zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Computer Maker Zotac Exposed Customers' RMA Info on Search Engines
  • New APT Targeting Russian Entities
  • CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40

Computer Maker Zotac Exposed Customers' RMA Info on Search Engines

Source: https://www.bleepingcomputer.com/news/security/computer-maker-zotac-exposed-customers-rma-info-on-google-search/

What happened: Zotac, known for its lineup of compact and mini PCs, has inadvertently made sensitive customer information publicly accessible by exposing return merchandise authorization (RMA) requests and related documents online for an unknown period.

Why it matters: The exposure of RMA requests and documents occurred due to a misconfiguration in their web folders, which allowed these documents to be indexed by search engines. As a result, anyone using specific search queries could access personal details such as invoices, addresses, request specifics, and contact information of Zotac customers. By failing to adequately restrict access to RMA-related documents, Zotac exposed its customers to potential risks of identity theft, fraud, and unauthorized use of personal information. The exposure of invoices and addresses can lead to targeted phishing attempts and other malicious activities that exploit sensitive data.

New APT Targeting Russian Entities

Source: https://thehackernews.com/2024/07/new-apt-group-cloudsorcerer-targets.html

What happened: Cybersecurity researchers have discovered a previously undocumented APT group, dubbed CloudSorcerer, targeting Russian government entities via cloud services to establish a command-and-control (C2) center and exfiltrate data.

Why it matters: An analysis of the APT’s malware source code revealed several innovative tactics to evade detection. The adversary is likely using the malware for cyberespionage to stealthily monitor the activities of the target systems, collect sensitive data, and transfer the collected data to a different server. Additionally, the malware can adapt its behavior based on the process it is involved in and facilitate inter-process communication. The sophisticated features of the malware are likely to let CloudSorcerer maintain its presence in an infiltrated system for a significant amount of time, making vigilance of its activities necessary. The observed attacks on government agencies and the nature of CloudSorcerer’s cyberarsenal suggest that the APT will likely target more government bodies in the near future. However, whether the APT is sponsored by any state has not yet been determined. Hence, it is difficult to assert any political motives behind its targets.

CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40

Source: https://www.cisa.gov/news-events/alerts/2024/07/08/cisa-and-partners-join-asds-acsc-release-advisory-prc-state-sponsored-group-apt-40

What happened: CISA and other global security agencies have released an advisory titled “People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action.” The advisory provides information about PRC state-sponsored cyber group APT40 (Kryptonite Panda, GINGHAM TYPHOON, Leviathan and Bronze Mohawk). CISA urges all organizations and software manufacturers to review the advisory to help identify, prevent, and remediate APT 40 intrusions.

Why it matters: According to the advisory, this group appears to prefer exploiting vulnerable, public-facing infrastructure over techniques that require user interaction such as phishing campaigns, and places a high priority on obtaining valid credentials to enable a range of follow-on activities. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted in the advisory are regularly used by other PRC state-sponsored actors globally. The collaborating parties believe the group pose a threat to their countries’ networks as well.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user dwShark: The threat actor dwShark has claimed to sell data from Fiscalía General del Estado de Veracruz in Mexico on the predominantly English-language dark web forum BreachForums. The leaked package contains information including name, phone number, and email.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-29510: It is a format string injection in the uniprint device in Ghostscript document conversion toolkit that can allow actors to conduct remote code execution (RCE). The toolkit is widely used in Linux systems and other services offering document conversions. A patch is available in Ghostscript version v10.03.1.

Affected products: Versions of Ghostscript 10.03.0 and lower.

Tags: DIB, tlp:green