zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 25, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 25, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • European Space Agency's Official Store Hacked to Steal Payment Cards
  • Mozi Botnet’s Successor Androxgh0st Poses Major Threat to Critical Infrastructure
  • Postman Workspaces Leaked Thousands of API Keys and Sensitive Tokens

European Space Agency's Official Store Hacked to Steal Payment Cards

Source: https://www.bleepingcomputer.com/news/security/european-space-agencys-official-store-hacked-to-steal-payment-cards/

What happened: The European Space Agency's (ESA) official web shop was hacked, and a malicious JavaScript script was injected during checkout. This script created a fake Stripe payment page that collected customer payment card details. The data was exfiltrated to a domain mimicking the legitimate ESA shop, but with a different top-level domain (.pics instead of .com).

Why it matters: The breach compromised ESA customers' payment information, putting them at risk of identity theft and financial loss. The use of a fraudulent domain likely misled shoppers, and ESA's lack of control over the third-party store exposes the risks of outsourcing sensitive data management. The ESA merchandise store is currently offline, displaying a message that it is "temporarily out of orbit."

Mozi Botnet’s Successor Androxgh0st Poses Major Threat to Critical Infrastructure

Source: https://www.theregister.com/2024/12/24/androxgh0st_botnet_mozi/

What happened: Cybersecurity researchers are warning that the Androxgh0st botnet, which has adopted some capabilities of the now-defunct Mozi botnet, is a major threat to critical infrastructure and is likely a cyber weapon of the Chinese government.

Why it matters: Androxgh0st has infected hundreds of thousands of systems and expanded its arsenal of exploits by 100% in almost a year by exploiting vulnerabilities in routers, VPNs, firewalls, web servers, and several popular operating systems. In January 2024, U.S. federal agencies released a joint advisory highlighting how Androxgh0st establishes a botnet for victim identification and exploitation in vulnerable networks and targets files that contain confidential information, such as credentials, for various high-profile applications. The likely association with the Chinese government and its sophisticated capabilities showcases how Androxgh0st is likely to be a threat to critical infrastructure—a hub of sensitive information that impacts national security.

Postman Workspaces Leaked Thousands of API Keys and Sensitive Tokens

Source: https://hackread.com/postman-workspaces-leak-api-keys-sensitive-tokens/

What happened: Over 30,000 publicly accessible Postman Workspaces were discovered leaking sensitive information, including API keys, tokens, and administrator credentials. The impacted data was associated with several organizations across various sectors and affected many widely used platforms due to misconfigured access controls and plaintext storage.

Why it matters: A portion of the leaked data that belonged to firms in the healthcare and financial sectors is likely sensitive and is also likely personal, potentially posing threats to those who own the data. Besides, the platforms affected by the leak are widely used across corporations and companies worldwide, leaving them vulnerable to further malicious attacks, including data breaches, unauthorized access, and targeted phishing attacks. Postman has since introduced a policy to detect and limit public exposure to sensitive data.

DEEP AND DARK WEB INTELLIGENCE

XSS user DARK_ALPHA: Untested threat actor "DARK_ALPHA" advertised network access to Singapore telecommunications company SIMBA Telecom on predominantly Russian language dark web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-43441: A vulnerability in Apache HugeGraph-Server allows attackers to bypass authentication due to improper handling of authentication mechanisms and assumed immutable data structures. Users are advised to upgrade to version 1.5.0, which resolves the issue.

Affected products: Apache HugeGraph-Server: from 1.0.0 before 1.5.0

Tags: DIB, tlp:green