ZeroFox Cyber Intelligence Daily Brief - January 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- BlackBasta Ransomware Linked Threat Actor Launches New Thread-Jacking Campaign
- Chinese Nation-State Hackers Found To Be Actively Exploiting Ivanti Zero-Days
- ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK
BlackBasta Ransomware Linked Threat Actor Launches New Thread-Jacking Campaign
Threat actor Water Curupira, associated with BlackBasta ransomware attacks, has been targeting organization networks with the help of a widespread phishing campaign using a loader similar to the infamous Qakbot malware. Using techniques of thread-jacking, Water Curupira targets its victims with phishing emails that appear to be a part of an ongoing email thread, deceiving the victim to engage with it. Once the victim clicks on the malicious link within the phishing email, it triggers the download and execution of Pikabot.
Chinese Nation-State Hackers Found To Be Actively Exploiting Ivanti Zero-Days
Researchers have reported that hackers purportedly linked to the Chinese state are actively exploiting a couple of remote zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN devices. Threat actors take advantage of the two vulnerabilities (CVE-2023-46805 and CVE-2024-21887) to gain unauthorized access to compromised systems. They can then steal data, configure files, or execute commands remotely. It is also possible that the Chinese government-backed hackers have exfiltrated some credentials of the VPN service users.
ZeroFox Intelligence Profile - APT28 Distributes New Malware Strains OCEANMAP, MASEPIE, and STEELHOOK
This intelligence profile from ZeroFox discusses an advisory the Computer Emergency Response Team of Ukraine (CERT-UA) released on a new phishing campaign by Russia state-affiliated Advanced Persistent Threat (APT) group APT28 (aka Fancy Bear, Sednit, Pawn Storm, and Sofacy Group). Detected between December 15 and December 25, the campaign utilizes previously undocumented malware strains—namely, OCEANMAP, MASEPIE, and STEELHOOK—to collect information from the networks of numerous Ukrainian government entities, as well as possibly several undisclosed Polish organizations. The extent of the sensitive information stolen in these attacks has not yet been publicly disclosed.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user NoName057(16): Actor Claims to Attack Various German Websites in Response to Farmers Protest
- Telegram user Blackjack: Actor Claims Attack Against M9com as Revenge for Kyivstar
VULNERABILITIES
- CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
- CVE-2023-6377: A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes.
EXPLOITS
- CVE-2022-36534: Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
- CVE-2020-25736: Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
Tags: DIB, tlp:green