zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • North Korea-Backed Kimsuky Believed to be Using Information Stealers to Target South Korea
  • Cisco Expressway Series Cross-Site Request Forgery Vulnerabilities
  • APTs Exploiting FortiOS Vulnerabilities in Critical Infrastructure Attacks

North Korea-Backed Kimsuky Believed to be Using Information Stealers to Target South Korea

North Korean state actor Kimsuky is believed to be using a priorly undocumented Golang-based information stealer called Troll Stealer to target South Korean entities. Troll Stealer shares similarities with malware families previously used by the threat group, thereby justifying its link to Kimsuky. An analysis from cybersecurity researchers reveals that the threat actor has been using a dropper disguised as a security program installation file from a South Korean company named SGA Solutions to launch Troll Stealer. The malware strain is capable of exfiltrating information from Government Public Key Infrastructure and has possibly been used to attack administrative and public organizations in South Korea.

Cisco Expressway Series Cross-Site Request Forgery Vulnerabilities

Cisco has released patches for vulnerabilities affecting its Expressway Series collaboration gateways, including two critical ones exposing devices to cross-site request forgery (CSRF) attacks. CSRF vulnerabilities allow attackers to manipulate users into performing unwanted actions, such as adding new user accounts or gaining admin privileges, by tricking them into clicking malicious links or visiting attacker-controlled webpages. The two critical CSRF vulnerabilities (CVE-2024-20252 and CVE-2024-20254) can be exploited remotely by attackers to target unpatched Expressway gateways. CVE-2024-20255 can alter system configurations and trigger denial of service conditions. Cisco's Product Security Incident Response Team (PSIRT) has not detected any public proof of concept exploits or exploitation attempts targeting these vulnerabilities.

APTs Exploiting FortiOS Vulnerabilities in Critical Infrastructure Attacks

Fortinet has warned of Advanced Persistent Threats (APTs), including those linked to China, exploiting two FortiOS vulnerabilities in attacks across various sectors. Two vulnerabilities, one patched in December 2022 and one revealed in June 2023, were exploited as zero-days by Chinese threat actors. One of these was used to specifically target government entities. Some organizations have yet to patch these vulnerabilities, leading to ongoing attacks in government institutions, service providers, manufacturing, consultancy, and critical infrastructure sectors. Fortinet has shared technical details and Indicators of Compromise (IoCs), connecting the attacks to Chinese threat groups like Volt Typhoon, APT15, and APT31, with CISA noting pre-positioning for disruptive actions.

Tags: DIB, tlp:green