ZeroFox Cyber Intelligence Daily Brief - January 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 27, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Blackwood Hackers Hijack WPS Office Update to Install Malware
- Critical Jenkins Vulnerability Exposes Servers to RCE Attacks
- Cisco Releases Security Advisory for Multiple Unified Communications and Contact Center Solutions Products
Blackwood Hackers Hijack WPS Office Update to Install Malware
A newly identified advanced threat actor named Blackwood is employing sophisticated malware known as NSPX30 in cyberespionage campaigns. The NSPX30 malware is used following adversary-in-the-middle (AitM) attacks. Blackwood's targets reportedly include entities in China, Japan, and the United Kingdom. The malware is delivered through the update mechanisms of legitimate software such as WPS Office, Tencent QQ, and Sogou Pinyin. Blackwood executes AitM attacks, intercepting NSPX30-generated traffic to conceal activities and hide command and control servers. The group may share access with other Chinese APT groups, as observed in toolkits associated with actors like Evasive Panda, LuoYu, and LittleBear.
Critical Jenkins Vulnerability Exposes Servers to RCE Attacks
Maintainers of the Jenkins open-source CI/CD automation software have addressed nine security flaws, including a critical bug (CVE-2024-23897) that could lead to remote code execution (RCE). This vulnerability is described as an arbitrary file read issue through the built-in command line interface (CLI), utilizing the args4j library for parsing command arguments. Exploiting this flaw, a threat actor with "Overall/Read" permission could read entire files, while those without permission could access the first three lines of files. This vulnerability could potentially be used to read binary files containing cryptographic keys, posing a security risk. Other resolved issues include vulnerabilities related to resource root URLs, "Remember me" cookies, stored XSS attacks via build logs, CSRF protection bypass, and more.
Cisco Releases Security Advisory for Multiple Unified Communications and Contact Center Solutions Products
Cisco released a security advisory to address a vulnerability (CVE-2024-20253) affecting multiple Unified Communications Products. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- XSS user KernelMode: Actor Claims to Promote an AV/EDR killer
- Telegram user Писарь из Штаба: Former Killnet Members Claim to Form Killnet 2.0
VULNERABILITIES
- CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity.
- CVE-2024-0812: Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
EXPLOITS
- CVE-2022-23277: Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-42321: Microsoft Exchange Server Remote Code Execution Vulnerability
BREACHES
- Combolist: 'Crunchyroll vVasar 2023-06-28_20-58-56.txt' (88 Records): Email Address, Password
Tags: DIB, tlp:green