zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 2, 2024

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - January 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hackers Hit Australian State's Court Recording Database
  • Yakult Australia Employee Files Leaked on Dark Web in Cyberattack
  • CERT-UA Detects New Malware Strains Connected to Russia-linked APT28

Hackers Hit Australian State's Court Recording Database

Hackers breached the court recordings database in Victoria, Australia, disrupting the audio-visual in-court technology network and potentially stealing recordings of court hearings between November 1 and December 21, 2023. Some hearings prior to November 1 may also have been affected. The access is limited to recordings stored on the network, with no compromise of other court systems or records, including employee or financial data. The incident impacted the functionality of recordings and transcription services, prompting an ongoing investigation.

Yakult Australia Employee Files Leaked on Dark Web in Cyberattack

Probiotics manufacturing and distributing giant Yakult Australia has suffered a cyberattack, after which almost 95 GB of sensitive employee information has been released on the dark web. The company has stated that even though its offices continue to operate, cybersecurity agencies are investigating the incident. A sample from the leaked data reportedly comprises scans of passports and driving licenses, salaries, and medical records. DragonForce, a ransomware threat actor, has claimed responsibility for the attack.

CERT-UA Detects New Malware Strains Connected to Russia-linked APT28

The CERT-UA has detected a Russia-linked APT28 group distributing undocumented malware strains like OCEANMAP, MASEPIE, and STEELHOOK via a new phishing campaign to steal information. The campaign targeted Ukrainian and Polish entities with malicious email messages that triggered the launch of MASEPIE. This in turn allowed the deployment of other malware strains.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-32878: In battery, there is a possible information disclosure due to a missing bounds check.
  • CVE-2023-32881: In battery, there is a possible information disclosure due to an integer overflow.

EXPLOITS

  • CVE-2022-45030: A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
  • CVE-2022-48194: TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

BREACHES

Tags: DIB, tlp:green