ZeroFox Cyber Intelligence Daily Brief - April 2, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 2, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia
- Shopping Platform PandaBuy Data Leak Impacts 1.3 Million Users
- Yacht Retailer’s Data Stolen in March Cyberattack
Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia
The Indian government has rescued and repatriated 250 citizens in Cambodia who were forced into conducting cybercrime. The Indian nationals were lured with employment opportunities in Cambodia but were forced to undertake illegal cyber work. According to sources, there are more than 5,000 Indians stuck in Cambodia and are forced to launch scams to extort money. The U.S. Department of State has called out China-based organized crime syndicates for posing as labor brokers to recruit people with English proficiency from Africa and Asia via social media with the promise of offering them lucrative jobs in Southeast Asia. An investigation is ongoing into locating and repatriating more victims.
Shopping Platform PandaBuy Data Leak Impacts 1.3 Million Users
Threat actor "Sanggiero," allegedly in coordination with IntelBoker," has leaked the data of more than 1.3 million customers of the PandaBuy online shopping platform. The threat actors have exploited multiple vulnerabilities to breach systems. The leaked data contained sensitive information such as email addresses, customer names, order numbers and details, shipping addresses, transaction details, payment IDs, and more. The data can be obtained by any registered members in exchange for a payment in cryptocurrency. PandaBuy has not made any statements about the data breach. The customers of PandaBuy are recommended to reset their password and to remain vigilant for scam attempts.
Yacht Retailer’s Data Stolen in March Cyberattack
MarineMax disclosed the theft of employee and customer data after a cyber attack last month. According to a filing with the Securities and Exchange Commission (SEC), the company is actively investigating the incident with external cybersecurity experts to determine the full scope of the breach. Reportedly, the threat actor accessed a restricted part of MarineMax's information network related to its retail operations. The investigation has confirmed that this threat actor managed to extract a limited amount of data, including personally identifiable information of customers and employees. Law enforcement authorities have been notified about the incident and that MarineMax will inform affected individuals.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user IntelBroker: Actor Claims to Leak Data From United States Army
- BreachForums user Osint_Proff: Actor Claims to Leak Data From Accipiter Capital Management
VULNERABILITIES
- CVE-2024-3160: ** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008 and HDCVI 1016 up to 20240401. This affects an unknown part of the file /cap.js of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier VDB-258933 was assigned to this vulnerability. NOTE: The vendor explains that they do not classify the information shown as sensitive and therefore there is no vulnerability which is about to harm the user.
EXPLOITS
- CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
- CVE-2020-11804: An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.
BREACHES
- Combolist: '3.txt' (639,373 Records): Email Address, Password
- Combolist: 'canada good.txt' (2,000 Records): Email Address, Password
Tags: DIB, tlp:green