ZeroFox Cyber Intelligence Daily Brief - March 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 27, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
- Apple Security Bug Opens iPhone, iPad to RCE
- Suspicious NuGet Packages Targets Industrial Systems to Exfiltrate Data
Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
Cybersecurity researchers have observed increased activities involving advanced persistent threat (APT) groups associated with China targeting entities in connection with the Association of Southeast Asian Nations (ASEAN). The recent wave of attacks include Mustang Panda in attacks against Myanmar and other Asian countries where the actor reportedly targeted them with phishing emails to deliver two malware packages. Additionally the actor was observed to install backdoors called DOPLUGS, a variant of PlugX backdoor. Other threat actors and groups include Earth Krahang which has targeted more than 100 entities across 35 countries to deliver malware like PlugX, ShadowPad, and more.
Apple Security Bug Opens iPhone, iPad to RCE
Apple has released more details on the security issues it patched for iOS and iPadOS 17.4.1. The updates address the vulnerability (CVE-2024-1580) that allows a remote attacker to execute arbitrary code on the affected devices. The vulnerability arises from an out-of-bounds write issue in dav1d AV1, an open source library for decoding AV1 video on a wide range of devices and platforms. The users of these affected devices can mitigate the risk by installing the new iOS and iPadOS updates.
Suspicious NuGet Packages Targets Industrial Systems to Exfiltrate Data
Cybersecurity researchers have reported a suspicious NuGet package that can harvest industrial data. According to the researchers, the package is likely designed to target users of technology from a Chinese industrial and digital equipment manufacturer, Bozhon. The malware strain exfiltrates data, including credentials, configuration settings, and proprietary data, through screenshots to a remote IP address. The strain is suspected to be a part of a supply chain campaign designed for industrial espionage.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user IntelBroker: Actor Claims to Leak Data From England and Wales Cricket Board
- Telegram user R00TK1T: Actor Allegedly Selling Source Code Of Financial Institutions
VULNERABILITIES
- CVE-2024-2944: A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php.
- CVE-2024-2945: A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php.
BREACHES
- Combolist: '236.0K Hotmail UHQ USA Target HQ Combolist Strong PWD.txt' (232,184 Records): Email Address, Password
- Combolist: 'shahid%20%285%29.txt' (12,223 Records): Email Address, Password
Tags: DIB, tlp:green