zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 10, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 10, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukraine Issues Alert on Hackers Employing “Merlin” Framework on State-Attacks
  • China-Linked Hackers Targeted 17 Countries in Cross-Continental Campaign
  • Security-Evading EvilProxy Phishing Campaign Targets 120,000 Microsoft 365 Users
  • Data broker / initial-access broker / hacktivist group: BreachForums user “Black” and ACEH ABOUT HACKED WORLD
  • Vulnerabilities: CVE-2023-38348 and CVE-2023-39006
  • Breaches: Combolist: '636K FRANCE Combolist Email' and 248K_Germany_ComboList_Hq

Ukraine Issues Alert on Hackers Employing “Merlin” Framework on State-Attacks

Ukraine has issued an advisory about impending attacks on state entities via "Merlin," an open-source post-exploitation framework. Freely available on GitHub, the Go-based toolkit used in red team exercises offers diverse features for network compromise. Threat actors exploit it to infiltrate networks through malicious CHM file attachments in phishing emails. Subsequent executions of JavaScript and PowerShell scripts lead to MerlinAgent infection, granting actors unauthorized network access. The advisory noted attribution challenges arising from actors exploiting open-source tools for attacks on government bodies.

China-Linked Hackers Targeted 17 Countries in Cross-Continental Campaign

Hackers tied to China's Ministry of State Security (MSS) conducted attacks across 17 countries in Asia, Europe, and North America between 2021 and 2023. Researchers attributed these actions to the nation-state group RedHotel, linked to Aquatic Panda, Bronze University, and other aliases. The group targets sectors like academia, aerospace, and government, demonstrating a dual mission of intelligence gathering and economic espionage, with a persistent global reach. Its tactics involve exploiting vulnerabilities using security tools and maintaining multi-tiered infrastructure, exemplifying extensive state-sponsored cyber-espionage activity.

Security-Evading EvilProxy Phishing Campaign Targets 120,000 Microsoft 365 Users

The EvilProxy phishing platform is being increasingly used for massive phishing operations, with one such campaign used for sending 120,000 phishing emails to over a hundred organizations to steal Microsoft 365 accounts. EvilProxy provides highly capable “reverse proxy phishing kits” bypassing security measures and account protections, which are primarily targeted at C-suite executives and higher.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-38348 - A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.
  • CVE-2023-39006 - The Crash Reporter (crash_reporter.php) component of OPNsense before 23.7 mishandles input sanitization.

BREACHES

  • Combolist:: '636K FRANCE Combolist Email-Pass.txt' (636,866 Records) | Email address and password
  • Combolist:: '248K_Germany_ComboList_Hq_Fresh.txt' (248,761 Records) | Email address and password

Tags: DIB, tlp:green