zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 16, 2024

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - February 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Government Neutralizes Botnet Operated by Russian APT28
  • Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
  • LockBit Claims Cyberattack on Fulton County

U.S. Government Neutralizes Botnet Operated by Russian APT28

The U.S. government has neutralized a Russian APT28 cyber-espionage operation using a small office/home office (SOHO) router botnet of several Ubiquiti Edge OS routers. The Justice Department revealed that hackers not associated with Russian Intelligence first infected the target routers with Moobot malware. Subsequently, APT28, connected to the Russian GRU, repurposed these compromised routers as a global espionage platform. Authorized by court order, U.S. law enforcement neutralized the botnet by copying and deleting stolen data from compromised routers. The operation also temporarily modified firewall rules to block remote access.

Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization

CISA and the Multi-State Information Sharing & Analysis Center (MS-ISAC) investigated a state government organization's network environment after documents containing host and user information, along with metadata, were discovered on a dark web brokerage site. The assessment confirmed that an unidentified threat actor accessed the documents via the account of a former employee after connecting to the victim's VPN [T1133] in an attempt to blend in with legitimate traffic and avoid detection. A Cybersecurity Advisory (CSA) has been released by CISA and MS-ISAC to offer network defenders with the tactics, techniques, and procedures (TTPs) used by the threat actor and methods to protect against similar exploitation of both unnecessary and privileged accounts.

LockBit Claims Cyberattack on Fulton County

On February 14, ZeroFox Intelligence observed the notorious LockBit 3.0 ransomware group claiming an attack on Fulton County, saying it has access to confidential documents. The cyberattack continues to disrupt technological systems at the county government, including justice and property tax systems and two-thirds of phone lines. The threat actor has stated it aims to “give maximum publicity to this situation” and that the documents, once public, will be of interest to many.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-6451: Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

  • CVE-2024-0036: In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EXPLOITS

  • CVE-2020-12502: Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.
  • CVE-2021-46398: A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

BREACHES

Tags: DIB, tlp:green