ZeroFox Daily Intelligence Brief - August 08, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 08, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- HC3 Sounds Alarm About Rhysida Ransomware Group
- North Korean Hackers Breach Top Russian Missile Maker
- Malicious OpenBullet Configs Used To Target Inexperienced Cybercriminals
- Data broker / initial-access broker / hacktivist group: NET - WORKER ALLIANCE: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach
- Vulnerabilities: CVE-2023-39530 and CVE-2023-38956
- BreachForums: BreachForums/XSS: MyFitnessPal Data Breach and BreachForums/XSS: Lifeboat Data Breach
HC3 Sounds Alarm About Rhysida Ransomware Group
The Health Sector Cybersecurity Coordination Center (HC3) has issued a security alert on Rhysida, a relatively new ransomware group conducting high-impact attacks across various industries. The attacks have spanned North and South America, Western Europe, and Australia, with the greatest impact on the United States, Italy, Spain, and the United Kingdom. Targets include healthcare / public health, education, government, manufacturing, and technology sectors. In the advisory, HC3 has provided IoCs and preventive steps to defend against this group’s attacks.
North Korean Hackers Breach Top Russian Missile Maker
North Korean hackers secretly infiltrated a major Russian missile developer's computer networks for at least five months last year. The hackers, identified as ScarCruft and Lazarus, implanted covert digital backdoors into systems at NPO Mashinostroyeniya, a rocket design bureau near Moscow. Although it's unclear what data was stolen, the breach coincided with Pyongyang's missile program advances. The incident underscores North Korea's willingness to target allies for technology acquisition.
Malicious OpenBullet Configs Used To Target Inexperienced Cybercriminals
Malicious OpenBullet configuration files are being shared on underground forums to bait inexperienced cybercriminals—enabling them to conduct automated credential stuffing attacks, while leaving the criminals themselves susceptible to a variety of attacks. The trojanized files allow attackers to capture screenshots, list files, terminate processes, and steal crypto wallets, credentials, and browser cookies.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- NET - WORKER ALLIANCE:: Threatened to attack Russian payments-services company Qiwi
- TeAm UcC OpErAtioNs:: Attacking airports and governmental bodies in Indonesia
VULNERABILITIES
- CVE-2023-39530 - Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API.
- CVE-2023-38956 - A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
BREACHES
- BreachForums/XSS: MyFitnessPal Data Breach - (49,043,906 Records) Email address and password
- BreachForums/XSS: Lifeboat Data Breach - (9,293,473 Records) Email address and password
Tags: DIB, tlp:green