zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Spyware Covertly Gathers Data from Android Users in Russia
  • Chinese Hackers Deliver Malware via ISP-Level DNS Poisoning
  • North Korean Hackers Exploit VPN Update Flaw to Install Malware

Spyware Covertly Gathers Data from Android Users in Russia

Source: https://www.darkreading.com/mobile-security/sophisticated-android-spyware-targets-users-in-russia

What happened: Cybersecurity researchers have discovered a three-year-long covert data-gathering operation conducted by an unknown (potentially state-sponsored) actor, who has been injecting Android systems in Russia with LianSpy spyware trojan.

Why it matters: LianSpy joins the ranks of notorious spyware plaguing the cyber world, including NSO Group-developed Pegasus Software. Observations indicate that LianSpy’s primary function is to conduct cyber espionage by intercepting calls, recording screens during outgoing and incoming communication, and recording the number of apps installed on the device. The post-exploitation trojan leverages root privileges to bypass security, for incognito screen-recording, and not for complete control over the device. It is currently unclear if the exfiltrated data could be potentially sold to other actors or used in financially and politically motivated attacks.

Chinese Hackers Deliver Malware via ISP-Level DNS Poisoning

Source: https://www.securityweek.com/chinese-hackers-deliver-malware-via-isp-level-dns-poisoning/

What happened: A threat actor linked to China has been observed using ISP-level DNS poisoning to deliver malware to targets. This operation, conducted by an APT group tracked as StormBamboo, Evasive Panda, and StormCloud, involved compromising an internet provider’s systems to perform DNS poisoning. This allowed the attackers to deliver specific malware through insecure automatic software update mechanisms.

Why it matters: Insecure update mechanisms in this case allowed threat actors to abuse software that did not properly validate digital signatures of installers. This has resulted in applications that tried to retrieve updates ending up installing malware instead, due to DNS poisoning. DNS poisoning has greater consequences that allow threat actors to steal data, block updates, and conduct malware and phishing attacks.

North Korean Hackers Exploit VPN Update Flaw to Install Malware

Source: https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-vpn-update-flaw-to-install-malware/

What happened: South Korea's National Cyber Security Center (NCSC) has reported that state-backed North Korean hackers exploited vulnerabilities in a VPN's software update to deploy malware and breach networks in South Korea, with Kimsuky (APT43) and Andariel (APT45) identified as the threat groups involved.

Why it matters: By exploiting vulnerabilities in a VPN's software update, North Korean hackers can deploy malware to gain unauthorized access to South Korean networks, steal sensitive data, and monitor communications. This can lead to theft of intellectual property, disruption of critical operations, and long-term espionage by planting persistent malware for ongoing surveillance and data exfiltration. This ultimately might fuel North Korea’s industrial modernization efforts by leveraging the stolen data to advance their own technological and industrial capabilities. The targeted theft of trade secrets from South Korean networks underscores the serious risk posed by these state-sponsored hackers. The simultaneous targeting of the same sector by threat actors like Kimsuky and Andariel is unprecedented and highlights a coordinated effort to achieve specific objectives. NCSC advises websites at risk of state-sponsored attacks to get security inspections from Korea's Internet & Security Agency (KISA), enforce strict software distribution policies with administrator authentication, and stay updated with software, employee training, and government advisories, to counteract such sophisticated attacks and protect sensitive information.

DEEP AND DARK WEB INTELLIGENCE

  • Actors Claim Cyberattacks Against Argentina: On August 4 and 5, pro-Palestine threat actor group LulzSec Muslims claimed to hack the Ministry of Health of the Argentine Republic and a major news channel. On August 1 and 3, threat actor dk0m claimed to be selling data/access associated with “Argentinian Government Official Web Mail.”

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-36971: Google has patched this use-after-free (UAF) bug in the Linux kernel's network route management. Threat actors are likely exploiting it to conduct arbitrary code execution without user interaction on unpatched devices.

  • Affected product: Linux Kernel

  • CVE-2024-38856: With a CVSS score of 9.8, this bug in the Apache OFBiz system can let attackers access critical endpoints via specially crafted requests. This can lead to data exfiltration.

  • Affected products: FactoryTalk Linx versions 6.30, 6.20, and prior.

Tags: DIB, tlp:green