ZeroFox Daily Intelligence Brief - July 6, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 6, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Suspected Key Figure of Notorious Cybercrime Group OPERA1ER Arrested
- Teams Exploit Tool Released by Member of U.S. Navy's Red Team
- Japanese Port of Nagoya’s Operations Affected by Ransomware Attack
- Data broker / initial-access broker / hacktivist group: Türk Hack Team and Solntsepek
- Vulnerabilities: CVE-2023-2156 and CVE-2022-41854
- Exploits: CVE-2007-3898 and CVE-2018-19246
- Breaches: Credit Card Data Breach: Credit Card Data Breach: 2023-7-4 and BreachForums/XSS: Coinmama Data Breach
Suspected Key Figure of Notorious Cybercrime Group OPERA1ER Arrested
A joint law-enforcement operation has led to the arrest of a key member of the OPERA1ER cybercrime group, which has targeted mobile banking services and financial institutions in Africa, Asia, and Latin America. OPERA1ER (also known as NX$M$, DESKTOP Group, and Common Raven) has stolen over USD 11 million via malware, phishing, and large-scale Business Email Compromise (BEC) scams over several years.
Teams Exploit Tool Released by Member of U.S. Navy's Red Team
A member of the U.S. Navy's red team has developed a tool called TeamsPhisher, which exploits an unresolved security flaw in Microsoft Teams. This flaw allows attackers to bypass restrictions for incoming files from external users by masquerading as internal users. Organizations are advised to disable communications with external tenants and implement trusted domain allow-lists until Microsoft resolves the issue.
Japanese Port of Nagoya’s Operations Affected by Ransomware Attack
The Port of Nagoya, Japan's largest and busiest port, reportedly fell victim to a LockBit ransomware attack that targeted the Nagoya Port Unified Terminal System—resulting in the disruption of container-terminal operations. The port remained affected for two days, which had a significant financial impact and disrupted the flow of goods to and from Japan; however, all services have since been restored.
THREAT ACTIVITY: INITIAL-ACCESS & DATA BROKERS
- Türk Hack Team: Claims to have attacked Swedish airport-operator websites Swedavia[.]se and Lfv[.]se, as part of #OpSweden.
- Pro-Russia group Solntsepek: Claims to have breached the State Statistics Service of Ukraine, erased databases, and leaked internal documentation
VULNERABILITIES
- CVE-2023-2156 - A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol.
- CVE-2022-41854 - Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks.
EXPLOITS
- CVE-2007-3898 - Microsoft Windows Server 2000/2003 - Recursive DNS Spoofing
- CVE-2018-19246 - PHP-Proxy 5.1.0 Local File Inclusion
BREACHES
- Credit Card Data Breach: 2023-7-4 (bc56b1 | 2675) Credit card
- BreachForums/XSS: Coinmama Data Breach (212,170 Records) Email address and password
Tags: DIB, tlp:green