zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 26, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 26, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Xenomorph Android Malware Targets Customers of 30 U.S. Banks
  • EvilBamboo Targets Tibetan, Uyghur, and Taiwanese Communities for Exploitation
  • Phishing Campaign Targets Ukrainian Military Entities with Drone Manuals
  • Data broker / initial-access broker / hacktivist group: Exploit user comedy_club & Exploit user levieux100
  • Vulnerabilities: CVE-2023-31445 and CVE-2023-20588
  • Breaches: BreachForums: Combolist: '130K COMBOLIST EDU.txt' and Credit Card Data Breach

Xenomorph Android Malware Targets Customers of 30 U.S. Banks

The cybercriminals behind banking trojan Xenomorph have shifted their focus to customers of more than two dozen prominent American banks, after previously attacking European entities for over a year. The latest campaign employs phishing web pages for distribution. Malware samples revealed additional features targeting cryptocurrency wallets, including those linking to Binance and Coinbase. The malware also boasts a sophisticated Automatic Transfer System (ATS) framework for transferring funds to attacker-controlled devices, including various modules, to allow control over compromised devices and prevent them from entering sleep mode.

EvilBamboo Targets Tibetan, Uyghur, and Taiwanese Communities for Exploitation

Threat actor group EvilBamboo is targeting Tibetan, Uyghur, and Taiwanese individuals and organizations with the aim to collect sensitive data. The group has been active since 2019 and employs Android malware like ActionSpy and PluginPhantom. Three new Android espionage tools—BADBAZAAR, BADSIGNAL, and BADSOLAR—have been attributed to this group. Distribution methods include APK forums, fake websites, ads, messaging apps, and fake profiles. While BADBAZAAR targets Uyghur and Muslim individuals, BADSOLAR primarily focuses on Tibetan-themed apps, with both incorporating malicious capabilities from remote servers.

Phishing Campaign Targets Ukrainian Military Entities with Drone Manuals

Ukrainian military entities are targets of a phishing campaign that employs drone manuals as bait to deliver the Go-based open-source post-exploitation toolkit known as Merlin. The campaign, dubbed STARK#VORTEX, initiates with a HTML Help (CHM) file purporting to be a manual. Once opened, it executes a malicious JavaScript file, triggering code to fetch an obfuscated binary from a remote server. This payload establishes communication with a command-and-control server to seize control over the system. The lure documents effectively bypass detection, as they mimic help-themed content that a victim might expect in such files.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-31445: Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability.
  • CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.

BREACHES

Tags: DIB, tlp:green