ZeroFox Cyber Intelligence Daily Brief - January 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- New macOS Backdoor via North Korean Hackers
- Merck Cyberinsurance Dispute Blurs Cyberwar Definition
- After Injecting Cancer Hospital with Ransomware, Crims Threaten to Swat Patients
New macOS Backdoor via North Korean Hackers
Cybersecurity researchers have identified a new macOS backdoor named SpectralBlur, linked to a North Korean malware family, KANDYKORN. SpectralBlur, a moderately capable backdoor, shares similarities with KANDYKORN, known for its remote access trojan capabilities. Lazarus-connected BlueNoroff has previously been associated with KANDYKORN. Recent observations indicate a combination of elements from KANDYKORN and RustBucket in the threat actor's campaigns. The findings suggest North Korean threat actors are increasingly targeting macOS, particularly in industries like cryptocurrency and blockchain. SpectralBlur attempts to hinder analysis and evade detection, showcasing the growing trend of macOS-focused malware threats.
Merck Cyberinsurance Dispute Blurs Cyberwar Definition
Merck and its insurers have settled an ongoing insurance dispute, where Merck seems to have won against the insurers’ arguments about the 2017 NotPetya Malware attack being a politically driven cyberwar effort. NotPetya was believed to be linked to Russia and was considered to be an act of cyberwar against Ukraine. To this end, the insurers had claimed that the damages sustained by Merck from the malware attack would be excluded by the standard war exclusion clause. However, two court judgments ruled in favor of Merck stating that the NotPetya attack, “is not sufficiently linked to a military action or objective as it was a non-military cyberattack against an accounting software provider.”
After Injecting Cancer Hospital with Ransomware, Crims Threaten to Swat Patients
Cybercriminals are turning their attention to patients in an attempt to have their ransomware demand fulfilled by threatening them with bogus police reports if medical centers do not pay their ransomware. These reports have the potential to bring swat teams to patient homes. After a cyberattack on Fred Hutchinson Cancer Center, where medical records were stolen, criminals threatened to make bomb threats or false reports to law enforcement about patients. Their aim is to pressure hospitals to pay ransoms to prevent harm to patients and avoid negative publicity. Similar threats were reported by Integris Health in Oklahoma.
VULNERABILITIES
- CVE-2024-0295: A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi.
- CVE-2024-0296: A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical.
BREACHES
- Combolist: '150K_000168.txt' (149,880 Records): Email Address, Password
- Combolist: 'Australia 100K.txt' (103,846 Records): Email Address, Password
Tags: DIB, tlp:green