zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Law Enforcement Halts LockBit’s Next-Gen Encryptor Development
  • Mustang Panda’s Advanced Malware Variant DOPLUGS Targets Asia
  • Cybercriminals Weaponizing Open-Source SSH-Snake Tool for Network Attacks

Law Enforcement Halts LockBit’s Next-Gen Encryptor Development

LockBit developers were crafting LockBit-NG-Dev, potentially the upcoming LockBit 4.0, before law enforcement agencies disrupted its operations in a joint operation dubbed "Operation Cronos." The United Kingdom's National Crime Agency and other cybersecurity researchers examined a sample of LockBit's latest iteration, designed to function on various operating systems. Unlike its predecessors, this work-in-progress malware strain is coded in .NET, compiled with CoreRT, and packed with MPRESS. While missing some features of earlier versions, it is in its last stages of development, offering three encryption modes, file exclusion options, and a self-delete mechanism.

Mustang Panda’s Advanced Malware Variant DOPLUGS Targets Asia

The China-linked APT group Mustang Panda has recently targeted several Asian countries using an updated version of the well-known PlugX (aka Korplug) backdoor dubbed DOPLUGS. DOPLUGS has several enhanced capabilities, including a separate launcher for DLL sideloading. This technique allows malicious code to piggyback on legitimate software, making it harder to detect. One of the most concerning features of DOPLUGS is the KillSomeOne module, which can spread malware via USB devices and steal data. This highlights the malware's versatility in digital espionage.

Cybercriminals Weaponizing Open-Source SSH-Snake Tool for Network Attacks

Threat actors have recently been exploiting an open-source network mapping tool called SSH-Snake in their attack campaigns. SSH-Snake, originally designed as a network mapping tool, has been repurposed into a self-modifying worm by these malicious actors. The worm utilizes SSH credentials obtained from compromised systems to propagate itself across networks. It autonomously scans known credential locations and shell history files to determine its next steps. Researchers have observed real-world attacks where threat actors use SSH-Snake to collect credentials, IP addresses of targets, and bash command history. These activities were uncovered following the identification of a command-and-control server hosting the stolen data.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-22547: WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
  • CVE-2024-25385: An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.

EXPLOITS

  • CVE-2021-41157: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type SUBSCRIBE are not authenticated in the affected versions of FreeSWITCH. Abuse of this security issue allows attackers to subscribe to user agent event notifications without the need to authenticate. This abuse poses privacy concerns and might lead to social engineering or similar attacks. For example, attackers may be able to monitor the status of target SIP extensions. Although this issue was fixed in version v1.10.6, installations upgraded to the fixed version of FreeSWITCH from an older version, may still be vulnerable if the configuration is not updated accordingly. Software upgrades do not update the configuration by default. SIP SUBSCRIBE messages should be authenticated by default so that FreeSWITCH administrators do not need to explicitly set the auth-subscriptions parameter. When following such a recommendation, a new parameter can be introduced to explicitly disable authentication.
  • CVE-2021-41105: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. When handling SRTP calls, FreeSWITCH prior to version 1.10.7 is susceptible to a DoS where calls can be terminated by remote attackers. This attack can be done continuously, thus denying encrypted calls during the attack. When a media port that is handling SRTP traffic is flooded with a specially crafted SRTP packet, the call is terminated leading to denial of service. This issue was reproduced when using the SDES key exchange mechanism in a SIP environment as well as when using the DTLS key exchange mechanism in a WebRTC environment. The call disconnection occurs due to line 6331 in the source file switch_rtp.c, which disconnects the call when the total number of SRTP errors reach a hard-coded threshold (100). By abusing this vulnerability, an attacker is able to disconnect any ongoing calls that are using SRTP. The attack does not require authentication or any special foothold in the caller's or the callee's network. This issue is patched in version 1.10.7.

BREACHES

Tags: DIB, tlp:green