zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 30, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 30, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • China-Linked Hackers Exploit Barracuda Zero-Day to Deliver Malware
  • Downfall (Steam Standalone) Was Breached
  • New Malware Loader Uses Obscure JavaScript Files

China-Linked Hackers Exploit Barracuda Zero-Day to Deliver Malware

A Barracuda Email Security Gateway (ESG) zero-day vulnerability (CVE-2023-7102) is being exploited by China-linked hackers to deliver malware and steal information from some organizations that use the email security product. The threat actors are leveraging the zero-day flaw to deliver new SeaSpy and SaltWater malware variants to compromised devices. Barracuda has alerted its customers via a blog post stating that it has deployed a patch to remediate compromised ESG appliances amid ongoing investigations.

Downfall (Steam Standalone) Was Breached

The game Downfall recently experienced a breach where attackers utilized the Steam update system to distribute information-stealing malware. The attack occurred through the compromise of one of the developers' Steam and Discord accounts, leading to control over the mod's Steam account. The affected package was a prepackaged standalone modified version of the original game, not a mod installed via Steam Workshop. While most antivirus programs did not prevent the malware from executing, they did stop the payload from being sent over the internet. The malware targeted passwords, particularly from browsers including Discord, Brave, Vivaldi, and Telegram, and applications, including files with the term "password."

New Malware Loader Uses Obscure JavaScript Files

Threat actors are leveraging a new malware loader to deliver several different types of information stealers, including Lumma Stealer (aka LummaC2), Vidar, RecordBreaker, and Rescoms, majorly in Canada and the United States. The tool is distributed via methods such as malvertising, fake browser updates, and cracked installations of popular software such as VLC media player and OpenAI ChatGPT. The malware loader begins infection through obscure JavaScript files, the execution of which retrieves the remote control and stealer malware from an actor-controlled server.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • [CVE-2023-4468] (https://cloud.zerofox.com/intelligence/vulnerabilities/513608): A vulnerability was found in Poly Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration.
  • CVE-2023-51420: Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.

EXPLOITS

  • CVE-2021-43116: An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
  • CVE-2022-45639: OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

BREACHES

Tags: DIB, tlp:green