zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 24, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 24, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Treasury Department Imposes Fresh Sanctions to Combat North Korea’s Illicit Revenue
  • Arms Maker Rheinmetall Confirms BlackBasta Ransomware Attack
  • GoldenJackal: New Threat Group Targeting Middle Eastern and South Asian Governments
  • CVE-2023-30763
  • CVE-2023-29242
  • CVE-2023-31922
  • CVE-2019-9596
  • Credit Card Data Breach: 2023-5-23
  • April Logs Botnet Breach
  • BreachForums: 1.6KK_VIP_GOLD Combolist

U.S. Treasury Department Imposes Fresh Sanctions to Combat North Korea’s Illicit Revenue

The U.S. Department of the Treasury has imposed sanctions on four institutions and one person in the Democratic People’s Republic of Korea (DPRK) for their involvement in cybercrime and illicit revenue generation for the incumbent regime. The sanctions have been levied on Pyongyang University of Automation and Technical Reconnaissance Bureau (alongside its subordinate cyber unit, the 110th Research Center) for conducting and coordinating malicious cyber activity across international borders. Further, Chinyong Information Technology Cooperation Company and North Korean national Kim Sang Man have been sanctioned for organizing IT employees to work overseas and generate revenue for the DPRK’s regime.

Arms Maker Rheinmetall Confirms BlackBasta Ransomware Attack

German automotive and arms manufacturer Rheinmetall confirmed a ransomware attack that impacted its civilian business; however, because of the separated IT infrastructure within the group, Rheinmetall's military business operations were unharmed. On May 20, 2023, ransomware group BlackBasta posted Rheinmetall on its leak site and shared stolen data samples, including non-disclosure agreements, technical schematics, and scanned passports. With over 25,000 employees and an annual revenue exceeding USD 7 billion, Rheinmetall produces military vehicles, armaments, air defense systems, engines, and steel products.

GoldenJackal: New Threat Group Targeting Middle Eastern and South Asian Governments

GoldenJackal, an advanced persistent threat (APT) group, is targeting government and diplomatic entities in the Middle East and South Asia. The group is known to target its victims using tailored malware to steal data, which is propagated through removable drives and used to conduct surveillance. Researchers have observed that GoldenJackal and Russian state-sponsored group Turla share several striking similarities in tactics, techniques, and targeted regions, suggesting that this APT might be a state-sponsored effort.

VULNERABILITIES

  • CVE-2023-30763 - Heap-based overflow in Intel(R) SoC Watch-based software before version 2021.1 may allow a user to potentially enable escalation of privilege via local access.
  • CVE-2023-29242 - Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
  • CVE-2023-31922 QuickJS commit 2788d71 was discovered to contain a stack overflow via the component js_proxy_isArray at quickjs.c.

EXPLOITS

  • CVE-2019-9596 - Darktrace POC - CVE-2019-9596 and CVE-2019-9597

BREACHES

Tags: DIB, tlp:green