ZeroFox Cyber Intelligence Daily Brief - January 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Releases Joint Advisory on Known IOCs Associated with Androxgh0st Malware
- Chrome Addresses Four Vulnerabilities Including an Actively Exploited Zero-Day
- Citrix Warns of New Netscaler Zero-Days Exploited in Attacks
CISA Releases Joint Advisory on Known IOCs Associated with Androxgh0st Malware
In a joint advisory, federal cybersecurity agencies have highlighted the known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) linked to the Androxgh0st malware strain. Androxgh0st malware establishes a botnet for victim identification and exploitation in vulnerable networks and targets files that contain confidential information, such as credentials, for various high-profile applications. Threat actors deploying Androxgh0st malware have been observed exploiting specific vulnerabilities (CVE-2017-9841, CVE-2021-41773, and CVE-2018-15133) which could lead to remote code execution. The advisory also comprises mitigation measures to reduce the likelihood and impact of cybersecurity incidents caused by the malware strain.
Chrome Addresses Four Vulnerabilities Including an Actively Exploited Zero-Day
Google Chrome recently addressed four vulnerabilities including an actively exploited zero-day flaw observed in the wild through now published updates. CVE-2024-0519 is a high severity vulnerability that allows threat actors to exploit its out-of-bounds memory access in the V8 JavaScript and WebAssembly engine to trigger a crash. By exploiting out-of-bounds memory access, an attacker could obtain secret values, including memory addresses. This could allow them to bypass security measures like address space layout randomization (ASLR), enhancing the likelihood of exploiting another vulnerability for unauthorized code execution instead of just causing denial of service.
Citrix Warns of New Netscaler Zero-Days Exploited in Attacks
Cirix’s Netscaler ADC and Gateway appliances have recently been the target of two active zero-day exploits. Two vulnerabilities, CVE-2023-6548 and CVE-2023-6549, affect the Netscaler management interface, posing risks of remote code execution and denial-of-service attacks on unpatched Netscaler instances. A threat monitoring platform shows that over 1,500 Netscaler management interfaces are now exposed on the Internet. Citrix reports that only customer-managed NetScaler appliances are affected by these zero-days, with Citrix-managed cloud services and Citrix-managed Adaptive Authentication remaining unaffected. The company urges admins and users to install the patch as soon as possible. Admins unable to install the patch right away are advised to block network traffic to affected instances and ensure they are not exposed online.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Athena Hack: Actor Claims Data Leak Against Bosch Turkey
- Telegarm user Team 1956: Actor Claims to Join Forces Against Israel
VULNERABILITIES
- CVE-2023-32726: The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
- CVE-2023-52069: kodbox v1.49.04 was discovered to contain a cross-site scripting (XSS) vulnerability via the URL parameter.
EXPLOITS
- CVE-2022-40797: Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload.
- CVE-2021-43258: CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads.
BREACHES
- Combolist: '144.172.113.70_4.txt' (18,533,681 Records): Email Address, Password
- Combolist: 'Yanbal.txt' (142 Records): Email Address, Password
Tags: DIB, tlp:green