ZeroFox Daily Intelligence Brief - June 28, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 28, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- EncroChat Takedown: Global Arrests and Exposure of Crime Networks
- Researchers Find Technique to Unveil Secret Keys Through LED Power Analysis
- Hacker Breaches Phone-Tracking App LetMeSpy
- Vulnerabilities: CVE-2020-18414 and CVE-2023-3436
- Exploits: CVE-2016-0099 and CVE-2015-2797
- Breaches: Telegram: SunCloudPubl_max[.]7z Botnet Breach and BreachForums/XSS: Bendercraft Data Breach
EncroChat Takedown: Global Arrests and Exposure of Crime Networks
Europol has announced that the dismantling of EncroChat, an encrypted communications tool widely used by organized crime groups, resulted in 6,558 arrests globally (including 197 High Value Targets) and the seizure of EUR 900 million in funds. The successful operation was conducted by a joint investigation team established in 2020 with support from Eurojust and Europol. EncroChat's takedown has prevented incidents of violent attack, murder, corruption, and drug trafficking and provided valuable insights into organized crime.
Researchers Find Technique to Unveil Secret Keys Through LED Power Analysis
Researchers have discovered a video-based cryptanalysis technique to recover secret keys from devices by analyzing LED video footage. The research finds that cryptographic computations affect device power consumption, altering LED brightness. By analyzing the RGB values of the frames, the secret keys can be recovered. The effectiveness of this method was demonstrated through two side-channel timing attacks on a smart card reader and a Samsung Galaxy S8.
Hacker Breaches Phone-Tracking App LetMeSpy
A data breach has compromised messages, email addresses, telephone numbers, call logs, and locations intercepted by popular phone-monitoring app LetMeSpy. This “stalkerware/spouseware” app is marketed for parental control or employee monitoring and stays hidden on a phone’s home screen, making it challenging to detect and remove. The breach package reportedly lists current records for at least 13,000 compromised devices, with call logs and text messages dating back to 2013.
VULNERABILITIES
- CVE-2020-18414 - Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 allows attackers to execute arbitrary code via /index.php?admin-master-webset.
- CVE-2023-3436 - Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
EXPLOITS
- CVE-2016-0099 : MS16-032 Secondary Logon Handle Privilege Escalation
- CVE-2015-2797 : Airties Air5650TT - Remote Stack Overflow
BREACHES
- Telegram: SunCloudPubl_max[.]7z Botnet Breach : 32,957 Records | Email address and password
- BreachForums/XSS: Bendercraft Data Breach : 158,181 Records | Email address and password
Tags: DIB, tlp:green