zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 25, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 25, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hamster Kombat Players Threatened by Spyware & Infostealers
  • Stargazers Ghost Network: Sophisticated Malware Scheme Discovered on GitHub
  • Ransomware Attack on Australian eScripts Provider Affects 12.9 Million Australians

Hamster Kombat Players Threatened by Spyware & Infostealers

Source: https://www.darkreading.com/cyber-risk/hamster-kombat-players-threatened-by-spyware-infostealers

What happened: Cybercriminals are exploiting the popularity of the mobile currency game Hamster Kombat by distributing fake Android software. They lure users with promises of cryptocurrency rewards, but instead, their software installs spyware and other malware. Through fake Telegram channels and websites mimicking legitimate game platforms, cybercriminals deceive users into downloading Ratel Android spyware under the guise of game-related utilities.

Why it matters: With Hamster Kombat’s rapid user growth surpassing 250 million, the game becomes a lucrative target for cybercriminals seeking to capitalize on the promise of cryptocurrency rewards. The tactics employed, such as fake Telegram channels and deceptive websites distributing malware like Ratel Android spyware and trojans, highlight a sophisticated approach to compromising user devices. Beyond financial exploitation through unauthorized subscriptions and advertisement fraud, the malware poses serious threats to user privacy by potentially exfiltrating sensitive personal information. These malicious tactics prey on users' trust and enthusiasm for the game, potentially compromising their privacy and security. As Hamster Kombat gains more users, the risk of falling victim to such scams increases, highlighting the urgent need for users to exercise caution when downloading software or interacting with game-related channels and websites.

Stargazers Ghost Network: Sophisticated Malware Scheme Discovered on GitHub

Source: https://cybersecuritynews.com/stargazers-ghost-github/

What happened: Researchers have discovered the Stargazers Ghost Network, a sophisticated network of over 3,000 GitHub accounts distributing malware and phishing links since June 2023. Threat actor Stargazer Goblin deploys "ghost" accounts to enhance the perceived legitimacy of malicious repositories, distributing malware like Atlantida Stealer.

Why it matters: The Stargazers Ghost Network represents a significant advancement in malware distribution tactics. The network distributes various types of malware designed to steal user credentials, cryptocurrency wallets, and other personal information. It can also create and maintain seemingly trustworthy repositories. An additional sophistication the network possesses is its ability to quickly recover from account bans and update malicious links, maintaining continuous operation and efficiency in spreading malware without detection. Moreover, by leveraging GitHub, a major code-hosting platform, threat actors have found a way to distribute malware that appears legitimate, bypassing traditional monitoring methods.

Ransomware Attack on Australian eScripts Provider Affects 12.9 Million Australians

Source: https://www.hipaajournal.com/medisecure-ransomware-attack/

What happened: A recent ransomware attack on MediSecure, an Australian electronic prescription service provider, has resulted in the theft of 6.5 TB of sensitive data, impacting up to 12.9 million Australians, about half the population. Efforts to reconstruct the affected server from a backup were successful, but the identification process is ongoing due to the sheer volume of data.

Why it matters: Researchers have observed that a sample of the stolen data was posted on the dark web by the threat actor behind the attack. Initially priced at USD 50,000, the data was marked as sold and has since been relisted by the buyer at a discounted price of USD 25,000. This indicates that the stolen information is actively being traded and potentially misused. The Australian National Cyber Security Coordinator has issued a warning to all affected individuals about the increased risk of scams and misuse of their data.

DEEP AND DARK WEB INTELLIGENCE

  • Exploit user "amigojuan": Untested and recently registered threat actor "amigojuan" announced that they are selling 140,000 U.S. credit cards of which 35 percent are likely still valid and only 3 percent have full details (the rest only have a number, expiry date, and a CVV).

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-41110: This is a critical issue with a CVSS score of 10.0. It enables an attacker to exploit the Docker daemon by sending a specially crafted API request with a Content-Length of 0, causing it to forward the request to the AuthZ plugin.

  • Affected products: Docker-ce versions v19.03.15 and lower, v20.10.27 and lower, v23.0.14 and lower, v24.0.9 and lower, v25.0.5 and lower, v26.0.2 and lower, v26.1.4 and lower, v27.0.3 and lower, and v27.1.0 and lower

Tags: DIB, tlp:green