ZeroFox Cyber Intelligence Daily Brief - November 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- NSA Issues Guidance for using Trusted Platform Modules (TPMs)
- North Korean Hackers Target macOS Users
- “SteelFox” Malware Infects 11,000 Victims
NSA Issues Guidance for using Trusted Platform Modules (TPMs)
What happened: The National Security Agency (NSA) has issued guidance for using Trusted Platform Modules (TPMs) to secure computing devices and harden the Department of Defense (DoD) enterprise infrastructure. A TPM is a security solution embedded in most enterprise computing systems.
Why it matters: The TPM protects keys—associated with certificates created by vendors and manufacturers—used during acceptance testing and operational use to validate the integrity of the computing system. TPMs are now required for many devices across the DoD to help protect user credentials and stored data. TPM is a vital component to mitigate vulnerabilities affecting user credentials, boot security, and static data.
North Korean Hackers Target macOS Users
Source: https://www.securityweek.com/north-korean-hackers-target-macos-users-with-fake-crypto-pdfs/
What happened: North Korean hacking group BlueNoroff has launched a new malware campaign targeting macOS users. They are using phishing emails, featuring fake cryptocurrency news stories to trick victims, embedding malicious applications that are disguised as PDF links.
Why it matters: Cryptocurrency-themed scams are on the rise, and this latest campaign by the North Korean BlueNoroff group highlights a significant threat. By targeting individuals in the decentralized finance (DeFi) and cryptocurrency sectors, the hackers aim to steal sensitive data and funds. The malware’s ability to bypass Apple’s security measures shows the growing risk to macOS users, who are often perceived to be less vulnerable than other popular operating systems.
“SteelFox” Malware Infects 11,000 Victims
Source: https://www.darkreading.com/cloud-security/steelfox-malware-blitz-infects-11k
What happened: A malware campaign targeting applications like AutoCAD and JetBrains has impacted thousands of users since February 2023. Distributed via forums and illegal torrents, the malware is designed to steal data and mine cryptocurrency. Over 11,000 users across countries such as Brazil, China, and Russia have reportedly been affected.
Why it matters: This malware campaign likely poses substantial risks for individuals and businesses. By targeting applications like AutoCAD and JetBrains, the attackers may be compromising sensitive project data and intellectual property, particularly from sectors that rely on these tools for software development, engineering, and design. The malware’s cryptomining capabilities reportedly strain infected systems, degrading performance, while data theft could expose users to credential compromise, financial loss, and corporate espionage.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Anonymous Sudan: On November 7, 2024, threat actor group Anonymous Sudan claimed to offer access to botnets of up to 1 TB for USD 500 weekly, USD 2,500 monthly, and a test price of USD 30.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-51567: CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. This flaw has a CVSS score of 10. CISA has added this vulnerability in its Known Exploited Vulnerabilities (KEV) Catalog.
Affected products: Versions through 2.3.6 and 2.3.7
CVE-2019-16278: Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution. CISA has added this vulnerability in its Known Exploited Vulnerabilities (KEV) Catalog.
Affected product: Nostromo nhttpd version 1.9.6
Tags: DIB, tlp:green