zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 1, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 1, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Kimsuky Using TRANSLATEXT Browser Extension to Steal Sensitive Data
  • Infosys McCamish Says LockBit Stole Data of Six Million People
  • New SnailLoad Attack Exploits Network Latency to Reveal User Web Activity Remotely

Kimsuky Using TRANSLATEXT Browser Extension to Steal Sensitive Data

Source: https://www.newsweek.com/north-korean-hackers-using-google-steal-passwords-1918745

What happened: A North Korea-linked group named Kimsuky has deployed a malicious web browser extension called TRANSLATEXT to target South Korean academia studying North Korean politics. The extension, disguised as a legit translation tool, steals sensitive information such as emails, passwords, and browser screenshots by bypassing security measures.

Why it matters: The stolen data, including credentials and sensitive information, could potentially be used for espionage, identity theft, phishing attacks, or further cyber operations. Moreover, the use of sophisticated techniques like masquerading as legitimate software highlights the evolving tactics of threat actors to deceive and exploit users. TRANSLATEXT has other capabilities such as capturing browser screenshots that can provide insights into user activities and potentially confidential information. It can also delete browser cookies that could disrupt user sessions, enabling attackers to perform unauthorized actions or maintain persistent access. Its ability to fetch commands from a remote server allows for dynamic control over infected machines, facilitating additional espionage or malware deployment.

Infosys McCamish Says LockBit Stole Data of Six Million People

Source: https://www.bleepingcomputer.com/news/security/infosys-mccamish-says-lockbit-stole-data-of-6-million-people/

What happened: Infosys McCamish Systems (IMS) confirms that the breach in November 2023, that LockBit had claimed, has actually affected more than six million people. According to the official notification, the impacted data included email address and password, Driver’s License number or state ID number, financial account information, and more.

Why it matters: The November breach impacted many of IMS’s clients, which include prominent financial institutions. A ransomware attack on financial businesses such as banks, insurance companies, or accounting firms can paralyze critical systems and compromise sensitive data. This exposed personal data creates opportunities for identity theft and fraud, potentially causing financial harm to affected individuals. Moreover, the stolen data can be used for future cyberattacks, including phishing scams and targeted malware distribution, exploiting the compromised information to gain unauthorized access to accounts or conduct further breaches.

New SnailLoad Attack Exploits Network Latency to Reveal User Web Activity Remotely

Source: https://thehackernews.com/2024/06/new-snailload-attack-exploits-network.html

What happened: Cybersecurity researchers have demonstrated a new side-channel attack called SnailLoad. Threat actors leveraging this attack can remotely infer a user’s web activity by exploiting latency bottlenecks without an adversary-in-the-middle position or physical proximity to the target.

Why it matters: SnailLoad is a novel method for adversaries to deduce a user’s online behavior, such as the websites they visit or videos they watch, by merely analyzing network latency. Threat actors trick users into loading harmless assets from a malicious server and measure the latency variations to infer network activity without user interaction or code execution, thereby bypassing security measures. Additionally, the security flaws in router firmware handling NAT (Network Address Translation) mapping call for rigorous inspection of network packets to prevent TCP (Transmission Control Protocol) connection manipulation, which can let attackers conduct denial-of-service.

DEEP AND DARK WEB INTELLIGENCE

Pro-Palestine Threat Actor Moroccan Black Cyber Army Group | Pro-Palestine threat actor Moroccan Black Cyber Army group announced that one of its team members had been arrested by French intelligence and police. The group confirmed that it will return soon, stating that they would not be idle during this arrest. The group stated that it will continue its attacks against Israel and the French government upon their return.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-0769: A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig[.]cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1[.]xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected products: D-Link DIR-859 1.06B01

Tags: DIB, tlp:green