ZeroFox Daily Intelligence Brief - September 27, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 27, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Sony Investigates Hacking Claims
- U.K. Information Commissioner Warns About Risks to Domestic Abuse Victims from Data Breaches
- Hackers Lure Organizations through Fake Red Cross Blood Drive Emails
- Data broker / initial-access broker / hacktivist group: BreachForums user boole3an & XSS user zetaboy
- Vulnerabilities: CVE-2023-4259 and CVE-2022-4318
- Exploits: CVE-2021-3129 and CVE-2021-40865
- Breaches: Combolist: 'PRIVATE DOMAIN COMBO'
Sony Investigates Hacking Claims
Sony is reportedly investigating claims of a recent cyberattack, with different hacker groups trying to claim responsibility for the attack. RansomedVC claims to have stolen 260 GB data and is supposedly selling the data because of Sony's refusal to pay a ransom of USD 2.5 million. Another actor, MajorNelson, refuted RansomedVC's claims and released its own purportedly stolen samples. Sony confirmed the investigation but has not yet disclosed additional details.
EvilBamboo Targets Tibetan, Uyghur, and Taiwanese Communities for Exploitation
Threat actor group EvilBamboo is targeting Tibetan, Uyghur, and Taiwanese individuals and organizations with the aim to collect sensitive data. The group has been active since 2019 and employs Android malware like ActionSpy and PluginPhantom. Three new Android espionage tools—BADBAZAAR, BADSIGNAL, and BADSOLAR—have been attributed to this group. Distribution methods include APK forums, fake websites, ads, messaging apps, and fake profiles. While BADBAZAAR targets Uyghur and Muslim individuals, BADSOLAR primarily focuses on Tibetan-themed apps, with both incorporating malicious capabilities from remote servers.
Hackers Lure Organizations through Fake Red Cross Blood Drive Emails
A new APT group named "AtlasCross" has surfaced, targeting organizations via phishing lures pretending to be from the American Red Cross to distribute backdoor malware. The attacks involve fake emails relating to a "September 2023 Blood Drive," using macro-enabled Word documents to deliver the malware. Two previously undocumented trojans, DangerAds and AtlasAgent, have been linked to this group. The attackers are highly sophisticated and elusive and employ custom trojans with narrow targeting and discreet infection methods, making it challenging to ascertain their origin.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user boole3an: Selling an alleged “email reset exploit for two popular email providers” for USD 15,000 to 20,000.
- XSS user zetaboy: Selling alleged unauthorized access to an African bank, claiming to have access to all machines (including ATMs).
VULNERABILITIES
- CVE-2023-4259: Cwo potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
- CVE-2022-4318: A vulnerability in cri-o allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
EXPLOITS
- CVE-2021-3129: Ignition Remote Code Execution.
- CVE-2021-40865: Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server.
BREACHES
- Combolist: 'PRIVATE DOMAIN COMBO': (137,956 Records)
Tags: DIB, tlp:green