ZeroFox Daily Intelligence Brief - September 25, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 25, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Stealthy Threat Actor observed Targeting Southeast Asian government
- National Student Clearinghouse Data Breach Affects 890 schools
- CISA Collaborates with NFL to Enhance Cyber Defenses Against Attacks
- Data broker / initial-access broker / hacktivist group: Exploit users: 1337sh[.]com & memeos
- Vulnerabilities: CVE-2023-41872 and CVE-2023-41949
- Exploits: CVE-2021-27342 and CVE-2021-35616
- Breaches: LeakBase: tecnovagroup.com Breach and Credit Card Data Breach
Stealthy Threat Actor observed Targeting Southeast Asian government
The Gelsemium APT group was observed targeting a Southeast Asian government over six months between 2022 and 2023. Researchers identify Gelsemium as a "quiet" cyberespionage group, skilled at evading detection. The sample in the recent attack was used to monitor HTTP requests, deploy commands via malicious cookies, upload further files, launch apps and proxy connections to additional systems.The proxy function demonstrates the group’s intentions to use compromised systems as a gateway to other systems within the network.
National Student Clearinghouse Data Breach Affects 890 schools
The National Student Clearinghouse (degree verification and student enrollment verification service across North America) has disclosed that it received a notice about a cybersecurity issue with MOVEit Transfer. Unauthorized access to certain files occurred around May 30, 2023. These files contained personal data, including names, dates of birth, Social Security numbers, contact information, student ID numbers, and certain school records such as enrollment, degrees, and course-related data. The organization claimed that it was working with experts and law-enforcement officials and that affected individuals will receive two years of free identity-monitoring services.
CISA Collaborates with NFL to Enhance Cyber Defenses Against Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) collaborated with the National Football League (NFL), Allegiant Stadium, and Super Bowl LVIII partners in a tabletop exercise in Las Vegas to assess cybersecurity response capabilities for the upcoming Super Bowl LVIII event. Over 100 participants, including NFL representatives and government officials, gathered to review and discuss plans for defending against, responding to, and recovering from a cyberattack during the event. It marked CISA's tenth year of collaborating with the NFL on such exercises to ensure event safety.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user 1337sh[.]com: Advertising network access to Japanese construction company.
- Exploit user: memeos Selling malware loader dubbed “Buer”.
VULNERABILITIES
- CVE-2023-41872: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.
- CVE-2023-41949: Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Avirtum iFolders plugin <= 1.5.0 versions.
EXPLOITS
- CVE-2021-27342: D-Link Router Timing Side-Channel Attack Vulnerability Writeup.
- CVE-2021-35616: Oracle Transportation Management Privilege Escalation
BREACHES
- LeakBase: tecnovagroup.com Breach: (168024 Records)
- Credit Card Data Breach: 2023-9-24 (773dea | 3133)
Tags: DIB, tlp:green