zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 13, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 13, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Swiss Government: Russia-Based DDoS Attacks Causing Access Problems
  • Researchers Report First Instance of Automated SaaS Ransomware Extortion
  • Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable
  • Vulnerabilities: CVE-2023-2876, CVE-2023-33986, and CVE-2023-32115
  • Exploits: CVE-2000-0884, CVE-2019-13623, and CVE-2017-12542
  • Breaches: BreachForums/XSS: Forex Investor Data Breach, Telegram: 'logs-a1.7z' Botnet Breach, and BreachForums/XSS: ViewPointS Data Breach

Swiss Government: Russia-Based DDoS Attacks Causing Access Problems

The Swiss government has disclosed access problems on various Federal Administration websites and services due to DDoS (distributed denial of service) attacks by a pro-Russia hacktivist known as “NoName.” ZeroFox Intelligence notes that NoName has been conducting numerous DDoS attacks on entities in countries seen to be against Russia in the ongoing geopolitical scenario, including government bodies and private companies in France, Japan, Italy, Poland, Slovakia, Estonia, and Ukraine.

Researchers Report First Instance of Automated Software-as-a-Service (SaaS) Ransomware Extortion

The 0mega ransomware group conducted a novel automated attack on a company's SharePoint Online environment without using a compromised endpoint. It gained access through an insecure admin account and then escalated privileges to perform automated exfiltration of sensitive data from the victim's SharePoint libraries. A recent study revealed that over half of the ransomware attacks in the past year targeted SaaS data, with a surge of 300% since March 2023.

Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

A malware obfuscation engine called BatCloak is being increasingly used by criminals to deploy various malware strains. The engine allows threat actors to load obfuscated batch files containing different malware families and exploits; nearly 80 percent of the 784 discovered artifacts were reportedly undetected by security solutions.

VULNERABILITIES

  • CVE-2023-2876 - Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).
  • CVE-2023-33986 - SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
  • CVE-2023-32115 - An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.

EXPLOITS

BREACHES

Tags: DIB, tlp:green