zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 16, 2024

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • StopCrypt: Most Widely Distributed Ransomware Now Evades Detection
  • Chinese Threat Actors Reported Backdooring Digital Locks
  • Pro-Palestine Threat Actor Claims to Have Breached Viber Messenger Data

StopCrypt: Most Widely Distributed Ransomware Now Evades Detection

Cybersecurity researchers have found a new variant of the STOP ransomware called StopCrypt (aka STOP Djvu), which employs shellcodes to evade security tools. StopCrypt is a widely distributed ransomware strain that targets consumers instead of businesses, hoping to generate small ransom payments. The malware is typically distributed through malvertising and shady sites distributing adware bundles disguised as free software, game cheats, and software cracks. The new variant uses a multi-stage execution process and process hollowing to hijack legitimate processes and inject its payload for discreet execution in memory. Once executed, files are encrypted and a ransom note is created in every impacted folder. It also uses dynamically constructed API calls on the stack to allocate the necessary memory space for read/write and execution permissions, making detection harder.

Chinese Threat Actors Reported Backdooring Digital Locks

A U.S. Senator has recently sent a letter to the National Counterintelligence and Security Center (NSCS) director warning that the electronic safes and locks made in China pose a significant national security risk to Americans. He has urged the White House threat-intel arm to sound the alarm on commercial safes and locks. The backdoor codes in commercially available safes can supposedly be exploited by foreign adversaries to steal sensitive information. The Senator has suggested that the NSCS update its educational materials with recommendations for businesses to use locks that meet U.S. government security standards. This will help businesses to protect their valuable intellectual property and America's global economic edge from foreign espionage.

Pro-Palestine Threat Actor Claims to Have Breached Viber Messenger Data

On March 14, ZeroFox observed threat actor “Handala Hack,” a pro-Palestine group, claiming to have infiltrated Viber Messenger and breached its data. The threat group alleges on its Telegram channel to be selling 740 GB of data as well as the company’s source code for 8 BTC (bitcoins). A Viber spokesperson has reportedly stated that upon investigation, the company has found no evidence to support any claims of intrusion or compromise of user data.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-2489: A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256896. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
  • CVE-2024-2488: A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIP leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256895. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

EXPLOITS

  • CVE-2020-12352: Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
  • CVE-2020-12351: Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

Tags: DIB, tlp:green