zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 12, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 12, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Chinese Hackers Gained Access to Government Email Accounts
  • Hackers Exploit Windows Kernel Loophole with Malicious Driver Signings
  • Financially Motivated Threat Actor ScarletEel Exploiting AWS for Malicious Activities
  • Data broker / initial-access broker / hacktivist group: Telegram channel 0x_dump and NoName057(16)
  • Vulnerabilities: CVE-2022-39280 and CVE-2022-39294
  • Exploits: CVE-2015-1701 and CVE-2013-6282
  • Breaches: BreachForums/XSS: Corevin Data Breach and Belly Ballot Data Breach

Chinese Hackers Gained Access to Government Email Accounts

Microsoft has disclosed that it mitigated an attack by a China-based threat actor (Storm-0558) that primarily targeted emails in government agencies in Western Europe and focused on espionage, data theft, and credential access. Since May 15, 2023, Storm-0558 gained access to email data from about 25 organizations. Microsoft has completed the mitigation for the attack and notified all impacted customers—no user action is required to address this threat.

Hackers Exploit Windows Kernel Loophole with Malicious Driver Signings

Microsoft blocked code signing certificates used by Chinese hackers to sign and load malicious kernel drivers onto systems. These drivers operate at the highest privilege level, enabling undetectable data exfiltration, persistent stealth, and process termination. Exploiting a policy loophole, threat actors altered the signing dates of drivers using tools like "HookSignTool" and "FuckCertVerify." Although Microsoft revoked these certificates and suspended developer accounts, the risk persists as more exposed or stolen certificates may still exist.

Financially Motivated Threat Actor ScarletEel Exploiting AWS for Malicious Activities

Researchers have discovered that financially motivated threat actor ScarletEel is targeting Amazon Web Services (AWS) to perform various malicious activities. ScarletEel demonstrates a deep understanding of AWS tools, allowing it to infiltrate cloud environments easily. The threat actor engages in activities such as stealing credentials and intellectual property, planting crypto mining software, conducting DDoS attacks, and more.

Threat Activity: Data broker / initial-access broker / hacktivist group

VULNERABILITIES

  • CVE-2022-39280 - dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service.
  • CVE-2022-39294 - An attacker could send a malicious request with an abnormally large Content-Length, which could lead to a panic if memory allocation failed for that request.

EXPLOITS

  • CVE-2015-1701 - Microsoft Windows ClientCopyImage Improper Object Handling
  • CVE-2013-6282 - Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation

BREACHES

Tags: DIB, tlp:green