zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 8, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 8, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance
  • Millions of User Records Stolen From 65 Websites via SQL Injection Attacks
  • ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced

CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance

A joint cybersecurity advisory and a supplemental joint guidance against China-sponsored Volt Typhoon highlights the threat actor’s attempts to pre-position itself using living off-the-land (LOTL) techniques on IT networks in cyberattacks. The advisory provides actionable information from U.S. incident response activity. It can help organizations recognize Volt Typhoon techniques, assess whether these techniques have compromised any systems, and secure networks by implementing recommended mitigations.

Millions of User Records Stolen From 65 Websites via SQL Injection Attacks

A hacking group known as ResumeLooters carried out a cyberattack, stealing over two million email addresses and other personal information from at least 65 websites, across November and December 2023. The group reportedly used SQL injection attacks selling the stolen data on Chinese-speaking hacking-themed Telegram groups. Their targets were mainly in India, Taiwan, Thailand, Vietnam, and China, but they also hit sites in other countries including Australia, the Philippines, South Korea, Japan, the US, Brazil, Russia, and Italy. The group focused on compromising retail and recruitment websites, although victims in various other sectors were also identified.

ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced

Since its announcement on January 25, 2024, by untested actor “Null14”, an innovative malware loader-as-a-service offering has been gaining traction on the predominantly Russian-speaking dark web community exploit[.]in. The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates, enabling its deployment to remain undetected by various Windows systems as well as VirusTotal. Although ZeroFox can neither confirm nor disconfirm the credibility of the service, positive indicators add credence to the legitimacy of this loader service as an innovative malware-spreading technique. Malware distribution based on emulating credible software is likely on an upward trajectory, and this trend is expected to continue in the first half of 2024

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-25146: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs.
  • CVE-2024-25148: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the doAsUserId URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user.

EXPLOITS

  • CVE-2022-29457: Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
  • CVE-2022-28117: A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

BREACHES

Tags: DIB, tlp:green