zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 21, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 21, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Interpol Operation Disrupts Thousands of Illicit Cyber Networks in Africa
  • WinRAR Patches Remote Code Execution Flaw
  • Malicious Campaign Targets Victims Through Malware Hidden in Image Files
  • Data broker / initial-access broker / hacktivist group: Exploit user “Roblette”
  • Exploits: CVE-2019-19781 and CVE-2017-11317
  • Vulnerabilities: CVE-2023-30861 and CVE-2022-24989
  • Credit Card Data Breach and Combolist: '260K.txt'

Interpol Operation Disrupts Thousands of Illicit Cyber Networks in Africa

INTERPOL and AFRIPOL conducted a joint operation in 25 African countries, leading to the arrest of 14 suspected cybercriminals and the identification of 20,674 suspicious cyber networks. These networks, responsible for over USD 40 million in financial losses, were targeted in the four-month Africa Cyber Surge II initiative. The operation comes amidst rising digital insecurity in the region.

WinRAR Patches Remote Code Execution Flaw

The widely-installed WinRAR app was recently patched in Update 6.23 to address the high-severity CVE-2023-40477 flaw, which allowed remote arbitrary code execution through specially crafted RAR files. The flaw was reported by a security researcher in June 2023 and was linked to the improper handling of recovery volumes and data validation, allowing hackers to access memory beyond buffers. Users must interact with disguised malicious content to be vulnerable.

Malicious Campaign Targets Victims Through Malware Hidden in Image Files

A recent report by cybersecurity researchers highlights the use of an updated WoofLocker toolkit for tech support scams. WoofLocker, also known as 404Browlock, redirects users through compromised sites which disguise malware through JavaScript and PNG image-based steganography. Active for years and known to target adult sites, it gains control over devices to trick victims into seeking help from unreliable sources. The operation has been linked to operators from Bulgaria and Ukraine.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

EXPLOITS

  • CVE-2019-19781 - Citrix Application Delivery Controller / Gateway Remote Code Execution
  • CVE-2017-11317 - Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization

VULNERABILITIES

  • CVE-2023-30861 -This issue has been fixed in versions 2.3.2 and 2.2.5 of Flask, a lightweight WSGI web application framework.
  • CVE-2022-24989 - TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation. .

BREACHES

Tags: DIB, tlp:green