zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security Flaws
  • Florida Department of Juvenile Justice Computer Network Hacked
  • Visa Warns of New JSOutProx Malware Variant Targeting Financial Orgs

Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security Flaws

Cybersecurity researchers have identified multiple China-linked threat actors exploiting three (CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893) Ivanti security flaws. The researchers have identified several clusters, such as UNC5221, UNC5266, UNC5291, UNC5325, UNC5330, and UNC5337, involved in these activities. UNC5330 and UNC5337 have targeted Ivanti devices with custom malware such as TONERJAM, PHANTOMNET, and SPAWN, enabling persistent access. UNC5221, previously known for web shells like BUSHWALK, CHAINLINE, FRAMESTING, and LIGHTWIRE, now utilizes ROOTROT embedded in legitimate files to compromise networks and targets VMware vCenter servers with BRICKSTORM. UNC5291, likely associated with UNC3236, targets academic, energy, defense, and health sectors.

Florida Department of Juvenile Justice Computer Network Hacked

Hackers breached the network of the Florida Department of Juvenile Justice in Tallahassee. This breach resulted in the ongoing shutdown of the agency's digital infrastructure used to manage cases statewide. Among the affected systems is the Juvenile Justice Information System, which is essential to the agency's operations. A spokesperson mentioned that they are still evaluating the situation. Reports indicate that the hackers demanded a ransom to restore the agency's systems. The breach occurred when an employee opened a malicious email last week, according to sources. The agency's public website remained unaffected by the breach.

Visa Warns of New JSOutProx Malware Variant Targeting Financial Orgs

Visa's Payment Fraud Disruption (PDF) unit is reportedly warning people about rising instances of financial firms being targeted by the JsOutProx malware. A phishing campaign is distributing a new variant of the remote access trojan to financial targets in South and Southeast Asia, the Middle East, and Africa. The phishing emails (sent by suspected China-affiliated threat actors) masquerade as SWIFT or MoneyGram payment notifications from legitimate organizations. Visa’s alert provides indicators of compromise and mitigation measures that can help protect organizations from these attacks.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-21848: Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
  • CVE-2024-26810: Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability.

EXPLOITS

  • CVE-2020-8605: A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.
  • CVE-2020-15492: An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

BREACHES

Tags: DIB, tlp:green