ZeroFox Daily Intelligence Brief - September 21, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 21, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- FBI and CISA Release Advisory on Snatch Ransomware
- Finnish Customs Service Brings Down Tor Web Server of Narcotics Site
- T-Mobile Patches Bug that Allowed Users to View Other People’s Account Information
- Data broker / initial-access broker / hacktivist group: SiegedSec & NoName057(16)
- Vulnerabilities: CVE-2023-40260 and CVE-2023-42322
- Exploits: CVE-2020-3992 and CVE-2020-25213
- Breaches: BreachForums/WWHClub:SberPravo Data Breach and BreachForums: Zurich Insurance Group Data Breach
FBI and CISA Release Advisory on Snatch Ransomware
U.S. authorities have released an advisory on the Snatch ransomware group—a versatile ransomware-as-a-service (RaaS) operation known to change their tactics according to current criminal trends and success stories of other ransomware operations. Snatch targets diverse critical infrastructure sectors (including the defense industrial base, food and agriculture, and information technology) in attacks leading to data exfiltration and “double extortion.” ZeroFox Intelligence has detected close to 60 victims of this ransomware in the past year, over 55 percent of which are based in North America.
Finnish Customs Service Brings Down Tor Web Server of Narcotics Site
The Finnish Customs service, in cooperation with foreign authorities, has seized the “Piilopuoti” web server and its contents. The web server was operational in the Tor network since 2022 and hosted a site that sold narcotics smuggled to Finland from abroad. While the criminal investigation is still underway, the Finnish Customs and its international cooperation partners have not divulged further information on the matter.
T-Mobile Patches Bug that Allowed Users to View Other People’s Account Information
T-Mobile fixed an issue resulting from a “technology update” glitch after several customers reported on Reddit and X (formerly Twitter) that they were able to see other users’ account data—including credit balance, purchase history, credit card information, and home address. The company claimed that there was no cyberattack or breach incident and that the breach involved limited account information for fewer than 100 customers.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- SiegedSec: Posted a 20 GB database allegedly stolen from European investment platform PeerBerry
- NoName057(16): DDoS attacking Canadian airports
VULNERABILITIES
- CVE-2023-40260: EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA requirement if the first factor (username and password) is known.
- CVE-2023-42322: Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
EXPLOITS
- CVE-2020-3992: VMware ESXI OpenSLP.
- CVE-2020-25213: Unauthenticated Arbitrary File Upload leading to RCE.
BREACHES
- BreachForums/WWHClub:SberPravo Data Breach: (72,152 Records) | Email address, date of birth, phone numbers, name, physical address, and usernames
- BreachForums: Zurich Insurance Group Data Breach: (757,446 Records)|Name, email address, and date of birth.
Tags: DIB, tlp:green