zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • European Law Enforcement Stops Illegal IPTV Service Providers
  • Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Friday
  • Bootkitty Emerges as the First UEFI Bootkit Targeting Linux Systems

European Law Enforcement Stops Illegal IPTV Service Providers

Source: https://www.europol.europa.eu/media-press/newsroom/news/european-law-enforcement-stops-illegal-iptv-service-providers

What happened: Law enforcement authorities across Europe have taken down one of the largest illegal Internet Protocol Television (IPTV) networks operating within and outside the European Union. The investigation targeted 102 suspects, 11 of whom were arrested, for distributing material from streaming services online illegally, including movies and series.

Why it matters: The accused individuals also pirated more than 2,500 television channels such as sports broadcasters, making them available to over 22 million users worldwide without the consent of the copyright holders. In addition to intellectual property crime (copyright infringement), there are, reportedly, indications of further crimes, such as money laundering and cybercrime. Many of these platforms likely operate without safeguards, leaving users vulnerable to exploitation, including data theft, fraud, and more.

Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Friday

Source: https://www.darkreading.com/application-security/sneaky-skimmer-malware-magento-sites-black-friday

What happened: Cyberattackers have targeted Magento-based e-commerce websites with a new card-skimming malware. This malware reportedly injects malicious JavaScript into checkout pages, stealing payment card details from online shoppers through fake credit card forms or by directly extracting data from payment fields.

Why it matters: Magento is a widely used open-source e-commerce platform, making it a prime target for cybercriminals seeking to exploit vulnerabilities. Attackers exploit these weaknesses to steal sensitive customer data, such as payment card information, potentially leading to significant financial losses for both consumers and merchants. This incident is especially concerning given its timing, as online retailers and shoppers prepare for Black Friday.

Bootkitty Emerges as the First UEFI Bootkit Targeting Linux Systems

Source: https://thehackernews.com/2024/11/researchers-discover-bootkitty-first.html

What happened: Bootkitty, the first known Unified Extensible Firmware Interface (UEFI) bootkit targeting Linux systems, disables kernel signature verification, bypasses UEFI Secure Boot, and modifies the Grand Unified Bootloader (GRUB) bootloader to preload unknown Executable and Linkable Format (ELF) binaries during startup.

Why it matters: Bootkitty bypasses UEFI authentication by hooking critical integrity-checking functions and patching the GRUB bootloader, enabling attackers to load malicious kernel modules undetected. Its ability to disable signature verification and install rootkit functionalities like hiding processes and files helps evade detection. This sophistication expands UEFI threats beyond popular operating systems, making securing Linux systems a pressing challenge for cybersecurity teams because UEFI attacks target firmware, a difficult layer to monitor and protect effectively.

DEEP AND DARK WEB INTELLIGENCE

XSS user R-N-R: Untested threat actor "R-N-R" advertised "Fullz" (complete set of information) of 14 million U.S. citizens on predominantly Russian language dark web forum XSS. According to R-N-R, the set includes personally identifiable information (PII), including IP address, full name, email, address, state, bank name, bank account, SSN (social security number), and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-11680: Versions of ProjectSend prior to r1720 are vulnerable to an improper authentication flaw. Remote, unauthenticated attackers can exploit this vulnerability by sending specially crafted HTTP requests to the options[.]php file, allowing them to make unauthorized changes to the application's configuration. If successfully exploited, attackers can create user accounts, upload webshells, and inject malicious JavaScript.

Affected products: ProjectSend versions prior to r1720

Tags: DIB, tlp:green