zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Missouri County Hit by Ransomware
  • U.S. State Department Launches Investigation into Claims of Data Breach
  • Mispadu Trojan Targets Europe, Thousands of Credentials Compromised

Missouri County Hit by Ransomware

Jackson County, Missouri disclosed a cyberattack that caused major disruptions to its IT systems, possibly due to a ransomware attack. Although investigations are ongoing to confirm the cause, the county has reportedly taken steps to contain the attack and is working on restoring services. The disruption has impacted various services including tax payments, online property, and inmate search systems. As a mitigation measure, Assessment, Collection, and Recorder of Deeds offices at physical locations are closed until the issue is resolved.

U.S. State Department Launches Investigation into Claims of Data Breach

The U.S. Department of State is reportedly investigating claims of a data breach after threat actor IntelBroker said it has leaked documents allegedly stolen from a government contractor, Acuity. The threat actor has further stated that the leaked database, containing classified information, belongs to the Five Eyes intelligence alliance. It supposedly includes the full names, emails, office numbers, and personal cell numbers of government, military, and Pentagon employees, as well as their email addresses.

Mispadu Trojan Targets Europe, Thousands of Credentials Compromised

Mispadu (aka URSA) has compromised thousands of credentials across Europe. Initially targeting Latin America, it has now expanded its operations to Italy, Poland, and Sweden. The banking trojan’s target entities span finance, services, motor vehicle manufacturing, law firms, and commercial facilities. The threat actor leverages stolen credentials to orchestrate malicious phishing emails, posing a significant threat to recipients. The multi-stage infection sequence starts with a PDF attachment sent via invoice-themed emails; this prompts the recipient to click on a booby-trapped link to download the complete invoice, resulting in the delivery of a ZIP archive. Mispadu attacks employ two command-and-control servers for fetching intermediate and final-stage payloads and credential exfiltration.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-2008: The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.2 via deserialization of untrusted input in the awl_modal_popup_box_shortcode function.
  • CVE-2024-2830: The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes.

BREACHES

Tags: DIB, tlp:green