zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • INC Ransom Threatens to Leak 3 TB of NHS Scotland Stolen Data
  • Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite
  • CISA Adds One Known Exploited Vulnerability to Catalog

INC Ransom Threatens to Leak 3 TB of NHS Scotland Stolen Data

ZeroFox has observed an update on the INC Ransomware leak site targeting NHS Scotland, UK-based healthcare system. The INC Ransom extortion gang has breached the National Health Service (NHS) of Scotland and is threatening to release three terabytes of stolen data unless a ransom is paid. They have shared images containing medical details and have posted sample documents with sensitive information about doctors and patients. NHS Dumfries and Galloway confirmed that clinical data of a small number of patients has been leaked as a result of a cyberattack two weeks ago, compromising IT systems and accessing a significant amount of patient and staff information. ZeroFox has detected 1,810 victims of ransomware and digital extortion in the past year, of which 25 percent are based in the Europe-Russia region.

Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite

Indian government entities and the energy industry have been hit with a cyberattack using a modified version of an open-source information stealer called HackBrowserData that can exfiltrate sensitive information. The information stealer was delivered via a phishing email, masquerading as an Indian Air Force invitation letter. The attacker used Slack channels as exfiltration points to upload confidential internal documents, private email messages, and cached web browser data after the malware's execution. The attack chain had a phishing message containing an ISO file, which contained a Windows shortcut (LNK), triggering the execution of a hidden binary present within the mounted optical disk image. The threat actor has successfully compromised private energy companies, harvesting financial documents, personal details of employees, and details about drilling activities in oil and gas. About 8.81 GB of data has been compromised throughout the campaign.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a Microsoft SharePoint Server Code Injection Vulnerability (CVE-2023-24955; CVSS base score of 7.2) to its Known Exploited Vulnerability catalog. This vulnerability has been observed to be exploited in the wild. Microsoft’s Security Response Center reports that “in a network-based attack, an authenticated attacker as a Site Owner could execute code remotely on the SharePoint Server.” CISA notes that vulnerabilities like this are frequently exploited by threat actors and pose “significant” risks to federal enterprises. CISA advises federal agencies as well as private organizations to patch this vulnerability at the earliest.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2013-4184: Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
  • CVE-2022-40896: A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

EXPLOITS

  • CVE-2020-12027: All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.
  • CVE-2020-12029: All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

BREACHES

Tags: DIB, tlp:green