ZeroFox Cyber Intelligence Daily Brief - March 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian Hackers Using TinyTurla-NG to Breach European NGO's Systems
- Exploit Released for Fortinet RCE Bug
- CISA, FBI, and MS-ISAC Release Update to Joint Guidance on Distributed Denial-of-Service Techniques
Russian Hackers Using TinyTurla-NG to Breach European NGO's Systems
The Russia-linked group Turla targeted an unnamed European non-governmental organization (NGO), infecting their systems with a backdoor known as TinyTurla-NG. This backdoor was first discovered during an attack on a Polish NGO supporting Ukrainian efforts during the Russian invasion. The attackers compromised systems, established persistence, and made exclusions to antivirus products. TinyTurla-NG functions as a backdoor for reconnaissance, file exfiltration to a command-and-control server, and deployment of a customized version of Chisel tunneling software. Investigations are ongoing to determine the exact intrusion pathway.
Exploit Released for Fortinet RCE Bug
Cybersecurity researchers have released a proof-of-concept (PoC) exploit for a critical Fortinet vulnerability (CVE-2023-48788) that Fortinet disclosed on March 12. This vulnerability in Fortinet's FortiClient Enterprise Management Server (EMS) software allows unauthenticated threat actors to gain remote code execution (RCE) with SYSTEM privileges. The vulnerability impacts FortiClient EMS versions 7.0 (7.0.1 through 7.0.10) and 7.2 (7.2.0 through 7.2.2). Fortinet has updated the advisory stating that the vulnerability is being exploited in the wild.
CISA, FBI, and MS-ISAC Release Update to Joint Guidance on Distributed Denial-of-Service Techniques
CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released a joint advisory to address the specific needs and challenges faced by organizations in defending against DDoS attacks. The guidance now includes detailed insight into three different types of DDoS techniques. Volumetric attacks aim to consume available bandwidth, protocol attacks exploit vulnerabilities in network protocols, and application attacks target vulnerabilities in specific applications or running services. The advisory also comprises steps for organizations to recover and mitigate any potential damages in case of a DDoS attack.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user infamous: Actor Claims to Sell Data from Department of Medical Examination and Treatment Management under Vietnam's Ministry of Health
- Telegram user Sylhet Gang: Actor Claims Attack Against Electrical Equipment Company in India
VULNERABILITIES
- CVE-2024-2805: A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan.
- CVE-2024-27516: Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
EXPLOITS
- CVE-2020-25901: Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
- CVE-2020-11698: An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.
BREACHES
- Combolist: 'COMBO%20CRISTIANOM%20NDUP%20-%2010mb.txt' (518,654 Records): Email Address, Password
- Combolist: 'Account.txt' (4,619 Records): Email Address, Password
Tags: DIB, tlp:green