ZeroFox Daily Intelligence Brief - August 25, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 25, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Suspected Chinese Hackers Continue to Exploit Barracuda ESG Zero-Day
- Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
- “Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
- Data broker / initial-access broker / hacktivist group: Cyb3r Drag0nz and BreachForums user AMLO
- Exploits: CVE-2020-1958 and CVE-2020-5902
- Vulnerabilities: CVE-2023-40530 and CVE-2023-39801
- Combolist: '170K COMBOLIST ITALY.txt' and Telegram: 18.07 google.rar'
Suspected Chinese Hackers Continue to Exploit Barracuda ESG Zero-Day
The FBI confirmed through its investigation of the zero-day CVE-2023-2868 exploit in Barracuda Network's ESG appliances that even patched appliances remain vulnerable to continued compromise by suspected Chinese cyber actors. These actors use the flaw to insert diverse malicious payloads into appliances, which can lead to persistent access, email scanning, credential theft, and data exfiltration. All affected ESG appliances should be isolated and replaced immediately.
Whiffy Recon Malware Locates Infected Devices Through WiFi Scans and Google API Abuse
Cybercriminals behind the Smoke Loader botnet are using a new malware variant called Whiffy Recon to locate infected devices via WiFi scanning and Google's geolocation API. The malware, part of the Smoke Loader botnet, targets specific regions using triangulation. Accuracy varies (20-50 meters) due to WiFi access points, and the data is sent to Google's API, then to C2 servers, allowing almost real-time tracking.
“Telekopye” Tool Facilitates Wide-Scale Phishing Campaigns
A new financially-motivated scheme designed by threat actor group "Neanderthals” exploits a widely used Telegram bot named Telekopye to scam victims. Telekopye creates phishing pages from templates, sending URLs to potential victims (referred to as “Mammoths”). The origin of the group is unclear, but Russia seems likely due to language and targeted marketplaces. Attackers target "Mammoths", establish rapport, and send deceptive links via email, SMS, or direct messages. Once payment details are entered on fake gateways, the funds are stolen and laundered through cryptocurrency.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Cyb3r Drag0nz:: Saudi group attacking governmental entities in Malta and Colombia.
- BreachForums user AMLO:: Claims to be selling email credentials of over a thousand Brazilian lawyers.
EXPLOITS
- CVE-2020-1958 -Druid LDAP injection vulnerability.
- CVE-2020-5902 - Traffic Management User Interface (TMUI) RCE vulnerability
VULNERABILITIES
- CVE-2023-40530 - Improper authorization in handler for custom URL scheme issue in 'Skylark' App allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device.
- CVE-2023-39801 - A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting a device to the vehicle's USB plug and play feature.
BREACHES
- Combolist: '170K COMBOLIST ITALY.txt' : A plain text 'combolist' file of various Italian credentials (170,104 Records)| Email address and password
- Telegram: 18.07 google.rar': Botnet Breach (68,010 Records) | Email address and password
Tags: DIB, tlp:green