zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Billions of Android Devices Open to 'Dirty Stream' Attack
  • Germany Says Russian Cyberattacks Targeted German Defence and Aerospace Sectors
  • The Five Families Cyberthreat Group Claims to Breach UAE Government Servers

Billions of Android Devices Open to 'Dirty Stream' Attack

Source: https://www.darkreading.com/cloud-security/billions-android-devices-open-dirty-stream-attack

What happened: Cybersecurity researchers have discovered a common security weakness in numerous Android applications, including Xiaomi Inc.'s File Manager and WPS Office, making them vulnerable to remote code execution attacks, token theft, and other issues. The vulnerability stemmed from Android's "content provider" feature that is used for file sharing among applications.

Why it matters: This security flaw puts millions of Android users at risk of exploitation and data compromise, as it allows malicious actors to execute remote-code attacks and steal sensitive information. While some affected vendors have patched their apps, there's concern that many other applications may still be vulnerable, highlighting the ongoing need for robust security measures in mobile app development.

Germany Says Russian Cyberattacks Targeted German Defence and Aerospace Sectors

Source: https://www.reuters.com/technology/cybersecurity/russian-cyber-attacks-targeted-defence-aerospace-sectors-berlin-says-2024-05-03/

What happened: APT 28, a Russian-state sponsored actor associated with the Russian military intelligence service GRU, targeted Germany's governing Social Democrats and itslogistics, defence, aerospace, and IT sectors, according to the German interior ministry.

Why it matters: Russian-state sponsored threat actors have been targeting critical infrastructure of governments in various countries. For instance, Winter Vivern group exploited cross-site scripting (XSS) flaws in chinRoundcube webmail servers across Europe in a campaign targeting government, military, and critical infrastructure in Georgia, Poland, and Ukraine. Additionally, as reported in ZeroFox’s Daily Cyber Intelligence Brief of March 18, APT 28 had reportedly been engaged in multiple ongoing phishing campaigns across Europe, Americas, Asia.

The Five Families Cyberthreat Group Claims to Breach UAE Government Servers

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/63552

What happened: The Five Families has claimed responsibility for breaching UAE government servers and accessing various sensitive information from several ministries and key government entities. Meanwhile, Stromous ransomware, a member of the collective, claimed to have targeted UAE’s Telecommunications and Digital Government Regulatory Authority and Federal Authority for Nuclear Regulation.

Why it matters: Even though the motives behind these attacks remain unclear, the alleged data breach has the potential to be the country’s largest if proven true. Moreover, Stromous ransomware is known for its “scavenger operations,” where it targets companies that have been subjected to a data breach.

DEEP AND DARK WEB INTELLIGENCE

Threat actor Red123: Threat actor Red123 announced the sale of a web exploit XSS injection vulnerability, priced at USD 900 on the predominantly Russian-language dark web forum “xss."

VULNERABILITIES

CVE-2024-4406: Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Tags: DIB, tlp:green