zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 2, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • “Voldemort” Malware Curses Orgs Using Global Tax Authorities
  • Newly Emerged Group with Global Targets Likely an ALPHV Rebrand
  • New Mirai Botnet Exploiting Old IP Cameras

“Voldemort” Malware Curses Orgs Using Global Tax Authorities

Source: https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities

What happened: A global malware campaign dubbed "Voldemort" has been targeting organizations by sending phishing emails primarily impersonating tax authorities in Europe, Asia, and the United States. This custom C backdoor malware is designed for data exfiltration and deploying additional malicious payloads.

Why it matters: The campaign saw a significant increase in activity around August, with nearly 6,000 phishing emails sent in a single day, impersonating various tax agencies such as the U.S. Internal Revenue Service (IRS), the UK’s HM Revenue & Customs, and France's Direction Générale des Finances Publiques. The phishing emails were meticulously crafted in the native language of the targeted tax authority and employed both compromised and legitimate domain names to enhance their credibility. This sophisticated and localized approach significantly increases the likelihood of deceiving recipients and compromising security. The campaign also utilizes a spreadsheet application for C2 communications and exploits legitimate software for further stealth. The scale and complexity of the campaign suggest an intent to conduct espionage, targeting sensitive organizational data and posing severe security and operational risks.

Newly Emerged Group with Global Targets Likely an ALPHV Rebrand

Source: https://www.bleepingcomputer.com/news/security/cicada3301-ransomwares-linux-encryptor-targets-vmware-esxi-systems/

What happened: A recently emerged ransomware-as-a-service (RaaS) operation—dubbed Cicada3301 and observed by ZeroFox intelligence to be active since June this year—targeting global companies, is likely a rebrand of the notorious ALPHV group. Like most other ransomware groups, Cicada3301 uses double-extortion tactics—encrypting and exfiltrating data—to coerce victims into paying ransom demands.

Why it matters: ZeroFox intelligence observed tthe threat group announce its ransomware malware on a predominantly Russian language Dark Web forum, RAMP in July 2024. This malware has overlapping features with the one ALPHV (BlackCat/Noberus) used, including the ChaCha20 algorithm for encryption and identical VM shutdown and snapshot-wiping commands. Besides, Cicada3301’s focus on VMware ESXi environments is a likely indication of its intent to severely target enterprise networks, which are crucial to modern infrastructure. Additionally, the group is reportedly aiming to collaborate with the Brutus botnet to gain initial access to corporate networks. The botnet has previously conducted large-scale VPN brute-forcing attacks targeting several popularly used appliances. The potential collaboration will likely facilitate such attacks and cause large-scale disruptions in crucial networks.

New Mirai Botnet Exploiting Old IP Cameras

Source: https://www.theregister.com/2024/08/31/ip_cameras_mirai_botnet/

What happened: End-of-life AVTECH AVM1203 IP cameras, which are still used globally, have been exploited to create a new Mirai botnet. This campaign reportedly takes advantage of a remote code execution (RCE) vulnerability in AVTECH AVM1203 IP cameras. Exploiting this flaw could enable an attacker to inject and execute commands with the same privileges as the running process owner.

Why it matters: The exploitation of the AVTECH AVM1203 IP cameras, despite their discontinuation and lack of support since 2019, poses a threat to global users, particularly for entities involved in critical infrastructure, as these cameras are still reportedly being used by commercial facilities, financial services, and healthcare. The global use of these vulnerable cameras in critical infrastructure shows the need for better cybersecurity hygiene amongst users. Not implementing mitigation measures will likely lead to the exploitation of these compromised devices for destructive attacks, impacting essential services and public safety.

DEEP AND DARK WEB INTELLIGENCE

  • XSS user KeeperZed: The untested threat actor "KeeperZed" advertised a zero-day iMessage Remote Code Execution (RCE) exploit on the predominantly Russian language Dark Web forum XSS. According to KeeperZed, the exploit is ZeroClick, supports versions iOS 17.xx, and iOS 18.xx.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-7513: A high-severity (CVSS score: 8.8) code execution vulnerability exists in FactoryTalk View Site Edition. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.

  • Affected products: FactoryTalk View SE version 13.0

  • CVE-2024-40766: An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash.

  • Affected products: SonicWall Firewall Gen 5 and Gen 6 devices, and SonicWall Firewall Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Tags: DIB, tlp:green