ZeroFox Cyber Intelligence Daily Brief - February 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Malicious 'SNS Sender' Script Abuses AWS for Bulk Smishing Attacks
- Cybercriminal Pleads Guilty in U.S. to Key Role in Zeus, IcedID Malware Operations
- Turla Hackers Backdoor NGOs with New TinyTurla-NG Malware
Malicious 'SNS Sender' Script Abuses AWS for Bulk Smishing Attacks
The SNS Sender is a Python script used by cybercriminals, attributed to the ARDUINO_DAS group, to conduct SMS phishing (smishing) attacks by exploiting Amazon Web Services' Simple Notification Service (SNS). This tool marks the first instance of leveraging AWS SNS for such attacks. It requires a list of phishing links, AWS access keys, target phone numbers, sender ID, and message content. The inclusion of sender ID indicates familiarity with regional practices, suggesting the author may be from a region where this is common. The tool aims to propagate malicious links to harvest sensitive information from victims.
Cybercriminal Pleads Guilty in U.S. to Key Role in Zeus, IcedID Malware Operations
A cybercriminal, formerly on the FBI's Cyber Most Wanted List, has admitted guilt to RICO (Racketeer Influenced and Corrupt Organizations Act) and wire fraud charges in the United States after being extradited from Switzerland. Known as 'Tank,' the individual played a pivotal role in cybercrime involving the Zeus and IcedID malware. The threat actor has allegedly helped lead the Zeus operation since May 2009, infecting millions for unauthorized bank transfers. They later steered the IcedID malware operation from November 2018 to February 2021. U.S. authorities estimate losses in the tens of millions. Sentencing has been scheduled for May 9, with a potential 20-year prison term for each charge.
Turla Hackers Backdoor NGOs with New TinyTurla-NG Malware
Security researchers have discovered new malware named TinyTurla-NG and TurlaPower-NG, utilized by the Russian hacker group Turla for network access and data theft. The malware recently targeted an NGO, using TurlaPower-NG to extract master passwords from popular password management software. TinyTurla-NG is actively attacking NGOs in Poland, utilizing legitimate but vulnerable WordPress sites as C2 servers. These sites are compromised to facilitate script deployment, infection logging, and data storage. TinyTurla-NG functions as a backdoor, enabling persistent access to compromised systems.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Ancient Dragon: New Russian Hacktivist Group Emerges
- Telegram user Anonymous Sudan: Actor Claims DDoS Attack Against Swedish Police and Broadcast Media
VULNERABILITIES
- CVE-2024-22076: MyQ Print Server before 8.2 patch 43 allows Unauthenticated Remote Code Execution.
- CVE-2019-25067: A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API.
EXPLOITS
- CVE-2022-22832: This module exploits MQTT creds dump vulnerability in Servisnet Tessa.
- CVE-2020-12502: Korenix Technology JetWave products JetWave 2212X, JetWave 2212S, JetWave 2212G, JetWave 2311, and JetWave 3220 suffer from unauthenticated device administration, cross site request forgery, multiple command injection, and unauthenticated tftp action vulnerabilities.
BREACHES
- Mother of All Breaches (MOAB): kaixin001.com (6,008,415 Records): Email Address, Username, Password
- Mother of All Breaches (MOAB): cdsn.net (6,428,633 Records): Password, Email Address, Username
Tags: DIB, tlp:green