zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and FBI Release Guide on Protecting National Political Organizations from Iranian Cyber Threats
  • APT Targets European Government Systems with Custom Malware
  • Lua Malware Targeting Student Gamers via Fake Game Cheats

CISA and FBI Release Guide on Protecting National Political Organizations from Iranian Cyber Threats

Source: https://www.cisa.gov/news-events/alerts/2024/10/08/cisa-and-fbi-release-fact-sheet-protecting-against-iranian-targeting-accounts-associated-national

What happened: CISA and the FBI have released a joint fact sheet titled "How to Protect Against Iranian Targeting of Accounts Associated with National Political Organizations." This fact sheet outlines the threats posed by actors linked to the Iranian Government's Islamic Revolutionary Guard Corps (IRGC), aiming to compromise American accounts to sow discord and undermine confidence in U.S. democratic institutions.

Why it matters: IRGC actors have previously gained and continue to seek access to personal and business accounts using social engineering techniques by targeting victims across email and chat. This fact sheet includes steps that individuals and organizations can take to enhance their security and resilience to protect themselves against the common techniques used by these cyber actors. CISA and FBI strongly recommend all individuals and organizations associated with national political organizations apply the mitigations in this fact sheet.

APT Targets European Government Systems with Custom Malware

Source: https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-using-custom-malware/

What happened: Advanced persistent threat (APT) group GoldenJackal breached air-gapped government systems in Europe using two custom tool sets to steal sensitive data, such as emails, encryption keys, and documents. The APT infected internet-connected machines with malware spread via USB drives, through which it infiltrated isolated systems between 2019 and 2024, targeting diplomatic and government entities.

Why it matters: The breach of air-gapped systems, specifically designed to be isolated for security, indicates a significant evolution of cyber espionage techniques and increased efficiency, making it harder for organizations to detect and counter such campaigns. Modular toolsets—like GoldenAce—designed to target offline networks by automating data theft and exfiltration can let threat actors bypass stringent security measures. Additionally, targeting government entities is a likely sign that the APT is either politically motivated or is seeking to attract state-aligned actors with sensitive information and access to government systems.

Lua Malware Targeting Student Gamers via Fake Game Cheats

Source: https://hackread.com/lua-malware-hit-student-gamers-fake-game-cheats/

What happened: Hackers are tricking users searching for game cheats into downloading Lua-based malware by manipulating search engine results (SEO poisoning) to lead them to malicious websites. This campaign is affecting users worldwide, including in North and South America, Europe, Asia, and Australia, posing a significant threat to unsuspecting student gamers.

Why it matters: According to researchers, the Lua malware is a part of an infection chain, leading to the deployment of infostealers like Redline. This can potentially lead to the harvest of sensitive credentials, including ChatGPT credentials, which are subsequently sold on the dark web. This likely increases the risk of further cyberattacks targeting individuals, gamers, and educational institutions. Users must be vigilant about downloading untrustworthy software, especially game cheats, and ensure their systems are protected with up-to-date security measures to minimize the threat.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user HikkI-Chan: Threat actor “HikkI-Chan” claimed to have leaked a database associated with the Florida Department of State on the predominantly English-language dark web forum BreachForums. The leaked database contains 5.53 GB of data, which includes 17 million unique email addresses and approximately 5 million records of personally identifiable information (PII), such as full names, addresses, phone numbers, and more. Additionally, the leak contains organizational data for over 83,000 entries.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-43572: This month’s Patch Tuesday addresses 117 security vulnerabilities, including five publicly disclosed zero-days, two of which are reportedly actively exploited. CVE-2024-43572 is a remote code execution flaw in Microsoft Management Console (MMC). This vulnerability allowed malicious MSC files to execute code on vulnerable devices, but Microsoft has fixed it by preventing untrusted MSC files from being opened.

Affected products: The affected products and versions have been listed by Microsoft in this security update.

CVE-2024-9379: SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. Ivanti has released updates for Ivanti CSA (Cloud Services Application) which addresses a medium severity and two high severity vulnerabilities. Successful exploitation could lead to an attacker with admin privileges to bypass restrictions, run arbitrary SQL statements or obtain remote code execution.

Affected products: Ivanti CSA before version 5.0.2

Tags: DIB, tlp:green