6657: A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used.
BREACHES
- Combolist: 'netflix.txt' (1,487 Records): Email Address, Password
- Combolist: '100.results (8).txt' (89 Records): Email Address, Password
Tags: DIB, tlp:green