zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • SEC Confirms X Account Hack
  • North Korea-Linked APT Weaponize Fake Research to Deliver RokRAT Backdoor
  • Chinese Cyberespionage Group Has Been Exploiting VMware Vulnerability Since 2021

SEC Confirms X Account Hack

The U.S. Securities and Exchange Commission (SEC) has confirmed unauthorized access and activity on its @SECGov X account, revealing that the breach resulted from a SIM swap attack on the associated cell phone number. In this attack, the unauthorized party gained control of the phone number associated with the account. However, there is no evidence suggesting access to SEC systems, data, devices, or other social media accounts. Law enforcement is currently investigating how the unauthorized party convinced the carrier to change the SIM and how they identified the specific phone number associated with the SEC account.

North Korea-Linked APT Weaponize Fake Research to Deliver RokRAT Backdoor

According to a cybersecurity investigation, North Korea-linked APT37 (alias ScarCruft, InkySquid, RedEyes, Ricochet Chollima, and Ruby Sleet) has been targeting cybersecurity professionals and North Korean affairs experts in a new campaign. The campaign involves new infection chains, including sharing a technical threat research report as a decoy to deliver RokRAT backdoor. ScarCruft, through this campaign, acquires strategic intelligence and possibly gains insights into non-public cyber threat intelligence and defense strategies.

Chinese Cyberespionage Group Has Been Exploiting VMware Vulnerability Since 2021

Chinese cyberespionage group UNC3886 has been exploiting a critical vCenter Server vulnerability (CVE-2023-34048) as part of a campaign revealed in June 2023. VMware has stated that it is aware of the wild exploitation of CVE-2023-34048 which was patched in October 2023. The cyberspies exploit the vulnerability to deliver backdoors to compromised systems and then weaponize a VMware Tools authentication bypass flaw to escalate privileges, harvest files, and exfiltrate them from guest VMs.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-34048: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol.A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
  • CVE-2024-22195: Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax.

EXPLOITS

  • CVE-2021-27878: An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication.
  • CVE-2021-27876: An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication.

BREACHES

Tags: DIB, tlp:green