zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CERT-UA Warns of a PurpleFox Malware Strain Campaign Targeting Systems in Ukraine
  • Nation State Hacker Suspected to Be Responsible for Cloudflare Cyberattack
  • New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways

CERT-UA Warns of a PurpleFox Malware Strain Campaign Targeting Systems in Ukraine

The Computer Emergency Response Team in Ukraine (CERT-UA) has detected a PurpleFox malware campaign that has infected at least 2000 computers. PurpleFox strain infects systems where users run laced Microsoft Software Installers (MSIs). The malware strain also has self-propagating functionalities that enable it to exploit multiple vulnerabilities. CERT-UA has listed the signs of PurpleFox malware infection and notes that the mitigation procedures can be challenging. It recommends isolating systems with outdated OS versions and software using VLAN or physical network segmentation with incoming or outgoing filtering to stop the infection from spreading.

Nation State Hacker Suspected to Be Responsible for Cloudflare Cyberattack

On November 23, 2023, Cloudflare detected a threat actor accessing one of its servers, prompting the company to immediately launch an investigation and remove the threat actor from the compromised systems. The attacker conducted reconnaissance and established persistent access to the targeted server. Cloudflare has confirmed the threat actor’s connections were terminated on November 24 and no customer data or systems were impacted by the cyberattack. Based on discussions with its colleagues in the industry and government, Cloudflare suspects a nation-state attacker aiming to access its global network to be responsible for the attack.

New Software Updates and Mitigations to Defend Against Exploitation of Ivanti Connect Secure and Policy Secure Gateways

A recent CISA advisory updates users on two new vulnerabilities and software updates as published by Ivanti in its official announcement. The two new vulnerabilities include CVE-2024-21888 and CVE-2024-21893, which involve privilege escalation and server-side request forgery. Ivanti’s new software updates address these vulnerabilities in specific versions of the software as well as present mitigations for affected software versions that do not yet have updates.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-22320: IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization.
  • CVE-2024-22779: Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin[.]java.

EXPLOITS

  • CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products.
  • CVE-2022-23642: Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the gitserver service. The service acts as a git exec proxy, and fails to properly restrict calling git config.

BREACHES

Tags: DIB, tlp:green