ZeroFox Cyber Daily Intelligence Brief - December 23, 2023
|by Alpha Team

ZeroFox Cyber Daily Intelligence Brief - December 23, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- German Law Enforcement Seizes Kingdom Market
- “The Five Families” Hacker Collective Disrupted After SiegedSec Blog Hijack
- Chinese-Speaking Hackers Pose as UAE Authority in Latest Smishing Wave
German Law Enforcement Seizes Kingdom Market
In a collaborative law enforcement operation, the Federal Criminal Police Office in Germany (BKA) and the internet-crime combating unit of Frankfurt (ZIT) have seized Kingdom Market, a darkweb marketplace. The marketplace has been a host for sale transactions of drugs, malware, cybercrime services, stolen personal information, and forged documents. BKA further announced that an investigation is underway to zero in on the individuals suspected of spearheading the marketplace. At the time of reporting, there has been one confirmed arrest of an administrator of the marketplace.
“The Five Families” Hacker Collective Disrupted After SiegedSec Blog Hijack
“The Five Families''—a collaboration between ThreatSec, SiegedSec, Stormous, BlackForums (now BlackSec), and GhostSec—witnessed internal strife with the excommunication of SiegedSec after its blog was supposedly hijacked. The reason behind this disruption seems to be sexually themed and inappropriate posts on SiegedSec’s blog. SiegedSec’s response to these accusations points to the possibility that its blog had been defaced. In the wake of these developments, the leader of SiegedSec has resigned from their post, intending to pass on their responsibilities and their username to another party.
Chinese-Speaking Hackers Pose as UAE Authority in Latest Smishing Wave
A Chinese-speaking threat group is posing as the United Arab Emirates Federal Authority for Identity and Citizenship in a smishing (SMS phishing) campaign. Targeting individuals who recently updated their residence visas, the attackers use a geofencing mechanism to load phishing forms only for UAE-based IP addresses and mobile devices. This campaign impacts both Android and iOS users, likely utilizing SMS spoofing or spam services. The threat actors are known for offering smishing kits for sale to other cybercriminals at USD 200 per month and engaging in Magecart-style attacks on e-commerce platforms to steal customer data.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Deanon Club: Actor Claims demolision of its Telegram Forum
VULNERABILITIES
- CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
- CVE-2023-49897: An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
EXPLOITS
- CVE-2023-27290: Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
- CVE-2022-47986: IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
BREACHES
- BreachForums: G-Infosoft Breach (634 Records): Email Address, Username, Physical Address, Physical Address, Password, Name
- Combolist: '450K Hotmail UHQ USA Mixed tematic Target.txt' (449,989 Records): Email Address, Password
Tags: DIB, tlp:green