zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 23, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 23, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hacker Group Abuses Software Trust Model to Disguise Malware
  • Akira Ransomware Compromise Enterprise VPNs to Backdoor Data Transmission
  • Native Xloader Malware Highlights Increased Targeting of MacOS Devices
  • Data broker / initial-access broker / hacktivist group: Cʏʙᴇʀ Cᴀᴛ and Mysterious team Bangladesh
  • Exploits: CVE-2020-0796 and CVE-2020-11651
  • Vulnerabilities: CVE-2023-4404 and CVE-2023-40144
  • Leakbase: Everyshop Data Breach and Bootskram Data Breach Botnet Breach

Hacker Group Abuses Software Trust Model to Disguise Malware

Hacker group CarderBee has been observed exploiting trusted software signing models from reputable vendors to disguise malware. The attackers hijacked the software update supply chain of “Cobra DocGuard” with malicious files—coupled with legitimate software trust signatures—to deliver the PlugX (Korplug) backdoor on victim networks. The implant granted a covert backdoor on compromised platforms, enabling additional payloads, command execution, keystroke captures, file listing, and process monitoring. Researchers noted the attack's sophistication, which suggested a highly skilled operator.

Akira Ransomware Compromise Enterprise VPNs to Backdoor Data Transmission

Akira ransomware has been targeting enterprise VPNs to breach corporate networks. In March 2023, Akira added a Linux encryptor to target VMware ESXi virtual machines. Akira exploits compromised VPN accounts to access backdoors to data transmission. While it is not clear if Akira brute-forced or purchased credentials, security researchers suspect an unknown vulnerability exists within these products, which can be exploited in the absence of additional security features like multi-factor authentication.

Native Xloader Malware Highlights Increased Targeting of MacOS Devices

A new Mac-focused variant of the XLoader infostealer has surfaced in the wild, indicating improved ability of hackers to target macOS systems. The file "OfficeNote.dmg" appeared on VirusTotal several times in July 2023, harboring an updated XLoader version tailored to steal Mac user credentials. Previous cross-platform malware efforts were ineffective. But with a natively written C and Objective C version, Macs are becoming attractive targets with cybercriminals forming dedicated teams for Mac malware development.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Cʏʙᴇʀ Cᴀᴛ:: Claims to have breached the website of Multilateral Fund for the European West African Economic and Monetary Area (EWEMF).
  • Mysterious team Bangladesh:: Threatens to attack France's critical infrastructure in relation to the Niger crisis

EXPLOITS

VULNERABILITIES

  • CVE-2023-4404 - The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation.
  • CVE-2023-40144 - OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings.

BREACHES

  • Leakbase:: Everyshop Data Breach (67,759 Records) | Email address, company name, gender, geographic location, name, national id, nationality, phone number, physical address
  • Leakbase: Bootskram: Bootskram Data Breach Botnet Breach (9,008 Records) | Name, physical address, and email address

Tags: DIB, tlp:green