zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hamster Kombat Players Threatened by Spyware & Infostealers
  • U.S. Government IT Services Provider Suffers Data Breach
  • EvilVideo, A Telegram Android Zero-Day, Allowed Sending Malicious APKs Disguised as Videos

Hamster Kombat Players Threatened by Spyware & Infostealers

Source: https://www.darkreading.com/cyber-risk/hamster-kombat-players-threatened-by-spyware-infostealers

What happened: Cybercriminals are exploiting the popularity of the mobile currency game Hamster Kombat by distributing fake Android software. They lure users with promises of cryptocurrency rewards, but instead, their software installs spyware and other malware. Through fake Telegram channels and websites mimicking legitimate game platforms, cybercriminals deceive users into downloading Ratel Android spyware under the guise of game-related utilities.

Why it matters: With Hamster Kombat’s rapid user growth surpassing 250 million, the game becomes a lucrative target for cybercriminals seeking to capitalize on the promise of cryptocurrency rewards. The tactics employed, such as fake Telegram channels and deceptive websites distributing malware like Ratel Android spyware and trojans, highlight a sophisticated approach to compromising user devices. Beyond financial exploitation through unauthorized subscriptions and advertisement fraud, the malware poses serious threats to user privacy by potentially exfiltrating sensitive personal information. These malicious tactics prey on users' trust and enthusiasm for the game, potentially compromising their privacy and security. As Hamster Kombat gains more users, the risk of falling victim to such scams increases, highlighting the urgent need for users to exercise caution when downloading software or interacting with game-related channels and websites.

U.S. Government IT Services Provider Suffers Data Breach

Source: https://www.bloomberg.com/news/articles/2024-07-23/hackers-leak-documents-from-pentagon-it-services-provider-leidos

What happened: Leidos Holdings Inc., one of the largest IT services providers of at least three U.S. government entities, has suffered a breach in which actors stole some internal documents.

Why it matters: A Leidos spokesperson has reportedly confirmed that the leaked data was from “a previous incident affecting a third-party vendor” and did not impact Leidos’ network or any sensitive customer data. However, Leidos has seen a dip of almost four percent in its shares since, signaling an erosion of shareholder trust and some reputational damage. Moreover, the leaked documents will likely tempt malicious threat actors and state-sponsored actors to abuse the data in attacks with far-reaching impacts, potentially affecting national security and sensitive operations. Besides, such attacks also lay a blueprint for adversaries to infiltrate critical infrastructure or government networks via third-party vendors for cyberespionage, persistent campaigns, and data exfiltration.

EvilVideo, A Telegram Android Zero-Day, Allowed Sending Malicious APKs Disguised as Videos

Source: https://securityaffairs.com/166042/hacking/evilvideo-telegram-android-zero-day.html

What happened: A zero-day vulnerability dubbed “EvilVideo” was discovered in Telegram for Android versions 10.14.4 and older. This vulnerability allowed attackers to send malicious Android APK payloads disguised as video files through Telegram. The exploit took advantage of Telegram's automatic media download feature, making users vulnerable to installing malicious apps when attempting to view the disguised video. On June 6, threat actor “Ancryno” initiated the sale of the Telegram zero-day exploit on the Russian-speaking XSS hacking forum.

Why it matters: The “EvilVideo” exploit in Telegram highlights significant security concerns for users of the messaging platform, particularly those using older versions of the app. The sale of the Telegram zero-day exploit by threat actor "Ancryno" poses a significant risk to those using affected versions of the app. Individuals who have not updated to the patched versions of Telegram could be targeted by malicious actors exploiting the “EvilVideo” vulnerability to deceive them into installing harmful applications disguised as innocuous video files. This incident highlights the importance of timely software updates and patching vulnerabilities in software applications. It also emphasizes the critical need for users to exercise caution when interacting with multimedia files and to update their apps promptly to protect against such exploits.

Tags: DIB, tlp:green