ZeroFox Cyber Intelligence Daily Brief - February 3, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 3, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CERT-UA Warns of a PurpleFox Malware Strain Campaign Targeting Systems in Ukraine
- Nation State Hacker Suspected to Be Responsible for Cloudflare Cyberattack
- New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways
CERT-UA Warns of a PurpleFox Malware Strain Campaign Targeting Systems in Ukraine
The Computer Emergency Response Team in Ukraine (CERT-UA) has detected a PurpleFox malware campaign that has infected at least 2000 computers. PurpleFox strain infects systems where users run laced Microsoft Software Installers (MSIs). The malware strain also has self-propagating functionalities that enable it to exploit multiple vulnerabilities. CERT-UA has listed the signs of PurpleFox malware infection and notes that the mitigation procedures can be challenging. It recommends isolating systems with outdated OS versions and software using VLAN or physical network segmentation with incoming or outgoing filtering to stop the infection from spreading.
Nation State Hacker Suspected to Be Responsible for Cloudflare Cyberattack
On November 23, 2023, Cloudflare detected a threat actor accessing one of its servers, prompting the company to immediately launch an investigation and remove the threat actor from the compromised systems. The attacker conducted reconnaissance and established persistent access to the targeted server. Cloudflare has confirmed the threat actor’s connections were terminated on November 24 and no customer data or systems were impacted by the cyberattack. Based on discussions with its colleagues in the industry and government, Cloudflare suspects a nation-state attacker aiming to access its global network to be responsible for the attack.
New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways
A recent CISA advisory updates users on two new vulnerabilities and software updates as published by Ivanti in its official announcement. The two new vulnerabilities include CVE-2024-21888 and CVE-2024-21893, which involve privilege escalation and server-side request forgery. Ivanti’s new software updates address these vulnerabilities in specific versions of the software as well as present mitigations for affected software versions that do not yet have updates.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user DBLand: Actor Allegedly Selling Access From Telefónica
- BreachForums user IntelBroker: Actor Claims to Leak Data From Hewlett Packard Enterprise
VULNERABILITIES
- CVE-2024-22320: IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization.
- CVE-2024-22779: Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin[.]java.
EXPLOITS
- CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products.
- CVE-2022-23642: Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the
gitserverservice. The service acts as a git exec proxy, and fails to properly restrict callinggit config.
BREACHES
- Mother of All Breaches (MOAB): gympass.com (242,944 Records): Email Address, Name
- BreachForums: Adobe Breach (152424760 Records): Email Address, Password, IP Address
Tags: DIB, tlp:green