zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 30, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 30, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Israeli Olympic Athletes' Data Leaked
  • Massive Spoofing Campaign Exploits Email Routing Flaw to Send Millions of Phishing Emails
  • USDoD Releases CrowdStrike Data in Retaliation to “Direct Attack”

Israeli Olympic Athletes' Data Leaked

Source: https://www.darkreading.com/threat-intelligence/zeus-hacker-group-strikes-israeli-olympic-athletes-data-leak

What happened: Threat actor “Zeus” is reportedly behind an alleged doxxing attack that exposed some sensitive data belonging to Israeli athletes participating in the Paris Olympics on Telegram. The data, allegedly including military statuses, blood test results, and login credentials, has prompted France's Anti-Cybercrime Office (OFAC) to intervene.

Why it matters: The Olympics is a lucrative target for financially motivated actors and politically guided adversaries. Several threat actors are targeting Israeli athletes, due to the geopolitical and military tensions involving Israel. The exposed personal and military information will likely invite other malicious actors to target the affected athletes in intimidation and fear-mongering or disrupt the athletes' participation in the Olympics. The leaked data, such as blood test results and login credentials, could be used for identity theft, blackmail, or further cyber-attacks. Additionally, disclosing military statuses could potentially endanger the athletes and their families. This attack not only impacts the individuals involved but also serves as a political statement, aiming to draw international attention to the ongoing conflicts involving Israel.

Massive Spoofing Campaign Exploits Email Routing Flaw to Send Millions of Phishing Emails

Source: https://thehackernews.com/2024/07/proofpoint-email-routing-flaw-exploited.html

What happened: An unknown threat actor exploited an email routing misconfiguration in Proofpoint's defenses to send millions of spoofed emails impersonating several popular companies, including Best Buy and Walt Disney. The campaign, named EchoSpoofing, started in January 2024 and peaked at 14 million emails daily in June.

Why it matters: The campaign uses SPF and DKIM signatures to make the emails appear legitimate and bypass major security protections, eventually deceiving the recipients. The combination of reputed names in the email domains and detection evasion techniques add to the sophistication of the campaign. Additionally, the large scale of the campaign, reaching up to 14 million emails per day, indicates the potentially vast reach of the activity. As a part of the mitigation process, Proofpoint has swiftly assembled a cross-functional team to identify and reach out to all customers with vulnerable configurations, prioritizing those actively exploited. It has also established a process to ensure new customers are configured to prevent relay abuse.

USDoD Releases CrowdStrike Data in Retaliation to “Direct Attack”

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67694

What happened: On July 29, the threat actor “USDoD” claimed to have leaked a list of 100,000 Indicator of Compromise (IOC) associated with CrowdStrike on the predominantly English-language dark web forum BreachForums. The leaked data includes IOCs, types, malware families, actors, kill chains, and other proprietary CrowdStrike intelligence.

Why it matters: The threat actor USDoD, on July 24, 2024, had warned of leaking CrowdStrike’s Indicator of Compromise (IoC) list after they had scrapped it earlier. An almost neutral CrowdStrike article about the threat actor supposedly instigated them to release data that was already available to possibly a larger audience. This disclosure might affect CrowdStrike’s business dealings with its clients and compromise the exclusiveness of the curated data. Making proprietary data public can also help threat actors better avoid detection. The threat actor also claimed access to CrowdStrike’s “report on threat intel” which they seem to be withholding, in the time of writing, as potential blackmail material.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user IntelBroker: On July 26, 2024, well-regarded and established threat actor IntelBroker claimed to be selling unauthorized NPM (Node Package Manager) and Github access to a well-known programming language on the predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management.

  • Affected products: VMware ESXi 8.0 (fixed in ESXi80U3-24022510), VMware ESXi 7.0 (no patch planned), VMware Cloud Foundation 5.x (fixed in 5.2), VMware Cloud Foundation 4.x (no patch planned)

  • CVE-2023-45249: This flaw, before being patched, was exploited in the wild as threat actors conducted remote command execution, which was possible due to the use of default passwords.

  • Affected products: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132

Tags: DIB, tlp:green