zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 08, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 08, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • HC3 Sounds Alarm About Rhysida Ransomware Group
  • North Korean Hackers Breach Top Russian Missile Maker
  • Malicious OpenBullet Configs Used To Target Inexperienced Cybercriminals
  • Data broker / initial-access broker / hacktivist group: NET - WORKER ALLIANCE: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach
  • Vulnerabilities: CVE-2023-39530 and CVE-2023-38956
  • BreachForums: BreachForums/XSS: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach

HC3 Sounds Alarm About Rhysida Ransomware Group

The Health Sector Cybersecurity Coordination Center (HC3) has issued a security alert on Rhysida, a relatively new ransomware group conducting high-impact attacks across various industries. The attacks have spanned North and South America, Western Europe, and Australia, with the greatest impact on the United States, Italy, Spain, and the United Kingdom. Targets include healthcare / public health, education, government, manufacturing, and technology sectors. In the advisory, HC3 has provided IoCs and preventive steps to defend against this group’s attacks.

North Korean Hackers Breach Top Russian Missile Maker

North Korean hackers secretly infiltrated a major Russian missile developer's computer networks for at least five months last year. The hackers, identified as ScarCruft and Lazarus, implanted covert digital backdoors into systems at NPO Mashinostroyeniya, a rocket design bureau near Moscow. Although it's unclear what data was stolen, the breach coincided with Pyongyang's missile program advances. The incident underscores North Korea's willingness to target allies for technology acquisition.

Malicious OpenBullet Configs Used To Target Inexperienced Cybercriminals

Malicious OpenBullet configuration files are being shared on underground forums to bait inexperienced cybercriminals—enabling them to conduct automated credential stuffing attacks, while leaving the criminals themselves susceptible to a variety of attacks. The trojanized files allow attackers to capture screenshots, list files, terminate processes, and steal crypto wallets, credentials, and browser cookies.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-39530 - Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API.
  • CVE-2023-38956 - A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

BREACHES

Tags: DIB, tlp:green