ZeroFox Cyber Intelligence Daily Brief - August 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Probe into Wi-Fi Router Maker TP-Link to Thwart Cyberattacks
- SolarWinds Recommends Critical RCE Bug Immediately Patched
- New Banshee Stealer Targets Over 100 Browser Extensions on macOS Systems
Probe into Wi-Fi Router Maker TP-Link to Thwart Cyberattacks
What happened: U.S. lawmakers have requested for a Commerce Department probe into TP-Link Technology Co., a Chinese company selling Wi-Fi routers, because of fears that malicious actors could target the United States with cyberattacks by exploiting vulnerabilities in TP-Link routers.
Why it matters: With the U.S. presidential elections on the horizon, various threat actors are gearing up to target the United States with cyberattacks ranging from ransomware incidents and data breaches to distributed denial-of-service (DDoS). Actors will also likely weaponize vulnerabilities in commonly used devices, like Wi-Fi routers. Compromised routers could provide a stealthy entry point for cyber espionage or attacks on U.S. entities. Moreover, with TP-Link being a leading provider of consumer routers, there is a justifiable concern regarding the safety of these widely used devices. Besides, there is also a geopolitical angle to this, where Chinese threat actors remain a persistent threat to the U.S. critical infrastructure, especially in light of a broader Chinese government-linked hacking campaign, Volt Typhoon.
SolarWinds Recommends Critical RCE Bug Immediately Patched
Source: https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1
What happened: SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.
Why it matters: SolarWinds recommends all Web Help Desk (WHD) customers to apply the now available patch. According to the advisory, all versions of WHD should be upgraded to WHD 12.8.3, and then the hotfix should be installed. SolarWinds' Web Help Desk is widely used by corporations, government organizations, healthcare, education, and help desk centers and that these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
New Banshee Stealer Targets Over 100 Browser Extensions on macOS Systems
Source: https://thehackernews.com/2024/08/new-banshee-stealer-targets-100-browser.html
What happened: Cybersecurity researchers have identified a new stealer malware dubbed Banshee Stealer, specifically targeting macOS systems. Priced at USD 3,000 per month in the cybercrime market, it operates on both x86_64 and ARM64 architectures and can extract a broad array of sensitive information from browsers, cryptocurrency wallets, and iCloud Keychain.
Why it matters: Banshee Stealer poses a critical threat due to its extensive data-harvesting capabilities and sophisticated evasion techniques. It can target a wide range of browsers, cryptocurrency wallets, and numerous browser extensions, capturing sensitive information from iCloud Keychain and Notes. By leveraging anti-analysis and anti-debugging measures to escalate privileges, it can bypass security mechanisms and compromise systems effectively. The specific targeting of systems based on language preferences further demonstrates its sophisticated approach to avoid detection and maximize impact. Its ability to collect data from various file types on users' desktop and documents folders further amplifies its potential for damage and data theft. Banshee Stealer's availability for USD 3,000 a month on the cybercrime market makes it highly dangerous, as it enables widespread and targeted attacks on macOS users by sophisticated criminals.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Dark Strom Team: On August 15, 2024, pro-Palestine threat actor group Dark Strom Team claimed to have conducted a DDoS attack against the website of NSO Group, an Israel-based cyber-intelligence firm.
RANSOMWARE INTELLIGENCE
CVE-2024-0056: Successful exploitation of this bug could allow an unauthenticated attacker located in the INTRALOG WMS network to decrypt and modify client-server communication, or potentially execute arbitrary code on the application servers.
Affected products: Siemens INTRALOG WMS versions prior to V4
Tags: DIB, tlp:green