zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 12, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 12, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Lazarus Group Is Still Juicing Log4Shell, Using RATs Written in 'D'
  • Americold Notifies Employees of A Data Breach Exposing Personal Information
  • Researchers Unmask Sandman APT's Hidden Link to China-Based KEYPLUG Backdoor

Lazarus Group Is Still Juicing Log4Shell, Using RATs Written in 'D'

Andariel, a subset of Lazarus, is reportedly exploiting Log4Shell globally and is targeting organizations with a new remote access Trojan (RAT) written in the D programming language, useful in avoiding detection and analysis. Andariel initiated attacks recently by exploiting exposed VMware Horizon servers vulnerable to Log4Shell, a two-year-old historic flaw in Apache Log4j (CVE-2021-44228). This vulnerability, rated 10 out of 10 on the CVSS bug-severity scale, is of maximum severity. Given the widespread use of the Log4J Java library it affected, researchers estimate that hundreds of millions of systems were impacted when initially discovered.

Americold Notifies Employees of A Data Breach Exposing Personal Information

An April 2023 cyberattack targeting Americold, a prominent American cold storage and logistics company, has exposed the personal information of approximately 129,000 employees and their dependents. In late July, ZeroFox Intelligence observed the Cactus ransomware group list Americold as one of its victims on its leak site. Americold has notified the impacted individuals that the stolen information may include names, Social Security numbers, passport information, and financial account information. Amongst other mitigation efforts, Americold has arranged for complimentary identity monitoring services for two years.

Researchers Unmask Sandman APT's Hidden Link to China-Based KEYPLUG Backdoor

The Sandman advanced persistent threat (APT) and a China-based threat cluster associated with KEYPLUG backdoor reveal tactical and targeting overlaps, according to cybersecurity researchers. LuaDream and KEYPLUG, the malware used by Sandman and Storm-0866/Red Dev 40, were reportedly found on the same victim networks. Shared infrastructure control, management practices, and development practices have a connection between the two threat groups. Both APTs target telecommunication providers and government entities in the Middle East and South Asia.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-49802: The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs.
  • CVE-2023-42581: Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

EXPLOITS

  • CVE-2023-33383: Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.
  • CVE-2023-37569: This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component.

BREACHES

Tags: DIB, tlp:green