zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 5, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Lurie Children's Hospital Investigating Cybersecurity Matter as Network Down for Second Day
  • AnyDesk Servers Hacked, Customers Urged to Reset Passwords
  • New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw

Lurie Children's Hospital Investigating Cybersecurity Matter as Network Down for Second Day

Lurie Children's Hospital reported a cyber incident that prompted the hospital to take its network offline, affecting phones, email, internet service and cerian medical equipment. The cyber incident is reported to have impacted the main hospital, outpatient centers and primary care offices. The incident has forced the hospital to adopt a first-come, first-served approach, prioritizing emergency situations as they work to address the impact of the cyberattack on their systems and services.

AnyDesk Servers Hacked, Customers Urged to Reset Passwords

AnyDesk, a remote access software company, has experienced a security breach compromising its production systems. Although attackers targeted the company and reportedly stole source code and code signing certificates, AnyDesk has confirmed that it was not a ransomware attack. The investigation indicates that there's no evidence suggesting the theft of private keys, tokens, or passwords that could provide access to end-user devices. In response to the incident, AnyDesk promptly revoked all security-related certificates and remediated or replaced affected systems. The company is planning to issue a new code signing certificate for binaries to enhance security. To proactively protect against potential threats, AnyDesk has revoked all passwords for its web portal and alerted the authorities to address the breach promptly. As of now, there are no indications that the breach has impacted end-user devices.

New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw

The Mispadu banking Trojan, known for targeting users in Latin America, has exploited a now-patched Windows SmartScreen security flaw to compromise users in Mexico. The attack involves a new variant of the malware, distributed through phishing emails, and utilizes a Windows SmartScreen bypass flaw that was patched by Microsoft in November 2023. The malware specifically targets victims in Latin America and has been part of a larger family of banking malware in the region. The attackers employ rogue internet shortcut files within bogus ZIP archives to deliver the malware. The article also mentions other cyber threats, including the DICELOADER downloader used by the Russian FIN7 group and new cryptocurrency mining campaigns employing booby-trapped archives and game hacks.

VULNERABILITIES

  • CVE-2024-1060: Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
  • CVE-2024-1077: Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

BREACHES

Tags: DIB, tlp:green