ZeroFox Cyber Intelligence Daily Brief - October 3, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 3, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Several Flaws in Business Routers Expose Networks to Major Attacks
- FIN7 Hackers Launch Deepfake Nude “Generator” Sites to Spread Malware
- North Korea's “Stonefly” APT Targets U.S. Private Companies
Several Flaws in Business Routers Expose Networks to Major Attacks
Source: https://www.theregister.com/2024/10/02/draytek_routers_bugs/
What happened: Cybersecurity researchers have found fourteen vulnerabilities in DrayTek Vigor routers, with one flaw rated a critical 10 in severity, exposing more than 700,000 devices to the public internet. The flaws can allow attackers to gain root access, deploy ransomware, exfiltrate data, conduct denial-of-service attacks, or create botnets.
Why it matters: Reportedly, most vulnerable routers are embedded in business networks and open to exploitation through their exposed web interfaces. With the routers functioning like small servers, attackers can use them to launch massive attacks, conceal their origins, and compromise connected devices, posing a serious risk to business operations and security. Chinese APTs have previously used DrayTek bugs to employ vulnerable devices in a botnet setup for a cover data transfer operation.
FIN7 Hackers Launch Deepfake Nude “Generator” Sites to Spread Malware
What happened: The APT group FIN7 has launched a network of fake AI-powered “deepnude generator” sites designed to infect visitors with infostealer malware. These sites entice users interested in generating non-consensual explicit images by offering free trials or free downloads, but instead, they distribute information stealing malware Lumma Stealer.
Why it matters: The rise of deepfake technology, particularly through AI-powered deepnude generators, poses serious ethical and legal challenges. These tools can create non-consensual explicit images, causing emotional distress and reputational harm for the individuals involved, while undermining personal autonomy and privacy. Additionally, groups like FIN7 exploit this technology to distribute malware, increasing risks to personal security. Cybercriminals prey on curiosity around deepfake generators, with malware like Lumma Stealer compromising sensitive data, including login credentials and financial information, leading to identity theft, financial loss, and more.
North Korea's “Stonefly” APT Targets U.S. Private Companies
Source: https://www.darkreading.com/vulnerabilities-threats/stonefly-apt-us-private-cos-north-korean-profit
What happened: A North Korea-linked APT group has shifted its focus to targeting private companies in the United States for financial gain, despite a USD 10 million bounty on a key member. In August, the group attempted intrusions on three U.S. organizations, likely for financial gain, though ransomware was not reportedly deployed.
Why it matters: Stonefly has been observed targeting private U.S. companies likely shows a shift in the group’s plans from gaining state secrets to amassing financial resources. Despite the U.S. Department of Justice's (DOJ) sanctions against the group and a USD 10 million bounty on a member, Stonefly remains active, likely reflecting a change in the group’s focus. This shift poses new risks to businesses, potentially threatening economic stability and exposing companies without strategic intelligence value to state-sponsored cyberattacks for financial extortion.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user Offensive_Sandman: Threat actor "Offensive_Sandman" has allegedly sold an Android zer0 day that can cause RCE on predominantly English-language dark web forum BreachForums. The exploit supposedly affects Android versions 11, 12, 13, and the recently released Android 14.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-29824: An unspecified SQL injection vulnerability in the Core server of Ivanti EPM 2022 SU5 and earlier versions enables an unauthenticated attacker on the same network to execute arbitrary code. This critical vulnerability has a CVSS score of 9.6. CISA has added this flaw to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
Affected products: Core server of Ivanti EPM 2022 SU5 and prior
CVE-2024-41925: CISA has warned about two critical vulnerabilities in Optigo Networks ONS-S8 Aggregation Switch products used in critical infrastructure. CVE-2024-41925 is identified as a PHP Remote File Inclusion (RFI) vulnerability caused by improper validation or sanitation of user-supplied file paths. This flaw could allow an attacker to perform directory traversal, bypass authentication, and execute arbitrary remote code. The details for CVE-2024-45367 can be found in CISA's Industrial Control Advisory.
Affected products: ONS-S8 - Spectra Aggregation Switch versions 1.3.7 and prior
Tags: DIB, tlp:green