zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 13, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Fortinet Confirms Data Breach After Hacker Claims to Steal 440 GB of Files
  • Iranian Actors Target Iraqi Government Networks with Sophisticated Malware
  • Federal Authorities Seize Over 350 Website Domains Used to Import Illegal Firearm Parts from China

Fortinet Confirms Data Breach After Hacker Claims to Steal 440 GB of Files

Source: https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/

What happened: Cybersecurity giant Fortinet has confirmed it experienced a data breach after a threat actor, known as "Fortibitch," claimed to have stolen 440 GB of files from the company's SharePoint server. The threat actor posted on a hacking forum about accessing data from Fortinet's Azure SharePoint instance and provided credentials to an S3 bucket containing the stolen files.

Why it matters: Fortinet confirmed that customer data was stolen from a "third-party cloud-based shared file drive." While the company did not disclose the number of affected customers or the specific type of compromised data, it stated that it "communicated directly with customers as appropriate." While the threat actor claimed to have stolen 440 GB of data, Fortinet confirmed that the breach affected less than 0.3 percent of its customer base and has not led to any reported malicious activity targeting those customers. Additionally, Fortinet clarified that the breach did not involve data encryption, ransomware, or access to its corporate network. Fortibitch reportedly attempted to extort Fortinet by demanding a ransom to prevent the publication of the stolen data, but the company refused to pay.

Iranian Actors Target Iraqi Government Networks with Sophisticated Malware

Source: https://thehackernews.com/2024/09/iranian-cyber-group-oilrig-targets.html

What happened: Iraqi government networks, including the offices of the Prime Minister Office and the Ministry of Foreign Affairs, were targets in a cyberattack linked to the Iranian state-sponsored group OilRig (APT34). The campaign involved social engineering tactics in deploying custom malware, enabling attackers to execute commands and steal sensitive data.

Why it matters: The malware strains—Veaty and Spearal—utilized a unique command and control (C2) structure involving DNS tunneling and compromised email accounts. The use of such tailored malware and specialized C2 channels reflects a likely trend of state-sponsored actors developing increasingly complex tools for cyber espionage. Furthermore, the campaign targets and the association of the actors with the Iranian state are indications of likely geopolitical motives. With cyber warfare emerging as a critical supplement to traditional military tactics, state-sponsored actors are key players in not just conducting cyber espionage but also in influencing regional dynamics. The OilRig operation, aiming to compromise sensitive communication channels, suggests a focused effort to access sensitive intelligence on Iraqi policies, internal affairs, and foreign relations. Such breaches can give Iran a tactical advantage in shaping regional politics, impacting diplomatic efforts, and asserting dominance in the Middle East.

Federal Authorities Seize Over 350 Website Domains Used to Import Illegal Firearm Parts from China

Source: https://www.justice.gov/usao-ma/pr/federal-authorities-seize-over-350-website-domains-used-import-illegal-switches-and

What happened: Federal authorities in Boston have seized over 350 domains that facilitated the import of switches and silences from China illegally. Possession and the importation of these parts from certain countries (including China) are prohibited under the National Firearms Act (NFA).

Why it matters: The seizure of over 350 domains facilitating the illegal importation of firearm switches and silencers from China is likely to be a significant step to counter a public safety threat, since gun violence is a severe issue in the United States. Many of the domains reportedly trafficked counterfeit goods and illegally used the firearm brand Glock’s trademark by offering “Glock” switches for sale. However, the company Glock has never manufactured switches. By shutting down these domains, authorities are disrupting the flow of contraband that could lead to more violent crime and undermine law enforcement efforts to counter gun violence in school shootings and mass shootings.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user CyberVolk: On September 12, threat actor CyberVolk claimed to have conducted a DDoS (distributed denial-of-service) attack against the website of the Recording Industry Association of America (RIAA). Additionally, the actor claimed to have hacked the complete database of the U.S. Geological Survey.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-6670: In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. The company has recently added indicators of compromise for this critical vulnerability (CVSS score: 9.8). Hackers have been exploiting this bug and CVE-2024-6671 (CVSS score: 9.8) to target vulnerable systems. The two bugs have been fixed in WhatsUp Gold 2024.0.0.

  • Affected products: WhatsUp Gold versions released before 2024.0.0

Tags: DIB, tlp:green