zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Infostealers Waltz Through macOS to Grab Crypto Wallets, Browser Creds
  • China-Linked APT Exploits Recently Disclosed Zero-Day in Communication Devices
  • Slack Patches AI Bug That Let Attackers Steal Data From Private Channels

Infostealers Waltz Through macOS to Grab Crypto Wallets, Browser Creds

Source: https://thehackernews.com/2024/08/new-macos-malware-cthulhu-stealer.html

What happened: A type of infostealer, dubbed as “Cthulhu Stealer,” has been identified by cybersecurity researchers. It reportedly takes advantage of inherent security flaws in the MacoS. The malware strain is seen to target cryptocurrency wallets and gaming credentials, and steal browser data.

Why it matters: The infostealer is not considered by researchers to be particularly sophisticated; despite its simplicity, Cthulhu’s success reveals gaps in user awareness and highlights how attackers exploit the misconception that Apple devices are inherently secure. Younger and less tech-literate users are especially easy victims to this infostealer since they are less likely to catch on to suspicious requests.

China-Linked APT Exploits Recently Disclosed Zero-Day in Communication Devices

Source: https://securityaffairs.com/167423/apt/china-velvet-ant-zero-day-ciasco-switches.html

What happened: China-linked advanced persistent threat (APT) group Velvet Ant has been exploiting a zero-day vulnerability to take over network services. The bug allows attackers with administrator credentials to execute commands as root, enabling them to install custom malware named VELVETSHELL on the affected devices.

Why it matters: Velvet Ant's ability to transition from typical endpoints to exploiting network appliances, traditionally considered secure, points to improved sophistication in maintaining persistent access and control over critical infrastructure. By targeting switches and deploying malware that evades detection, the group effectively bypassed standard security defenses, enabling ongoing espionage and data exfiltration. Besides, Velvet Ant has previously demonstrated other cyberespionage activities. Researchers found it engaging in a multi-year cyberespionage campaign targeting a large company in South Asia, to steal crucial data. Moreover, the threat actor’s connection to China suggests a likely geopolitical motive. However, the motive cannot be confirmed at the time of reporting.

Slack Patches AI Bug That Let Attackers Steal Data From Private Channels

Source: https://www.darkreading.com/cyberattacks-data-breaches/slack-ai-patches-bug-that-let-attackers-steal-data-from-private-channels

What happened: Salesforce's Slack Technologies has patched a flaw in Slack AI that could have allowed attackers to steal data from private channels or perform phishing attacks. The issue stemmed from a prompt injection vulnerability in the AI feature, which processes natural language queries.

Why it matters: The vulnerability posed significant risks because it could enable attackers to access sensitive data and files from private Slack channels, potentially exposing confidential business information. Additionally, the flaw could facilitate phishing attacks within the Slack workspace, increasing the likelihood of user deception and security breaches. Given Slack's widespread use in professional settings, the flaw highlighted serious concerns about data security and integrity in collaborative platforms. This flaw's exploitation could have led to unauthorized access to sensitive business data and secrets, jeopardizing organizational security and potentially exposing confidential information to malicious actors.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user Black Maskers Army: Pro-Palestine hacktivist group Black Maskers Army has claimed to have launched a cyberattack against the U.S. Environmental Protection Agency (EPA).

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-28987: The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated users to access internal functionality and modify data. The critical vulnerability has a CVSS score of 9.1. To address the risks posed by this vulnerability, it is recommended to upgrade to version 12.8.3 HF2 that includes the necessary security fixes.

  • Affected products: WHD 12.8.3 HF1 and all previous versions

Tags: DIB, tlp:green