zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • New Cyber Espionage Group Targets Azerbaijani and Israeli Diplomats
  • Iran's Charming Kitten Targets U.S. Presidential Elections, Israeli Military
  • Ransomware Gang Deploys New Malware to Kill Security Software

New Cyber Espionage Group Targets Azerbaijani and Israeli Diplomats

Source: https://thehackernews.com/2024/08/new-cyber-threat-targets-azerbaijan-and.html

What happened: Researchers have linked a previously unknown threat actor, Actor240524, to a sophisticated spear-phishing attack targeting Azerbaijani and Israeli diplomats. The campaign used malicious Word documents to deploy malware chains, including ABCloader and ABCsync, to steal sensitive data and execute remote commands while employing advanced evasion techniques.

Why it matters: The attack very likely has certain geopolitical implications, as it targets diplomats from two allied nations with strong economic and political ties. While the political allegiance of the threat actor is yet to be determined, the targets of the attack indicate possible political or strategic motives, possibly associated with espionage. The sophisticated techniques used, including anti-sandbox measures and persistent malware, suggest a high level of expertise and intent. The ability to remotely execute commands on compromised systems could let the attackers manipulate diplomatic communications or gain further access to classified data.

Iran's Charming Kitten Targets U.S. Presidential Elections, Israeli Military

Source: https://www.darkreading.com/cyberattacks-data-breaches/google-iran-charming-kitten-targets-presidential-elections-israeli-military

What happened: Threat intelligence researchers have detected and blocked multiple phishing attempts by the Iran-backed group APT42 (aka Charming Kitten), targeting personal email accounts of people linked to President Biden and former President Trump. The researchers also reported a surge in phishing attacks on Israeli military and political figures, including those in the defense sector, diplomats, academics, and NGOs, since April this year.

Why it matters: Security personnel have blocked multiple login attempts by the Iran-backed group APT42 (aka Charming Kitten) targeting the personal email accounts of individuals affiliated with President Biden and former President Trump, including current and former U.S. government officials and campaign staffers. The discovery of the Telegram bot service "IntelFetch," which aggregates compromised credentials from the DNC and Democratic Party websites, poses a significant threat to the upcoming U.S. elections. This breach could result in unauthorized access to sensitive political information, heighten the risk of mis/disinformation and election manipulation, and undermine public trust in the electoral process by exposing vulnerabilities for adversaries to exploit. Additionally, the group Charming Kitten used Google Sites for phishing campaigns against Israeli military and political figures. By masquerading as credible sources and using sophisticated tactics, the group Charming Kitten jeopardizes the security of sensitive individuals and institutions. Several now-removed Google Sites pages created by Charming Kitten were disguised as petitions from the Jewish Agency for Israel urging mediation to end the conflict. The attacks, likely motivated by U.S. support for Israel's actions in Gaza, are expected to continue as regional tensions rise.

Ransomware Gang Deploys New Malware to Kill Security Software

Source: https://www.bleepingcomputer.com/news/security/ransomware-gang-deploys-new-malware-to-kill-security-software/

What happened: The RansomHub ransomware gang has been observed in various campaigns involving new malware dubbed EDRKillShifter that disables endpoint detection and response (EDR) security software. Investigations suggest that the malware’s language property can be traced back to Russian origins.

Why it matters: The malware is said to deploy legitimate but vulnerable drivers to disable security and take control of systems. Researchers suspect that the drivers are exploited by copying portions of proofs-of-concept available on GitHub and are modified to suit the attack. This attack is observed in various attack campaigns ranging from those leveraged by hacktivists to prominent ransomware groups like RansoHub.

DEEP AND DARK WEB INTELLIGENCE

  • Pro-Russia threat actor group “Server Killers”: Pro-Russia threat actor group Server Killers claimed to have conducted a DDoS attack against the United Arab Emirates government portal and Ministry of Defense of United Arab Emirates. The attack supposedly lasted for 5 hours.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-41908: The affected applications contain an out-of-bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

  • Affected products: All NX versions prior to V2406.3000

  • CVE-2024-6456: AVEVA Historian Server has a vulnerability that, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.

  • Affected products: Historian Server verision 2023 R2, versions 2023 to 2023 P03, and versions 2020 to 2020 R2 SP1 P01

Tags: DIB, tlp:green