zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 5, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • UK NCSC Warns of Stealthy Chinese Malware Targeting Network Firewalls
  • APT36 Refines Tools in Attacks on Indian Targets
  • Columbus Ransomware Attack Exposes Sensitive Data of 500,000, Including Crime Victims

UK NCSC Warns of Stealthy Chinese Malware Targeting Network Firewalls

Source: https://www.bleepingcomputer.com/news/security/custom-pygmy-goat-malware-used-in-sophos-firewall-hack-on-govt-network/

What happened: The UK National Cyber Security Centre (NCSC) has released a report on a Linux malware strain, "Pygmy Goat," targeting specific network firewall devices via a sophisticated backdoor. The malware, likely linked to a Chinese threat actor, uses deceptive techniques to blend into systems and access devices remotely.

Why it matters: Pygmy Goat’s ability to disguise itself as a trusted network component enables it to bypass security monitoring, especially in environments with similar infrastructure. The malware can execute remote commands, monitor network activity, and establish hidden access points by exploiting specific SSH traffic patterns and concealing its communication through encrypted Internet Control Message Protocol (ICMP) packets. Because of its camouflaging features, critical systems in government and defense sectors likely face a high threat from Pygmy Goat.

APT36 Refines Tools in Attacks on Indian Targets

Source: https://www.darkreading.com/cyberattacks-data-breaches/apt36-refines-tools-attacks-indian-targets

What happened: Pakistan's APT36 group has upgraded its ElizaRAT malware targeting Indian government, military, and diplomatic sectors. The updated ElizaRAT reportedly includes several features including advanced command-and-control capabilities, a new payload that exfiltrates sensitive file metadata from compromised systems, and new evasion techniques.

Why it matters: The new capabilities APT36 has adopted likely increases the threat posed to India's government, military, and diplomatic infrastructure, potentially further compromising sensitive information essential to national security. The advanced evasion techniques in the new ElizaRAT variant is likely intended to make it more difficult for defenders to detect and weed out the malware, prolonging attackers' access to compromised systems. Additionally, the new payload reportedly enables APT36 to collect targeted data, which could provide valuable intelligence or be leveraged for further attacks, thereby amplifying the group’s intended impact on critical sectors.

Columbus Ransomware Attack Exposes Sensitive Data of 500,000, Including Crime Victims

Source: https://www.theregister.com/2024/11/04/columbus_rhysida_ransomware/

What happened: The City of Columbus, Ohio, has confirmed that a July ransomware attack compromised personal data for 500,000 people, with the attackers leaking around 3 TB of stolen information. The breached data included records from the prosecutor's office and crime databases dating back to 2015.

Why it matters: The exposed data includes sensitive details of crime victims, police officers, and even minors and domestic violence survivors who are likely to face additional threats. Exposed details like home addresses, bank account information, and Social Security numbers are likely to threaten the physical security of the targeted individuals while subjecting them to identity fraud and financial extortion scams. The City of Columbus has offered two years of free credit monitoring to all its residents.

DEEP AND DARK WEB INTELLIGENCE

  • Exploit user DarkAmbur: Untested threat actor "DarkAmbur" has advertised an auction for access to what they claim is a web panel of the Dell Logistics Services in Europe on predominantly Russian language Dark Web forum "Exploit." According to DarkAmbur the web panel contains information about shipments, service tags, customers, and more than 30,000 orders per day.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-39720: An out-of-bounds read vulnerability in the /api/create endpoint that lets attackers send two HTTP requests with a malformed GGUF file, triggering a segmentation fault and causing a denial-of-service (DoS) crash. Cybersecurity researchers have also discovered five more flaws in the Ollama artificial intelligence (AI) framework that actors could exploit for DoS attacks, model poisoning, and model theft.

  • Affected product: Ollama versions before 0.1.46

  • CVE-2024-8957: PTZOptics PT30X-SDI/NDI before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices. CISA has added these vulnerabilities to its Known Exploits Vulnerabilities (KEV) Catalog based on evidence of active exploitation.

  • Affected products: PTZOptics PT30X-SDI from versions 0 before 6.3.40

Tags: DIB, tlp:green