ZeroFox Cyber Intelligence Daily Brief - March 21, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 21, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is todayβs daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Sale of Custom Phishlets for Evilginx3 Tool
- Spa Grand Prix Email Account Hacked to Phish Banking Info From Fans
- 300,000 Systems Vulnerable to New Loop DoS Attack
ZeroFox Intelligence Flash Report - Sale of Custom Phishlets for Evilginx3 Tool
On March 11, the well-regarded threat actor βblackdatabaseβ announced the sale of custom phishlets for Evilginx3 on the dark web forum xss. The phishlets for sale target multiple companies; prices start at USD 500 and range up to USD 5,000 for phishlets targeting specified financial sector entities. Evilginx3, when used in conjunction with phishlets, could enable attackers to steal session data, facilitate multi-factor authentication (MFA) bypass, and grant seamless access to sensitive data and funds stored in bank accounts.
Spa Grand Prix Email Account Hacked to Phish Banking Info From Fans
Hackers recently targeted the Belgian Grand Prix event in a phishing attack that lured fans with the promise of EUR 50 gift voucher, with a purchase, to a fake website resembling its official site. The attackers hijacked the official contact email to send victims malicious emails with an embedded link directing them to the site where victims entered their payment information. The phishing attack is being contained as investigations are trying to determine the cause and the scale after SPA GP responded to the attack in a few hours.
300,000 Systems Vulnerable to New Loop DoS Attack
German researchers have discovered a new denial-of-service (DoS) attack vector that uses IP spoofing to create a loop between two servers, creating large volumes of traffic that can result in a denial of service for involved systems or networks. The list of confirmed impacts includes Network Time Protocol (NTP), Domain Name System (DNS), and Trivial File Transfer Protocol (TFTP), as well as legacy protocols such as Echo, Chargen, and Quote of the Day (QOTD). The researchers have estimated roughly 300,000 impacted internet hosts. New CVE identifiers CVE-2024-1309 and CVE-2024-2169 have been assigned to the vulnerabilities involved in the new loop DoS attack. The researchers have published an advisory recommending several preventive measures and have advised defenders to disrupt the DoS loop in case of an attack.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user OneERA: Actor Claims to Leak Data From MediaWorks
- Telegram user UserSec: Actor Claims Attack Against Multiple Entities
EXPLOITS
- CVE-2020-15505: A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2020-11854: Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulnerability could allow Arbitrary code execution.
BREACHES
- Combolist: 'πππππΉππππ_ππ@π½πππ±πππ.txt' (75,795 Records): Email Address, Password
- Combolist: '#AMAZON3.9.24.txt' (800 Records): Email Address, Password
Tags: DIB,Β tlp:green