zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 25, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 25, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Action Against Digital Skimming Reveals 443 Compromised Online Merchants
  • U.S. Water Utilities were Hacked After Leaving Their Default Passwords Set to ‘1111’
  • Geopolitical and Cyber Implications of China’s Rare Metals-Related Export Ban

Action Against Digital Skimming Reveals 443 Compromised Online Merchants

Europol and other law enforcement authorities’ two-month action against digital skimming attacks found that 443 website’s online stores have been hacked by malicious scripts that steal debit and credit cards from customers making purchases. Skimmers are malicious tools designed to intercept and steal sensitive payment card information, including card numbers, expiration dates, and addresses. Threat actors leverage this information for unauthorized transactions, such as online purchases, or may sell the data to other cybercriminals on dark web marketplaces. This two-month action found 23 distinct families of JavaScript sniffers. These families, including ATMZOW, Inter, and R3nin, exhibit elusive behavior such as abusing Google Tag Manager and mimicking Google Analytics code to evade detection during website code inspections.

U.S. Water Utilities were Hacked After Leaving Their Default Passwords Set to ‘1111’

The U.S. federal government is investigating multiple cyberattacks believed to be carried out by an Iranian government-linked group, CyberAv3ngers against U.S. water facilities utilizing Israeli-manufactured Unitronics programmable logic controllers. The attacks targeted at least 11 entities across the United States, including local water facilities, a pharmacy, an aquatics center, and a brewery. Some compromised devices had default passwords, making them vulnerable, highlighting the broader issue of the security of technology powering critical infrastructure. The affected water authority disabled the system, ensuring no impact on the water supply for residents.

Geopolitical and Cyber Implications of China’s Rare Metals-Related Export Ban

China has announced new export controls on key technologies with immediate effect, including an immediate ban on the export of technologies that process rare-earth metals. The ban is likely retaliation for U.S. export controls and an effort to undercut U.S. ventures to develop its own clean energy and rare-earth metal supply. ZeroFox reporting since the first iteration of the CHIPS Act in 2022 has warned against cyber espionage campaigns as the amount of advanced technology withheld from China grows. The global semiconductor industry will very likely continue to be targeted by Chinese APT groups. Verticals of the semiconductor industry—such as prominent universities and government research labs specializing in semiconductor research and development—are also likely to be targeted.

VULNERABILITIES

  • CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
  • CVE-2023-6377: A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

BREACHES

Tags: DIB, tlp:green