ZeroFox Cyber Intelligence Daily Brief - December 17, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 17, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Network Access Sale Linked to Chandrayaan-3 Mission
- Chinese-Linked Botnet Can Potentially Disrupt U.S. Communication Infrastructure
- AutoSpill Attack Steals Credentials from Android Password Managers
ZeroFox Intelligence Flash Report: Network Access Sale Linked to Chandrayaan-3 Mission
On December 6, 2023, well-regarded access broker “RobinHood” announced on Russian-language dark web forum RAMP the sale of likely network access to an unnamed India-based organization that has an ongoing partnership with India’s Chandrayaan-3 mission. Ransomware cartels frequently leverage RAMP to purchase such accesses from brokers; the post likely represents a legitimate network access sale, judging from RobinHood’s long-standing positive reputation.
Chinese-Linked Botnet Can Potentially Disrupt U.S. Communication Infrastructure
International cybersecurity authorities are associating Chinese state-sponsored APT group Volt Typhoon with a botnet called KV-botnet, which is known to compromise small office/home office (SOHO) networks. The threat actors have been using living off-the-land tactics that deploy built-in network administration tools to target critical organizations, including telecommunication and internet service providers, a U.S. territorial government entity in Guam, a renewable energy firm in Europe, and U.S. military organizations. The list of targets implies that the attacks are being conducted for espionage and information-gathering purposes.
AutoSpill Attack Steals Credentials from Android Password Managers
Researchers have developed a new attack tactic called AutoSpill that can access users’ account information during autofill operations. They uncovered this vulnerability in Android devices that can allow potential attackers to gain access to user’s information. Threat actors can gain access to this data by introducing applications and logins that require users to fill their information using autofill. According to the researchers, Android's inability to specify or enforce who is responsible for managing auto-filled data securely may be the root cause of the AutoSpill problem.
Tags: DIB, tlp:green