zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 20, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • China-Based APT41 Targets Entities in Italy, Spain, Taiwan, Thailand, Turkey, and the UK
  • Revolver Rabbit Gang Registers 500,000 Domains for Malware Campaigns
  • SolarWinds Fixes 8 Critical Bugs in Access Rights Audit Software

China-Based APT41 Targets Entities in Italy, Spain, Taiwan, Thailand, Turkey, and the UK

Source: https://thehackernews.com/2024/07/apt41-infiltrates-networks-in-italy.html

What happened: China-linked APT41 conducted a persistent campaign targeting several organizations associated with global shipping and logistics, media and entertainment, technology, and automotive sectors in Italy, Spain, Taiwan, Thailand, Turkey, and the United Kingdom. The group reportedly infiltrated and maintained prolonged, unauthorized access to numerous victims' networks.

Why it matters: The group's prolonged infiltration into diverse sectors across multiple countries enables extensive data exfiltration, posing risks to intellectual property, sensitive information, and national security. The adversary has been exploiting tools like web shells and SQLULDR2 and using sophisticated, non-public malware for espionage-like activities, indicating an evolving threat landscape where state and non-state actors blur lines. The tactics also include using stolen code-signing certificates, custom droppers, and exploiting cloud services for data exfiltration, complicating tracking and mitigation efforts. The campaign's impacts can extend to significant data breaches and potential economic and strategic consequences on targeted sectors.

Revolver Rabbit Gang Registers 500,000 Domains for Malware Campaigns

Source: https://bleepingcomputer.com/news/security/revolver-rabbit-gang-registers-500-000-domains-for-malware-campaigns/

What happened: Researchers have observed that the cybercriminal group tracked as Revolver Rabbit has spent over USD 1 million on registering more than 500,000 domain names using registered domain generation algorithms (RDGAs). These domains are used in infostealer campaigns targeting multiple operating systems.

Why it matters: The sheer financial investment and operational scale of Revolver Rabbit underscore the sophistication and persistence of modern cybercriminal operations. The domains are utilized as command and control (C2) servers for the distribution of XLoader, an advanced info-stealing malware. XLoader, an evolution of Formbook, is designed to target various operating systems and is capable of stealing sensitive data and executing malicious files. The use of RDGAs allows Revolver Rabbit to rapidly create a vast number of domains, complicating efforts by cybersecurity researchers to preemptively block or monitor malicious activities. Unlike domain generation algorithms (DGAs) embedded in malware, which can be reverse-engineered once discovered, RDGAs remain hidden and under the control of the threat actor. This secrecy makes identifying and neutralizing potential attack vectors more challenging for defenders, potentially prolonging the effectiveness and impact of the infostealer campaigns.

SolarWinds Fixes 8 Critical Bugs in Access Rights Audit Software

Source: https://www.solarwinds.com/trust-center/security-advisories

What happened: SolarWinds recently fixed eight vulnerabilities in the Access Rights Manager (ARM) software, which allowed threat actors to conduct remote code execution (RCE). The vulnerabilities, specifically six critical-severity bugs, could potentially allow attackers to execute code or commands “with or without SYSTEM privileges depending on the exploited flaw.”

Why it matters: SolarWinds’ ARM software helps admins manage and audit access rights in IT infrastructure. The six RCE vulnerabilities observed and now patched in the ARM software are CVE-2024-23469, CVE-2024-23466, CVE-2024-23467, CVE-2024-28074, CVE-2024-23471, and CVE-2024-23470. The company also patched two critical directory traversal flaws (CVE-2024-23475 and CVE-2024-23472). The flaws, if unpatched by the user, could allow attackers to delete arbitrary files and breach sensitive information by accessing files or folders outside of restricted directories. Additionally, the company fixed a high-severity authentication bypass vulnerability (CVE-2024-23465) that could enable unauthenticated malicious actors to gain domain admin access within the Active Directory environment.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Team “UCC Operations”: Threat actor group Team UCC Operations announced that they will join forces with Network Nine and launch operation, "Pawn_Algeria" to carry out cyberattacks against the Algerian government.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-4807: A denial-of-service vulnerability exists in the OpenSSL library used in MELSOFT MaiLab due to improper verification of cryptographic signature resulting from improper implementation of the POLY1305 message authentication code (MAC). CISA has released an Industrial Control Systems (ICS) Advisory highlighting this bug.

Affected products: MELSOFT MaiLab SW1DND-MAILAB-M versions 1.00A to 1.05F and MELSOFT MaiLab SW1DND-MAILABPR-M versions 1.00A to 1.05F

Tags: DIB, tlp:green