ZeroFox Daily Intelligence Brief - September 18, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 18, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- DarkGate Popularity Prompts Pause on New User Support
- Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks
- CISA Releases Continuous Diagnostics and Mitigation Program: Identity, Credential, and Access Management (ICAM) Reference Architecture
- Data broker / initial-access broker / hacktivist group: Exploit users opal & soflyaway and Black Hat Forum (BHF) user tonny_gram
- Vulnerabilities: CVE-2023-2848 and CVE-2023-38557
- Exploits: CVE-2020-6418 and CVE-2020-11108
- Breaches: Credit Card Data Breach: Combolist: 'pasteServices.txt' (269,366 Records) and Credit Card Data Breach: 2023-9-16 (399c64 | 2623)
DarkGate Popularity Prompts Pause on New User Support
ZeroFox Intelligence has published a Flash Report on the DarkGate malware, whose resurgence in popularity prompted its founder to discontinue support for new users. ZeroFox assesses that this move is temporary and will lead to a larger number of threat actors deploying this tool, particularly in light of this malware hitting the news cycle. ZeroFox researchers have identified the channels used to market the malware, with the latest updates being promoted exclusively on Exploit.
Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks
Security researchers have observed that financially motivated threat actor UNC3944 (0ktapus, Scatter Swine, and Scattered Spider) is deploying ransomware to enhance the monetization of its operations. The group is working as an affiliate for the ALPHV ransomware crew and works at an “extremely high operational tempo”—primarily targeting business-critical systems and virtual machines across industries.
CISA Releases Continuous Diagnostics and Mitigation Program: Identity, Credential, and Access Management (ICAM) Reference Architecture
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has initiated a new program to help federal civilian departments and agencies integrate their identity and access management capabilities into their ICAM (Identity, Credential, and Access Management) architectures. CISA noted that there was no singular, authoritative, and recognized reference for architecting an ICAM capability across an enterprise before this initiative.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit users opal and soflyaway: Multiple threat actors targeting U.S.-based wireless resellers
- Black Hat Forum (BHF) user tonny_gram: Advertising custom web scraping tool
VULNERABILITIES
- CVE-2023-2848: Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability.
- CVE-2023-38557: This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
EXPLOITS
- CVE-2020-6418: Google Chrome 80 JSCreate Side-Effect Type Confusion
- CVE-2020-11108: Pi-Hole heisenbergCompensator Blocklist OS Command Execution
BREACHES
- Combolist: 'pasteServices.txt': (269,366 Records) | Email address and password
- Credit Card Data Breach:: 2023-9-16 (399c64 | 2623) | Credit card
Tags: DIB, tlp:green