zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - December 16, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - December 16, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - SiegedSec Hacktivist Group Creates New Data Leak Site
  • “Pig Butchers” Charged for Laundering Millions from Cryptocurrency Investment Scams
  • Ten New Android banking Trojans Targeted 985 Bank Apps in 2023

ZeroFox Intelligence Flash Report - SiegedSec Hacktivist Group Creates New Data Leak Site

SiegedSec, a hacktivist group established prior to the Russian invasion of Ukraine, established a new leak site in December 2023. The group has posted sensitive information on the leak site, including a database of alleged NATO documentation. SiegedSec has conducted attacks against numerous sectors and nations, with a recent focus on government organizations, and will likely continue to leak sensitive data via the new leak site.

“Pig Butchers” Charged for Laundering Millions from Cryptocurrency Investment Scams

Four individuals have been charged in Los Angeles for a pig-butchering scheme involving money laundering from a cryptocurrency investment scam. In such schemes, scammers build trust with victims through platforms like social media, posing as potential business partners interested in cryptocurrency investments. Victims are directed to fraudulent investment platforms, where they make financial investments. The four individuals allegedly laundered their proceeds, involving shell companies and bank accounts. The scheme involving over 200 transactions, resulted in over USD 80 million in victim losses, with more than USD 20 million directly deposited into accounts linked to the defendants.

Ten New Android banking Trojans Targeted 985 Bank Apps in 2023

Ten new banking trojan families have targeted over 900 banks and fintech apps across 61 countries including the United States, United Kingdom, and Italy. In addition to the ten new families, 19 others are also involved with modified capabilities. Researchers observe common trends in their operations like keylogging, overlaying phishing pages, and stealing SMS messages. Other trends include the implementation of an automated transfer system (ATS), social engineering tactics where actors manipulate victims to download trojan payloads, the introduction of live screen-sharing for direct interaction with infected devices, and the sale of the malware through monthly subscription packages to other cybercriminals. Banking trojans have expanded their focus beyond just banking credentials and financial theft to include targeting social media, messaging apps, and personal data.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-6838: Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
  • CVE-2023-6835: Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.

EXPLOITS

  • CVE-2022-47075: An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
  • CVE-2022-47076: An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.

BREACHES

Tags: DIB, tlp:green