zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukraine Military Targeted With Russian APT PowerShell Attack
  • INTERPOL-Led Operation Targets Growing Cyber Threats
  • Johnson Controls Confirms Data Theft and USD 27 Million Expenses in Cyberattack

Ukraine Military Targeted With Russian APT PowerShell Attack

A Russian advanced persistent threat (APT) has initiated a targeted PowerShell attack campaign against the Ukrainian military. The attack is reportedly observed to share certain similarities in TTP with prior campaigns against the Ukrainian military. The campaign is reported to be associated with the threat actors behind Shuckworm. The STEADY#URSA, a campaign nicknamed by cybersecurity researchers, employs a newly discovered SUBTLE-PAWS PowerShell-based backdoor to infiltrate and compromise targeted systems. Researchers claim that the SUBTLE-PAWS backdoor is exclusive for its use of off-disk/PowerShell stagers for execution and employs additional layers of obfuscation and evasion techniques.

INTERPOL-Led Operation Targets Growing Cyber Threats

INTERPOL has recently released its findings on a three-month investigation in 2023 into growing global phishing, malware and ransomware attacks. One thousand three hundred suspicious IP addresses or URLs have been identified in Operation Synergia, while 70 percent of the command-and-control (C2) servers identified have been taken down, with the remainder currently under investigation. According to INTERPOL, authorities detained 31 individuals and identified 70 suspects involved in cybercrime. The majority of the 26 C2 servers taken down were in Europe, leading to 26 arrests.

Johnson Controls Confirms Data Theft and USD 27 Million Expenses in Cyberattack

Johnson Controls, a building technologies multinational conglomerate, has disclosed that a September 2023 ransomware attack resulted in data theft and cost the company more than USD 27 million in expenses. The cyberattack continued to disrupt and limit the company’s systems well into the first quarter of 2024. Johnson Controls has further confirmed that it has now restored the impacted systems and applications. However, it expects to incur additional third-party expenses to remediate the incident.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-32333: IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.
  • CVE-2023-48792: Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

EXPLOITS

  • CVE-2022-29593: relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.
  • CVE-2022-35411: rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

BREACHES

Tags: DIB, tlp:green