zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 5, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Europol Nukes Close to 600 IP Addresses in Cobalt Strike Crackdown
  • Ethereum Mailing List Breach Exposes 35,000 to Crypto Draining Attack
  • Threat Actor Claims to Leaks Database from Canadian E-Commerce Platform Shopify

Europol Nukes Close to 600 IP Addresses in Cobalt Strike Crackdown

Source: https://www.theregister.com/2024/07/04/europol_cobalt_strike_crackdown/

What happened: Europol announced that it has taken down nearly 600 illegal copies of Cobalt Strike. Cobalt Strike is a legitimate software that threat actors have been abusing to infiltrate victims’ systems. The software helps users detect weaknesses in their systems but cracked versions have the ability to allow bad actors to install backdoors and deploy malware..

Why it matters: Cybercriminals have in the past conducted cyberattacks at a global scale by combining sophisticated tools— like Cobalt Strike and custom malware— with ransomware to extort ransom, sabotage, distract, misattribute, and eliminate evidence reflects the evolving techniques and skills of state-sponsored cyber espionage groups. Misusing this software has given hacktivists the ability for reconnaissance and post-exploitation activities such as dropping additional tooling.

Ethereum Mailing List Breach Exposes 35,000 to Crypto Draining Attack

Source: https://www.bleepingcomputer.com/news/security/ethereum-mailing-list-breach-exposes-35-000-to-crypto-draining-attack/

What happened: Ethereum, a blockchain platform, has recently disclosed in a blog post that a threat actor exploited Ethereum's mailing list provider to send phishing emails to over 35,000 addresses. The email, appearing to be from “updates@blog[.]ethereum[.]org,” directed recipients to a malicious website hosting a crypto drainer.

Why it matters: The phishing lure falsely announced a partnership with Lido DAO and offered a high annual percentage yield (APY) on staked Ethereum, aiming to deceive recipients into divulging sensitive information or performing malicious actions. Users who clicked on the phishing link could have unknowingly exposed sensitive information, potentially leading to financial losses, identity theft, unauthorized access to cryptocurrency wallets, or further phishing campaigns. Despite the attack's scale, Ethereum reassured users of minimal impact and swiftly launched an internal investigation. The patform blocked the attacker's email access, issued warnings on X (Twitter) about the phishing attempt, and added the malicious link to blocklists used by major Web3 wallet providers and Cloudflare, ensuring broad protection against the phishing campaign.

Threat Actor Claims to Leaks Database from Canadian E-Commerce Platform Shopify

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66781

What happened: ZeroFox intelligence has observed threat actor "888" claiming to leak a database allegedly from the Canadian e-commerce platform Shopify on the predominantly English-language dark web forum BreachForums. Threat actor 888 has claimed that the leaked database contains 179,873 users' information, including first name, last name, email address, subscription date, Shopify ID, and more.

Why it matters: With a user base that is millions strong, Shopify is a go-to option for many small digital e-commerce businesses who wish to cater to a global audience. Any cyberattack on the platform can spell financial losses not just for the platform but also for its consumers. If threat actor 888’s leaked database is at all Shopify’s, the affected victims will likely face threats, like identity theft, financial fraud, and privacy breaches like spam and phishing attacks. Merchants might be targeted in extortion scams or even blackmail over confidential information. Shopify itself could face legal penalties, lawsuits, and loss of business, damaging its market trust and increasing security costs.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums User “xenZen”: Threat actor xenZen claimed to have leaked a database associated with Airtel, an India-based communications company on the predominantly English-language dark web forum, “BreachForums." Allegedly, a leaked database contains over 375 million customer details that includes phone number, email addresses, name, date of birth, Aadhaar ID, and more. The threat actor charged USD 50,000 for the data and requested interested parties to contact them via Tox or session. The threat actor did not disclose the ultimate source of the data breach or how it was exploited.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2023-2071: Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There is a routine that restricts it to execute specific functions from two dynamic link library files. By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

  • Affected products: FactoryTalk View Machine Edition versions 13.0, 12.0, and prior.

  • CVE-2023-29464: FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

  • Affected products: FactoryTalk Linx versions 6.30, 6.20, and prior.

Tags: DIB, tlp:green