zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Actor Seeks Access to Government and Critical Infrastructure Networks
  • ZeroFox Intelligence Flash Report - New “Wolf’s Den” Platform Comes With Uncensored AI Text Generation
  • Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

ZeroFox Intelligence Flash Report - Actor Seeks Access to Government and Critical Infrastructure Networks

On March 27, untested threat actor “Nikazon” posted in the deep and dark web (DDW) forum RAMP advertising their search for affiliates able to provide illicit access to the networks of industrial, military, justice, and political targets. ZeroFox observed an approximately 55 percent increase in the number of ransomware and digital extortion (R&DE) attacks targeting organizations within the defense, government, and critical infrastructure sectors between Q1 2023 and Q1 2024. This advertisement is likely supportive of an ongoing shift in DDW norms manifested by financially-motivated R&DE threat actors punitively seeking victim organizations—the targeting of which would traditionally be frowned upon by other groups, affiliates, and platform moderators.

ZeroFox Intelligence Flash Report - New “Wolf’s Den” Platform Comes With Uncensored AI Text Generation

On March 21, well-known threat actor and malware-developer “Poe” announced on the dark web forum Onniforums the launch of a new anti-censorship underground community dubbed “Wolf’s Den.” Access to the full version of Wolf’s Den is expected to only be available via manually issued invites. Poe claims Wolf’s Den features uncensored artificial intelligence (AI) text and image generation—including malware scripting—and contains a video allegedly showing live interaction demonstrating a generative model writing out ransomware code. The project is expected to gain significant traction within Russian and English-speaking threat actor communities, with actors attempting to get an invite to Wolf’s Den in order to freely create malware applications.

Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

The threat actor known as TA558 has been attributed to a new phishing campaign that targets a wide range of sectors in Latin America with the goal of deploying Venom RAT. The attacks are primarily on hotel, travel, trading, financial, manufacturing, industrial, and government verticals in Spain, Mexico, the United States, Colombia, Portugal, Brazil, Dominican Republic, and Argentina. According to cybersecurity researchers, phishing emails are being used as an initial access vector to deploy Venom RAT, a fork of Quasar RAT that is capable of extracting sensitive data and commandeering systems remotely. Following the law enforcement takedown of QakBot last year, it has been observed that threat actors have been increasingly using the DarkGate malware loader to target financial institutions in Europe and the United States.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-3227: A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument image_type leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259072.
  • CVE-2024-31033: JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class. NOTE: the vendor disputes this because the "ignores" behavior cannot occur (in any version) unless there is a user error in how JJWT is used, and because the version that was actually tested must have been more than six years out of date.

EXPLOITS

  • CVE-2020-8010: CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
  • CVE-2020-8012: CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

BREACHES

Tags: DIB, tlp:green