ZeroFox Cyber Intelligence Daily Brief - April 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Bassterlord Returns to Sell Third Malicious Publication
- 576,000 Roku Accounts Hacked in Credential-Stuffing Attacks
- U.S. Treasury Targets Hamas UAV Unit Officials and Cyber Actor
ZeroFox Intelligence Flash Report - Bassterlord Returns to Sell Third Malicious Publication
On April 7, threat actor “Bassterlord” posted in the the deep and dark web (DDW) forum xss. The thread addresses multiple topics but was locked shortly after upon the author’s request. Bassterlord claims that following the February 2024 law enforcement (LE) disruption of LockBit, their associated group, the National Hazard Agency (NHA), was under close surveillance by the Federal Bureau of Investigation (FBI). This led to the seizure of all of NHA’s funds (including those stored in XMR) and the cessation of NHA’s operations. A new educational manual was also advertised for sale, which allegedly assists threat actors in mass brute force targeting corporations, including how to “organize” attacks.
576,000 Roku Accounts Hacked in Credential-Stuffing Attacks
Roku has warned that 576,000 user accounts were hacked in a credential stuffing attack. Meanwhile, about 15,000 accounts were accessed by unauthorized actors using login credentials in early March. Roku clarifies that its systems were not compromised in the two credential stuffing attacks. The attackers likely obtained login credentials from other sources where users reused the same login information. In less than 400 instances, unauthorized purchases were made using stored payment methods, but no sensitive information such as full credit card numbers was accessed. Roku has reset passwords for affected accounts, refunded unauthorized charges, and enabled two-factor authentication for all accounts. Users are advised to create strong passwords, remain vigilant for suspicious activity, and stay informed about account security measures.
U.S. Treasury Targets Hamas UAV Unit Officials and Cyber Actor
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) and the European Union are imposing sanctions on Hamas leaders involved in cyber and unmanned aerial vehicle (UAV) operations. This joint action aims to disrupt Hamas's ability to conduct further attacks, through cyber warfare and the production of UAVs. The property and interests in the United States of the designated leaders are blocked and transactions involving them are prohibited. Non-U.S. financial institutions and other individuals engaging in certain transactions or activities with sanctioned entities and individuals may expose themselves to sanctions risk or be subject to an enforcement action.
VULNERABILITIES
- CVE-2024-3774: aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
- CVE-2024-3157: Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
BREACHES
- Combolist: 'THE_HUNTER%20COMBO%20IPTV%20EXPLOIT%20MIX%20TARGET%20IPTV%2013_3_2024.txt' (69,722 Records): Email Address, Password
- Combolist: '750x_Paypal_Logs_Full_Caprure_Private_By_PrXService.txt' (741 Records): Email Address, Password
Tags: DIB, tlp:green