zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 27, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Health Insurance Giant Kaiser will Notify Millions of a Data Breach After Sharing Patients’ Data With Advertisers
  • Godfather Banking Trojan Spawns 1.2K Samples Across 57 Countries
  • China-Linked Actors Target Chairperson of Belgian Foreign Affairs in Cyberattack

Health Insurance Giant Kaiser will Notify Millions of a Data Breach After Sharing Patients’ Data With Advertisers

Kaiser Permanente disclosed a data breach that affected 13.4 million former and current members and patients in the United States. An investigation found that certain technologies installed on its websites and mobile applications may have transmitted patients’ information with third-party advertisers. Information such as Personal data like names, IP addresses, account status, website and mobile app interactions, and health encyclopedia search terms were compromised in the breach. Following an internal investigation, the tracking codes have been removed from its websites and mobile apps. Meanwhile, the company will begin notifying the impacted individuals.

Godfather Banking Trojan Spawns 1.2K Samples Across 57 Countries

The Godfather mobile banking Trojan has proliferated rapidly since 2022 with approximately 1,000 samples circulating in many countries globally. This malware targets hundreds of banking apps and possesses sophisticated capabilities such as recording screens and keystrokes, intercepting two-factor authentication (2FA) calls and texts, and initiating unauthorized bank transfers. The developers of Godfather have reportedly been distributing this malware strain by automatically generating unique samples for customers, enabling them to evade detection more effectively.

China-Linked Actors Target Chairperson of Belgian Foreign Affairs in Cyberattack

According to an FBI report, Chinese hackers breached the personal computer of Els Van Hoof, chair of Belgium's Foreign Affairs Committee, in 2021. Van Hoof, also an Inter-Parliamentary Alliance on China (IPAC) member, has further stated that the cyberattack targeted 400 IPAC members. Beijing has denied involvement. The impact of the attack is still under investigation, though a Belgian newspaper has reported ongoing surveillance since 2021. This incident coincides with the arrest of an aide to a member of the European Parliament for the far-right Alternative for Germany for suspected espionage for China, highlighting growing concerns over Chinese cyber activities in Europe.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-4198: Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
  • CVE-2024-2312: GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

EXPLOITS

  • CVE-2024-3400: A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software.
  • CVE-2024-28741: Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

BREACHES

Tags: DIB, tlp:green