zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Foreign Threat Actor Conducting Large-Scale Spear-Phishing Campaign with RDP Attachments
  • Chinese Botnet Exploits Router Vulnerabilities for Credential Theft
  • Long Island Plastic Surgical Group Confirms 161,000-Record Data Breach

Foreign Threat Actor Conducting Large-Scale Spear-Phishing Campaign with RDP Attachments

Source: https://www.cisa.gov/news-events/alerts/2024/10/31/foreign-threat-actor-conducting-large-scale-spear-phishing-campaign-rdp-attachments

What happened: CISA has received multiple reports of a large-scale spear-phishing campaign targeting organizations in several sectors, including government and information technology (IT). The foreign threat actor, often posing as a trusted entity, is sending spear-phishing emails containing malicious remote desktop protocol (RDP) files to targeted organizations to connect to and access files stored on the target’s network.

Why it matters: CISA and industry partners are reportedly coordinating, responding, and assessing the impact of this campaign. Once access has been gained, it is likely the threat actor may pursue additional activity, such as deploying malicious code to achieve persistent access to the target’s network. CISA urges users and administrators to remain vigilant against spear-phishing attempts, and hunt for any malicious activity.

Chinese Botnet Exploits Router Vulnerabilities for Credential Theft

Source: https://thehackernews.com/2024/11/microsoft-warns-of-chinese-botnet.html

What happened: Chinese threat actor Storm-0940 has been reportedly conducting password spray attacks using the Quad7 (aka 7777 or xlogin) botnet, which targets vulnerable SOHO routers and VPN appliances. This group has been active since at least 2021, exploiting security flaws to gain unauthorized access to organizations in North America and Europe.

Why it matters: Storm-0940’s password spray attacks using the Quad7 botnet significantly increase the risk of unauthorized access to networks, potentially enabling attackers to exfiltrate sensitive data or disrupt operations. This threat actor has been observed targeting critical sectors such as think tanks, government agencies, NGOs, law firms, and the defense industrial base. Its sophisticated targeting strategy can result in data breaches, and espionage, compromising the confidentiality of sensitive information. Additionally, the Quad7 botnet exacerbates this threat by exploiting vulnerabilities in various SOHO routers and VPN appliances, allowing attackers to gain network access and facilitate further intrusions.

Long Island Plastic Surgical Group Confirms 161,000-Record Data Breach

Source: https://www.hipaajournal.com/long-island-plastic-surgical-group-confirms-161k-record-data-breach/

What happened: Long Island Plastic Surgical Group has confirmed that the data of more than 161,000 individuals was compromised in a cyber incident early this year. The breach involved a network intrusion where the threat actors exfiltrated data. It was confirmed that personally identifiable information (PII) including names, dates of births, Social Security numbers, medical data, biometric data, and clinical photographs were stolen.

Why it matters: Data breaches are a significant concern, but breaches affecting healthcare institutions have a far more serious implication since they endanger sensitive information, especially clinical photos. Threat actors responsible are likely to be more incentivised to press both the institution and patients for exorbitant ransom demands while patients, especially, will likely readily give in to these demands to protect their identity and privacy. Threat actors may even engage in double extortion where threat actors harass the victims to further expose compromised data.

DEEP AND DARK WEB INTELLIGENCE

RAMP user Kyley: The untested threat actor "Kyley" advertised source code of the previously announced Ransomware-as-a-Service malware dubbed "PlayBoy" on predominantly Russian language Dark Web forum RAMP.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-6943: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 and later, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) all versions, GX Works2 versions 1.11M and later, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E and later, MT Works2 all versions, MX Component versions 4.00A and later and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.

Affected products: The affected products and versions have been listed in this update.

Tags: DIB, tlp:green