zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • News Farm Found Impersonating Over 60 Prominent English Media Outlets
  • CryptoChameleon Attackers Target Apple, Okta Users with Tech Support Gambit
  • U.S. Charges Hacker, Offers USD 10 Million Reward for Capture

News Farm Found Impersonating Over 60 Prominent English Media Outlets

Cybersecurity researchers have come across a news farm impersonating over 60 prominent English-language media outlets based in the United States and the United Kingdom , including Reuters and The Washington Post. The research has identified over 60 domains reposting articles from credible media and research organizations without proper attribution and traced the websites’ proprietor in India. The proprietor has been observed spamming comments sections of various websites with backlinks to the domains to improve their credibility. Some of the comments also appear to be advertisements for the sale of slots for press releases and product reviews, starting at USD 50 per post or a "bulk deal" priced at USD 1000.

CryptoChameleon Attackers Target Apple, Okta Users with Tech Support Gambit

A sophisticated phishing kit called CryptoChameleon has reportedly been targeting cryptocurrency companies where threat actors have been able to gain access to sensitive data like usernames and passwords, password reset URLs and photo IDs. A researcher suggests cryptocurrency platforms and other customer-facing organizations to strengthen authentication, such as WebAuthn-based passkeys. The attackers’ tactics largely involve personal outreach where personalized text messages and voice calls impersonate an employee’s support personnel.

U.S. Charges Hacker, Offers USD 10 Million Reward for Capture

A cyber attacker has been indicted by the United States Department of Justice (DoJ) for allegedly orchestrating a multi-year cyber campaign aimed at compromising U.S. government and private entities. The campaign targeted over a dozen entities including the United States Departments of the Treasury and State, defense contractors, an accounting firm, and a hospitality company. The cyber attacker purportedly posed as a cybersecurity specialist while orchestrating the attacks. The methods employed included spear-phishing, deploying malware, and masquerading as other individuals to gain victims' confidence. The U.S. State Department has announced a reward of up to USD 10 million for information leading to the hacker’s identification or location.

VULNERABILITIES

  • CVE-2024-20018: In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.
  • CVE-2024-20019: In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00351241; Issue ID: MSV-1173.

BREACHES

Tags: DIB, tlp:green