zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Two Hacktivist Group’s Members Sanctioned for Attacks Against U.S. Critical Infrastructure
  • EvilVideo, A Telegram Android Zero-Day, Allowed Sending Malicious APKs Disguised as Videos
  • NCA Infiltrates World's Most Prolific DDoS-for-Hire Service

Two Hacktivist Group’s Members Sanctioned for Attacks Against U.S. Critical Infrastructure

Source: https://www.bleepingcomputer.com/news/security/us-sanctions-russian-hacktivists-who-breached-water-facilities/

What happened: The U.S. Treasury sanctioned two individuals linked with the cyber group known as “Cyber Army of Russia Reborn” (CARR) for their participation in cyberattacks against U.S. critical infrastructure. The group is known for its attacks on critical infrastructure including water treatment and energy facilities.

Why it matters: The group has been observed conducting DDoS attacks targeting Ukraine and its supporters as well. In June, this group had announced its plans to continue to conduct DDoS campaigns as the Paris Olympics approached with the support of allies like Noname057(16), Hacknet, and People's CyberArmy. Pro-Russia hacktivist activity appears mostly limited to unsophisticated techniques that manipulate industrial control systems (ICS) equipment to create nuisance effects. However, investigations have identified that these actors are capable of techniques that pose physical threats against insecure and misconfigured OT environments. Earlier this year, the group took responsibility for causing water tanks in a Texas city to overflow leading to the wastage of thousands of gallons. Although these attacks have reportedly been of low impact, any compromise poses significant risks to operational safety, reliability, regulatory compliance, and civilian safety. Moreover, these systems often manage essential services, making them prime targets for malicious actors seeking to disrupt operations.

EvilVideo, A Telegram Android Zero-Day, Allowed Sending Malicious APKs Disguised as Videos

Source: https://securityaffairs.com/166042/hacking/evilvideo-telegram-android-zero-day.html

What happened: A zero-day vulnerability dubbed “EvilVideo” was discovered in Telegram for Android versions 10.14.4 and older. This vulnerability allowed attackers to send malicious Android APK payloads disguised as video files through Telegram. The exploit took advantage of Telegram's automatic media download feature, making users vulnerable to installing malicious apps when attempting to view the disguised video. On June 6, threat actor “Ancryno” initiated the sale of the Telegram zero-day exploit on the Russian-speaking XSS hacking forum.

Why it matters: The “EvilVideo” exploit in Telegram highlights significant security concerns for users of the messaging platform, particularly those using older versions of the app. The sale of the Telegram zero-day exploit by threat actor "Ancryno" poses a significant risk to those using affected versions of the app. Individuals who have not updated to the patched versions of Telegram could be targeted by malicious actors exploiting the “EvilVideo” vulnerability to deceive them into installing harmful applications disguised as innocuous video files. This incident highlights the importance of timely software updates and patching vulnerabilities in software applications. It also emphasizes the critical need for users to exercise caution when interacting with multimedia files and to update their apps promptly to protect against such exploits.

NCA Infiltrates World's Most Prolific DDoS-for-Hire Service

Source: https://www.nationalcrimeagency.gov.uk/news/nca-infiltrates-world-s-most-prolific-ddos-for-hire-service

What happened: The UK National Crime Agency (NCA) along with other law enforcement (LE) agencies infiltrated and disabled digitalstress[.]su, a major DDoS-for-hire service responsible for numerous global attacks.

Why it matters: DDoS attacks are favored by hacktivists for their ability to disrupt and draw attention to social or political causes. DDoS-for-hire services operate by allowing users to purchase attacks, typically using online platforms or forums. These attacks flood a target's server with overwhelming traffic, rendering it inaccessible to legitimate users. The use of obscure domains like [.]su may attempt to evade law enforcement scrutiny, complicating efforts to track and mitigate such criminal activities. This operation led by the NCA and other LE agencies is crucial because DDoS-for-hire services pose significant threats to businesses and critical infrastructure worldwide. By dismantling digitalstress[.]su, law enforcement agencies demonstrate the ability to penetrate sophisticated criminal networks, challenging the perceived anonymity of domains like [.]su. This takedown could hinder hacktivists' ability to launch large-scale DDoS attacks, potentially prompting them to seek alternative, less impactful methods to advocate for their causes.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user “888”: The threat actor 888 claimed to have leaked a database associated with L'Oréal, a France-based personal care product manufacturer, on the predominantly English-language dark web forum BreachForums. The threat actor claimed that L'Oréal's information was exposed after a third-party data breach in July 2024. The leaked data includes first name, last name, job title, email, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-6806: The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution.

Affected products: NI VeriStand 2024 Q2 and prior versions

Tags: DIB, tlp:green