zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 20, 2024

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - January 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian APT Develops a Custom Malware Strain; Diverts from its Usual Tactics
  • TeamViewer Abused to Breach Networks in New Ransomware Attacks
  • Oracle Critical Patch Update Advisory

Russian APT Develops a Custom Malware Strain; Diverts from its Usual Tactics

With just a few days to go for the U.S. elections, Russia-backed APT ColdRiver has rolled out a custom malware strain called Spica. The strain is a proprietary backdoor enabling hackers to gain control over compromised systems. Hackers can then execute arbitrary shell commands and exfiltrate files. The APT group’s deployment of malware indicates an evolutionary shift from its regular modus operandi involving credential phishing. The threat group’s primary cyberespionage targets in the past have been NGOs, former intelligence and military officers, and NATO governments.

TeamViewer Abused to Breach Networks in New Ransomware Attacks

Ransomware actors are using TeamViewer to gain initial access to organizational endpoints and attempting to deploy encryptors based on the leaked LockBit ransomware builder. A recent report shows that cybercriminals are adopting newer methods to take over devices through TeamViewer for ransomware deployment. Log files revealed connections from the same source suggesting a common attacker. Reportedly, the attackers attempted to deploy the payload with a DOS batch file (PP.bat), which executed a DLL file (payload) via a rundll32.exe command.

Oracle Critical Patch Update Advisory

Oracle released its Critical Patch Update Advisory for January 2024 to address vulnerabilities in multiple products. This Critical Patch Update contains 389 new security patches across the product families; addressing vulnerabilities like CVE-2022-36944, CVE-2022-42920, CVE-2022-36944, CVE-2022-1471, CVE-2023-34034, and CVE-2023-34034 with a base score of 9.8 each. Oracle reportedly continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CCVE-2024-0705: The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

BREACHES

Tags: DIB, tlp:green