zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 31, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 31, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Western Europe: A Regional Assessment by ZeroFox
  • CISA Releases Malware Analysis Reports on Remote Execution Vulnerability in Barracuda Email Gateway
  • New Android Malware Uses OCR to Steal Data and Cryptocurrency Wallets
  • Data broker / initial-access broker / hacktivist group: Exploit: Actor Auctioning RDP Access To Unnamed Australian Boat Dealer and Actor Auctioning RDP Access To U.S.-Based Media & Internet Company
  • Vulnerabilities: CVE-2023-3390 and CVE-2023-28130
  • Exploits: CVE-2013-3763
  • Breaches: Credit Card Data Breach and CafePress Data Breach

Western Europe: A Regional Assessment by ZeroFox

Chinese political, economic, and cyber retaliation pose critical threats to European economic security as the continent diversifies its industrial sector. Europe has identified clean energy, advanced technology, and agriculture as key industries it will need to develop going forward. These industries will require greater cyber protections, as they aim to exclude trading with China while also diversifying supply chains away from China. China and Russia, in turn, are likely to increase cyber espionage and disruption campaigns.

CISA Releases Malware Analysis Reports on Remote Execution Vulnerability in Barracuda Email Gateway

CISA has published three reports on malware variants linked to CVE-2023-2868, a remote command injection vulnerability affecting Barracuda Email Security Gateway (ESG). Exploited since October 2022, the bugs relate to various backdoors, including the novel backdoor SUBMARINE—which allows unauthorized access, persistence, root privileges and lateral movement. Threat actors also use phishing emails to deliver the Barracuda Exploit Payload, leading to a reverse shell backdoor that connects to their command server to deploy the SEASPY backdoor.

New Android Malware Uses OCR to Steal Data and Cryptocurrency Wallets

A new Android malware strain called CherryBlos uses optical character recognition (OCR) to extract sensitive data from pictures. Distributed through fake social media posts, it steals cryptocurrency wallet credentials and manipulates copied wallet addresses. CherryBlos also displays fake overlays on legitimate apps and employs OCR to identify mnemonic phrases from images—relying on users taking screenshots of recovery phrases.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit: : Actor Auctioning RDP Access To Unnamed Australian Boat Dealer
  • Exploit: : Actor Auctioning RDP Access To U.S.-Based Media & Internet Company

VULNERABILITIES

  • CVE-2023-3390 - A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c.
  • CVE-2023-28130 - Local user may lead to privilege escalation using Gaia Portal hostnames page.

EXPLOITS

BREACHES

Tags: DIB, tlp:green