ZeroFox Daily Intelligence Brief - September 19, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 19, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- SprySOCKS Linux Malware Employed in Cyber Espionage Campaign
- Payment Card-Skimming Campaign Expands to Target Websites in North and Latin America
- Microsoft Mitigates Exposure of Internal Information via Overly-Permissive SAS Token
- Data broker / initial-access broker / hacktivist group: Exploit user ppfuck & XSS user TOP G
- Vulnerabilities: CVE-2023-42399 and CVE-2023-41599
- Exploits: CVE-2020-27950 and CVE-2020-8950
- Breaches: Combolist: '113.txt'
SprySOCKS Linux Malware Employed in Cyber Espionage Campaign
Chinese espionage group "Earth Lusca" has targeted government agencies worldwide using a new Linux backdoor called "SprySOCKS.” The backdoor appears to originate from Trochilus, an open-source Windows malware, with adaptations for Linux. Earth Lusca has primarily targeted government entities in Southeast Asia, Central Asia, and the Balkans. SprySOCKS establishes persistence on victim systems, and its capabilities include system data collection, interactive shell, network listing, SOCKS proxy management, and basic file operations. Organizations are advised to apply all available security updates to prevent initial compromise.
Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks
A Chinese-speaking threat actor tracked as "Silent Skimmer" has expanded its credit-card skimming attacks from the Asia/Pacific region to include North and South America. The group exploits vulnerabilities in web applications to gain access to various organizations across different sectors, and targets payment pages to steal card numbers from online shoppers. Researchers noted the threat actor's use of legitimate open-source tools and geolocation-based command-and-control infrastructure. The group has exploited vulnerabilities such as CVE-2019-18935, also used by other actors like "Hafnium" and "XE Group.”
Microsoft Mitigates Exposure of Internal Information via Overly-Permissive SAS Token
Microsoft has remediated an incident involving an employee sharing an overly-permissive Shared Access Signature (SAS) token for an internal storage account while contributing to open-source AI learning models. This led to the exposure of internal data contained in that storage account, including backups of two former employees’ workstation profiles and internal Microsoft Teams messages of the two employees. Microsoft reported that no customer data was exposed and no other internal services were put at risk because of this issue. No customer action is required in response to this incident.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user ppfuck: Auctioning network access bundle to more than 500 different companies worldwide.
- XSS user TOP G: Advertising custom web scraping tool
VULNERABILITIES
- CVE-2023-42399: Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.
- CVE-2023-41599: An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
EXPLOITS
- CVE-2020-27950: XNU Kernel Memory Disclosure in Mach Message Trailers
- CVE-2020-8950: AMD User Experience Program Launcher from Radeon Software Privilege Escalation.
BREACHES
- Combolist: '113.txt': (3,235,736 Records) | Email address and password
Tags: DIB, tlp:green