ZeroFox Cyber Intelligence Daily Brief - July 29, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 29, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- French Authorities Launch Operation to Remove PlugX Malware from Infected Systems
- PKFail Secure Boot Bypass Issue Compromises Millions of Devices
- China-Backed Phishing Attack Targets India Postal System Users
French Authorities Launch Operation to Remove PlugX Malware from Infected Systems
Source: https://thehackernews.com/2024/07/french-authorities-launch-operation-to.html
What happened: French authorities have announced a disinfection operation to take down a malware strain called PlugX. PlugX is a remote access trojan (RAT) reportedly also used by nation-state actors, like China-linked threat actors, along with other malware strains like Gh0st RAT and ShadowPad.
Why it matters: In the past, cybersecurity researchers have attempted to sinkhole a command and control (c2) server of one of PlugX malware’s variants. The backdoor, PlugX, has evolved over the years and has been observed to be a part of several campaigns including many reportedly connected to the Chinese Ministry of State Security. This disinfection operation led by the French authorities in collaboration with Europol is significant to taking down this malware variant that has affected millions of victims globally. A hundred victims in the time of writing have reportedly have benefited from the efforts.
PKFail Secure Boot Bypass Issue Compromises Millions of Devices
What happened: A critical security vulnerability named “PKFail” in the Secure Boot process had made millions of Intel and ARM microprocessor-based computing systems vulnerable. Attackers can potentially bypass the Secure Boot process because of misused test Platform Keys (PK) in production devices.
Why it matters: The exposure of private keys will likely make the systems vulnerable to low-level malware attacks that would go undetected by OS-level antimalware protections. An attacker could leverage the vulnerability to trick the Windows UEFI framework into accepting a malicious OS installation as genuine and replace the existing OS with one filled with malware. However, the attacker would first need full system access, meaning they would already have control of the machine. This vulnerability primarily facilitates persistent attacks, enabling long-term access even after thorough anti-malware efforts and a re-install. Users have been advised to update their firmware and follow security best practices to prevent the initial breach needed for such an attack.
China-Backed Phishing Attack Targets India Postal System Users
What happened: A China-based hacking group known as Smishing Triad targeted iPhone users in India with phishing attacks through text messages. The messages falsely claimed that a package was waiting at an India Post warehouse, containing URLs leading to fraudulent websites. Over 470 domains mimicking the India Post's official domain were registered, primarily through Chinese and American registrars. Phishing emails were also sent via iMessage using third-party email services.
Why it matters: By mimicking official communication and using convincing lures, the attackers increase the likelihood of their targets falling victim to the scam. If successful, threat actors could steal sensitive personal information from victims, such as login credentials and financial details, potentially leading to identity theft, financial loss, or unauthorized access to other accounts. The involvement of both Chinese and American domain registrars in registering deceptive domains complicates the tracking and mitigation of the threat. Additionally, the use of iMessage and third-party email services broadens the attack vector, making mobile devices a highly attractive target for such campaigns. During the 2023 holiday season, researchers detected a surge in DNS queries to "combosquatting" domains mimicking USPS services. By impersonating postal services like India Post and USPS, attackers leverage the inherent trust people place in these organizations to create a sense of legitimacy. This tactic increases the likelihood that individuals will interact with malicious content or provide sensitive information, thereby enhancing the effectiveness of the phishing attacks.
DEEP AND DARK WEB INTELLIGENCE
Threat actor group “RipperSec”: Threat actor group RipperSec claimed to have leaked a database associated with the Sri Mahesh Prasad Degree College, India.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-6327: The vulnerability (CVE-2024-6327), with a CVSS score of 9.9, is a critical insecure deserialization flaw impacting Telerik® Report Server versions released before the second quarter of 2024 (10.1.24.709).
Affected products: Report Server 2024 Q2 (10.1.24.514), and earlier
Tags: DIB, tlp:green