ZeroFox Daily Intelligence Brief - August 18, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 18, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Criminals Share Malicious Android APKs that Evade Security Measures
- Russian Threat Actors Target Ministries of Foreign Affairs of NATO-Aligned Countries
- Researchers Demonstrate Inconspicuous Exploit in iOS devices Through Fake Airplane Mode
- Data broker / initial-access broker / hacktivist group: BreachForums user “c0wb0y5”and Mysterious Team Bangladesh
- Vulnerabilities: CCVE-2023-33934 and CVE-2023-4364
- Leakbase: CompAndSave Data Breach and Mosquiteras Data Breach
Criminals Share Malicious Android APKs that Evade Security Measures
Threat actors are increasingly distributing malicious Android APKs with mechanisms to make them resistant to decompilation. This evades security tool-detection and hampers research, ultimately delaying understanding of Android malware. Tactics used include using unsupported or tweaked compression algorithms, filenames exceeding 256 bytes, corrupted AndroidManifest.xml files, and malformed String Pools to crash analysis tools. These apps are not on Google Play; security researchers have listed the hashes associated with some malicious APKs for third-party app users to find and remove.
Russian Threat Actors Target Ministries of Foreign Affairs of NATO-Aligned Countries
An ongoing cyber-espionage campaign with suspected Russian links targets foreign-affairs ministries of NATO-aligned countries via PDFs with diplomatic baits. Initial infection involves a PDF attachment named "Farewell to Ambassador of Germany," containing JavaScript code to trigger a multi-stage Duke malware deployment sequence. The Duke malware variant is linked to APT29 (Midnight Blizzard / Cozy Bear). The campaign uses collaborative chat software Zulip as a command-and-control tool, concealing their actions within legitimate web traffic.
Researchers Demonstrate Inconspicuous Exploit in iOS devices Through Fake Airplane Mode
Security researchers have detailed an innovative post-exploit persistence technique for iOS 16, enabling ongoing device access even when users believe the devices are offline. The method involves tricking victims by creating a fake Airplane Mode UI, maintaining hidden cellular connectivity for malicious applications while cutting off internet access to other apps. Apple clarified that this technique doesn't exploit a specific vulnerability but demonstrates post-compromise persistence possibilities.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user “c0wb0y5”: : Selling access to client data from Buenos Aires-based BTR Consulting
- Mysterious Team Bangladesh, Systemadminbd Official (BCF), FidzXpoi, and allies:: Continue to target Indian entities, as part of #OpIndia
VULNERABILITIES
- CVE-2023-33934 - Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.
- CVE-2023-4364 - Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page .
BREACHES
- Leakbase/BreachForums:: CompAndSave Data Breach (1,97,405 Records)| Email address, IP address, name, and physical address
- Leakbase: : Mosquiteras Data Breach (1,04,388 Records) | Name, email address, and user activity
Tags: DIB, tlp:green