ZeroFox Cyber Intelligence Daily Brief - March 2, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 2, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway Vulnerabilities
- Hackers Breach Taiwan Telecom Giant; Steal Sensitive Data
- New Bifrost Malware for Linux Mimics VMware Domain for Evasion
Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway Vulnerabilities
The Five Eyes intelligence alliance has issued an advisory about cyber threat actors exploiting security flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways. Cyber researchers have described how an encrypted version of malware known as BUSHWALK is placed in a directory excluded by Integrity Checker Tool (ICT). Ivanti has disclosed five security vulnerabilities impacting its products since January 10. Agencies have urged organizations to consider the significant risk of adversary access to these devices. Ivanti is releasing a new version of ICT that provides additional visibility into a customer's appliance and all files on the system.
Hackers Breach Taiwan Telecom Giant; Steal Sensitive Data
Hackers have breached Taiwan's largest telecom company, Chunghwa Telecom, stealing sensitive data, including documents from the armed forces, foreign affairs ministry, coast guard, and more. The Taiwanese defense ministry has confirmed the leak, revealing the hackers had sold the stolen 1.7 TB of information on the dark web. Additionally, the ministry has stated that an Air Force contract in the leak is not confidential information, “thus (there was) no information leakage.” The telecom company has conducted investigations to determine the cause of the attack. It has also confirmed that the attack had no significant impact on the company’s operations.
New Bifrost Malware for Linux Mimics VMware Domain for Evasion
Researchers have discovered a new Linux variant of the long-standing Bifrost remote access trojan (RAT). It infects users via malicious email attachments, payload-dropping sites, or deceptive domains resembling a legitimate VMware domain, making it harder to detect. Additionally, the malware's binary is compiled without debugging information, enhancing its stealth capabilities. Bifrost collects the victim's information, encrypts it using RC4, and exfiltrates it to the C2 server via a newly created TCP socket. A new finding highlights the emergence of an ARM version of Bifrost, indicating a broader targeting scope.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user R00TK1T ISC CYBER TEAM: Actor Announces Massive Cyber Attack Against High Profile Companies
- BreachForums user 303: Actor Claims to Leak Data From United States National Institutes of Health
VULNERABILITIES
- CVE-2024-0692: The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability.
- CVE-2024-23742: An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
BREACHES
- Telegram: '@BRADMAX 1900 FEB.zip' Botnet Breach (75,913 Records): Email Address, Password
- Telegram: 'GODELESS CLOUD.rar' Botnet Breach (18,891 Records): Email Address, Password
Tags: DIB, tlp:green