ZeroFox Daily Intelligence Brief - May 31, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 31, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Cyber Threat Advisory: Ransomware Update
- CISA Industrial Control Systems Advisory: Advantech WebAccess/SCADA
- DogeRAT Malware Impersonates BFSI, Entertainment, and E-Commerce Apps
- Vulnerabilities: CVE-2022-47178, CVE-2023-2952, and CVE-2023-29741
- Exploits: CVE-2020-5741 and CVE-2021-2529
- Breach: Credit Card Data Breach: 2023-5-29
ZeroFox Intelligence Cyber Threat Advisory: Ransomware Update
A ZeroFox Intelligence advisory on ransomware activity notes an increased threat from ransomware and digital extortion, with the total incidents this quarter likely to exceed that in Q1 2023. The emergence of new ransomware variants (such as Akira, CrossLock, and Cryptnet), proliferation of Ransomware-as-a-Service (RaaS) activity, emboldened threat actors, and victims' susceptibility to paying ransom are probable causes of this rise.
CISA Industrial Control Systems Advisory: Advantech WebAccess/SCADA
A high-severity bug in Advantech WebAccess/SCADA (Supervisory Control and Data Acquisition) version 8.4.5 could allow an attacker full control over the SCADA server. Advantech has released a new version (V9.1.4) to address the problem.
DogeRAT Malware Impersonates BFSI, Entertainment, and E-Commerce Apps
A new malware campaign called DogeRAT impersonates popular Android apps for e-commerce, entertainment, and banking, financial service, and insurance (BFSI) services. The malware compromises devices to obtain private data such as contacts, messages, and banking details and can send spam messages, make unauthorized payments, and alter files on victim devices. Promoted through Telegram Channels, DogeRAT also comes in a premium version (priced at USD 30) that offers capabilities like taking screenshots, stealing images, and acting as a keylogger.
VULNERABILITIES
- CVE-2022-47178 - Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions
- CVE-2023-2952 - XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 that allows denial of service via packet injection or crafted capture file
- CVE-2023-29741 - An issue found in BestWeather v.7.3.1 for Android that allows unauthorized apps to cause an escalation of privileges attack by manipulating the database
EXPLOITS
- CVE-2020-5741 - Plex Unpickle Dict Windows Remote Code Execution
- CVE-2021-2529 - Nagios XI 5.7.5 Remote Code Execution
BREACH
- Credit Card Data Breach: 2023-5-29 - (3e2a69 | 2393) Credit card
Tags: DIB, tlp:green