zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - An Introduction to Stealer Logs
  • Hackers Target Rabbi in an Elaborate Social Engineering Campaign
  • FBI Highlights Safety Measures to Safeguard the Nation’s Critical Food Infrastructure

ZeroFox Intelligence Brief - An Introduction to Stealer Logs

Source: https://zerofox.com/advisories/25392/

What happened: ZeroFox researchers provide an introduction to info-stealing malware and the stealer logs that they produce, the cyber threat actors providing the supply and demand for them, as well as the threats that they pose to individuals and organizations. A stealer log is a series of data files generated and compiled by malicious software known as “infostealers.” The log contains personal and sensitive information that has been collated and extracted by a cyber threat actor.

Why it matters: Numerous data-stealing techniques are leveraged by infostealers; form grabbing, keylogging, credential dumping, and screen scraping are all commonly used to uncover and extract information from the target endpoints. Threat actors responsible for the production of stealer logs often seek to sell the stolen data in deep and dark web (DDW) forums, supplying cybercriminals with a constant trove of stolen information. The information found in stealer logs (such as credentials, personal financial details, browser information, and hardware specifications) is used to enable and enhance a broad array of cyberattacks. The mitigation strategies of individuals and organizations must be as diverse as the stealer logs themselves and address the full scope of network access vectors that can be targeted by an attacker in possession of credentials, cookies, and tokens or other browser data.

Hackers Target Rabbi in an Elaborate Social Engineering Campaign

Source: https://www.darkreading.com/threat-intelligence/irgc-linked-hackers-package-modular-malware-into-monolithic-trojan

What happened: TA453, an Iran-linked threat group, targeted an Israeli rabbi with a modular PowerShell backdoor deployed via a phishing attack. The modular malware strain reportedly makes phishing attacks harder to detect and gives threat actors more obscurity to collect information since they can be deployed in stages and take up relatively a smaller footprint.

Why it matters: Researchers observe a change in the group’s tactics from previously similar attack campaigns. In the past, researchers observed that TA453, after receiving a response from a target, would immediately send an attachment that loaded malware. However, their tactics have evolved; now, they send a ZIP file containing an LNK file that, when executed, deploys multiple additional stages of malware. While this approach may seem overly complex, it highlights a deliberate strategy. The malware is only deployed after TA453 confirms that the target is engaging with them, clicking on links, downloading files from file-sharing websites, and entering passwords into documents. This phased approach suggests that TA453 is confident the target will execute the payload, ensuring the success of their operation. In social engineering attacks, threat actors are likely to use the information for account takeovers, unauthorized transactions, and for further creating fake identities. Impersonating genuine institutions and companies makes it easy for adversaries to trick people into divulging sensitive information and carrying out actions that they normally would not.

FBI Highlights Safety Measures to Safeguard the Nation’s Critical Food Infrastructure

Source: https://www.fbi.gov/news/stories/agriculture-threats-symposium-in-nebraska-highlights-safety-measures-to-protect-nations-critical-food-infrastructure

What happened: FBI’s second annual Agriculture Threats Symposium in Omaha, Nebraska focused on rising cyber threats to the U.S. agriculture sector, including ransomware attacks, intellectual property theft, and bioterrorism, exacerbated by increased digital connectivity in farming operations. Over 400 farmers, cybersecurity experts, and policymakers from 30 states attended the symposium.

Why it matters: The FBI is monitoring four major threats to the nation’s agriculture sector, which—like water, power, and transportation—is considered part of the nation’s critical infrastructure. The agriculture sector, integral to national security, is increasingly vulnerable due to its reliance on digital technologies. As foreign adversaries, particularly China, target this critical infrastructure, the potential impact extends beyond farms to the broader economy. Any disruption in the agricultural sector to any degree affects rural life in the country because of the dependency on this critical sector. Examples of imminent cyber threats mentioned in the symposium included ransomware attacks that cripple operations, network hacks that take control of systems, and the theft of seeds worth millions of dollars in intellectual property and research. Additionally, the symposium highlighted the urgency for stronger partnerships between the public and private sectors to bolster cybersecurity defenses.

DEEP AND DARK WEB INTELLIGENCE

Telegram user EvilByte: A pro-Palestine hacktivist group claimed to have breached the security of the French government's open data portal. Allegedly, the actor gained access to vast amounts of sensitive data that includes personal information of government officials and employees, financial data, economic data, environmental data, and social data.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-4577: When using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in the command line given to Win32 API functions. The PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Affected products: PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8

CVE-2024-5932: The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.

Affected products: GiveWP version 3.14.1 and prior

Tags: DIB, tlp:green