zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 20, 2024

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Operation DuneQuixote Delivers New Backdoor to Government Entities in Middle East
  • Europol Dismantles Phishing Platform LabHost
  • Cyberattack Takes Frontier Communications Offline

Operation DuneQuixote Delivers New Backdoor to Government Entities in Middle East

A previously undocumented backdoor named CR4T has emerged in a stealthy cyber campaign dubbed DuneQuixote, targeting Middle Eastern government entities. Discovered in February 2024, the operation researchers suspect the campaign began a year earlier. The attack starts with a dropper masquerading as a regular executable, DLL file, or a modified installer for Total Commander. The dropper extracts an embedded command-and-control (C2) address decoded using an inventive method involving Spanish poetry snippets. Once activated, CR4T, a C/C++-based memory-only implant, facilitates remote command execution and file manipulation, posing a grave threat to targeted systems.

Europol Dismantles Phishing Platform LabHost

Law enforcement agencies across 19 countries have collaborated to dismantle LabHost, a major phishing-as-a-service platform. The operation led to the shutdown of several surface web sites and the arrest of 37 individuals, including four believed to be the masterminds behind LabHost, originating from the UK. Investigators raided 70 addresses globally, uncovering over 40,000 phishing domains used by 2,000 registered users. The platform facilitated the theft of half a million payment card numbers, 64,000 PINs, and over one million passwords. The service, operational since 2021, offered fake websites for phishing, targeting financial, postal, and telecommunication sectors. The Metropolitan Police revealed LabHost's operators earned over USD 1.1 million from customers. Additionally, over 800 users are now under active investigation.

Cyberattack Takes Frontier Communications Offline

Frontier Communications has recently suffered a cyberattack that resulted in the theft of unspecified personally identifiable information (PII). The company has shut down its operations in 25 U.S. states. According to sources, an unauthorized third party gained access to "portions of its information technology environment." The company has taken certain systems offline as part of its containment efforts. An investigation is underway and the company has notified law enforcement authorities.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-0671: Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Midgard GPU Kernel Driver: from r19p0 through r32p0; Bifrost GPU Kernel Driver: from r7p0 through r48p0; Valhall GPU Kernel Driver: from r19p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r48p0.
  • CVE-2024-1065: Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.

EXPLOITS

  • CVE-2023-5222: A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0.
  • CVE-2023-5702: A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic.

BREACHES

Tags: DIB, tlp:green