zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 19, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Malware on Japanese Tech Giant Fujitsu’s Computers Exposed Customer Data
  • APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme
  • Chinese APT Conducts Widespread Operation; Breaches 70 Organizations Worldwide

Malware on Japanese Tech Giant Fujitsu’s Computers Exposed Customer Data

Fujitsu has recently issued an apology for exposing customer data after discovering malware on its computers. The multinational corporation has released a statement saying that it had disconnected the affected business computers immediately after it confirmed the presence of malware and deployed measures to strengthen the monitoring of other business computers. Fujitsu has also reported the incident to Japanese regulators at the Personal Information Protection Commission. However, it remains unknown how long the data was exposed, and Fujitsu has yet to provide additional details about the breach.

APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme

Russian cyber espionage group APT28 has reportedly been engaged in multiple ongoing phishing campaigns across Europe, Americas, Asia. These campaigns use lure documents impersonating government and non-governmental organizations in sectors such as finance, critical infrastructure, cyber security, and healthcare. APT28 has targeted Ukrainian government entities and Polish organizations with phishing messages deploying customized decoys and information stealers like MASEPIE, OCEANMAP, and STEELHOOK. The phishing attacks impersonate entities from countries including Argentina, Ukraine, and the United States, using actual and doctored government documents to initiate infection chains. The scheme reportedly concludes with the execution of these tools, aimed at exfiltrating files, executing commands, and stealing browser data.

Chinese APT Conducts Widespread Operation; Breaches 70 Organizations Worldwide

Chinese advanced persistent threat (APT) group Earth Krahang has breached 70 organizations and targeted at least 116 across 45 countries in a sophisticated campaign active since early 2022. The threat group has reportedly compromised 48 government institutions, 10 of which are Foreign Affairs ministries, and targeted another 49 government agencies. The attackers exploit vulnerabilities in internet-connected servers and send spear-phishing emails to trick targets into installing custom backdoors for cyberespionage. Earth Krahang hackers misuse their access to hacked government systems to attack other governments. They set up private internet servers on compromised computers and try different password combinations to break into significant email accounts.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-47995: Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.
  • CVE-2023-47997: An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.

EXPLOITS

  • CVE-2021-3355: A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.
  • CVE-2020-7200: A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.

BREACHES

Tags: DIB, tlp:green