zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and Partners Release Advisory on Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
  • Iranian Hackers Breach Critical Sectors Using New Malware
  • Hackers Use Rare Stealth Techniques to Down Asian Military, Govt Orgs

CISA and Partners Release Advisory on Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations

Source: https://www.cisa.gov/news-events/alerts/2024/08/28/cisa-and-partners-release-advisory-iran-based-cyber-actors-enabling-ransomware-attacks-us

What happened: CISA and the FBI released an advisory warning that cyber actors, known in the private sector as “Pioneer Kitten,” are targeting and exploiting U.S. and foreign organizations across multiple sectors in the United States. The FBI previously observed these actors attempt to monetize their access to victim organizations on cyber marketplaces. A significant percentage of the group’s U.S.-focused cyber activity is in furtherance of obtaining and maintaining technical access to victim networks to enable future ransomware attacks.

Why it matters: The FBI assesses a significant percentage of these threat actors’ operations against U.S. organizations intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as intrusions enabling the theft of sensitive technical data against organizations in Israel and Azerbaijan).

Iranian Hackers Breach Critical Sectors Using New Malware

Source: https://www.bleepingcomputer.com/news/security/APT33-Iranian-hacking-group-uses-new-tickler-malware-to-backdoor-us-govt-defense-orgs/

What happened: Iranian APT33 (alias Peach Sandstorm and Refined Kitten) has deployed newly developed Tickler malware to gather intelligence from organizations in the government, defense, satellite, oil, and gas sectors in the United States and the United Arab Emirates.

Why it matters: Between April and July 2024, APT33—operating under the Iranian Islamic Revolutionary Guard Corps (IRGC)—used Tickler malware and exploited popular cloud services for command-and-control operations to breach networks as a part of an intelligence gathering operation. APT33 used fake subscriptions to popular cloud services for command-and-control during its attacks. It aimed to access multiple accounts without triggering security alerts or account lockouts by using common passwords in the attacks. The campaign targets, government, defense, satellite, oil, and gas sectors, are lucrative for data breaches, cyber espionage, and sabotage because of the valuable, strategic, and sensitive information they hold that is critical to national security and infrastructure. It further indicates that the adversary was either likely motivated by political inclinations or aimed to attract politically motivated actors with the intel it might have gathered.

Hackers Use Rare Stealth Techniques to Down Asian Military, Govt Orgs

Source: https://www.darkreading.com/application-security/hackers-use-rare-stealth-techniques-to-down-asian-military-govt-orgs

What happened: A new cyberattack campaign is targeting key organizations in Southeast Asia using two advanced techniques that are not widely known. The first technique, called GrimResource, allows hackers to inject malicious code into a tool used to manage a widely used operating system. The second method, AppDomainManager Injection, involves inserting harmful files in a more streamlined way than traditional methods.

Why it matters: Although these techniques have existed in the past—reportedly used by Iran-linked threat actors, China, penetration testers, and others—they are not often seen in campaigns in the wild. A group of hackers has been observed using these methods to launch attacks on the IT systems of Taiwanese government agencies, the Philippine military, and energy companies in Vietnam. Their objective appears to be gaining control over these systems, endangering national data, personally identifiable information (PII), civilian safety, and resources.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user DNI: On August 27, 2024, the threat actor "DNI" claimed to be selling data related to Spanish citizens on the predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-6633: The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.

  • Affected products: FileCatalyst Workflow 5.1.6 Build 139 (and earlier)

  • CVE-2024-3982: An attacker with local access to a device where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it. Hitachi has added several other vulnerabilities to its advisory affecting the Hitachi Energy MicroSCADA X SYS600 product.

  • Affected products: MicroSCADA X SYS600 versions 10.5 and below

Tags: DIB, tlp:green