ZeroFox Daily Intelligence Brief - October 14, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 14, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Location of Israeli Festival May Have Been Exposed in Hack Before Hamas Massacre
- ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers
- WhatsApp Refutes Claims of Malicious Forwards Targeting Jewish People
- Data broker / initial-access broker / hacktivist group: Exploit user: AnonGhost Indonesian and Killnet
- Vulnerabilities: CVE-2023-5554 and CVE-2023-5344
- Exploits: CVE-2023-34960 and CVE-2023-31497
- Data Breach: Telegram: '850 LOGS JUNE.rar' Botnet Breach and '788.rar' Botnet Breach
Location of Israeli Festival May Have Been Exposed in Hack Before Hamas Massacre
The location of the southern Israel rave where nearly 300 people were killed was kept secret, leading investigators to suspect Hamas hacked the event organizers' social media accounts. Israel's General Security Service is now looking into possible cyber intrusions. The event, billed as a "journey of unity and love," drew 3,500 attendees and was ambushed by Hamas. One organizer, whose Facebook account he suspected was hacked, reported the issue to authorities after the attack. Invitations did not specify the location; partygoers received location details via WhatsApp shortly before the party took place.
ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers
Threat actors behind ShellBot are exploiting Linux SSH servers with weak management, using hexadecimal IP addresses for infiltration and possibly to evade detection. ShellBot breaches servers via dictionary attacks, facilitating the use of compromised servers for DDoS attacks and cryptocurrency miner delivery. This Perl-based malware employs the IRC protocol for command-and-control (C2) communication. The development indicates that ShellBot continues to remain prevalent in attacks against Linux systems.
WhatsApp Refutes Claims of Malicious Forwards Targeting Jewish People
WhatsApp has refuted claims of cyberattacks through its platform that target Jewish people through forwarded messages as baseless hoaxes. Messages warning of such attacks circulated widely on social media, but the Meta-owned platform clarified they are false. These messages falsely suggested that opening pictures of the conflict, shared as a file named "Seismic Waves CARD," could lead to phone hacking. This misinformation is similar to rumors following an earthquake in Morocco.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- AnonGhost Indonesian:: Targeting entities from Israel in #OP_Israel and #OpIsrahell.
- Killnet:: Planning to attack Discord as the Ukrainian Armed Forces use it to exchange info.
VULNERABILITIES
- CVE-2023-5554:: Lack of TLS certificate verification in log transmission within LINE Client for iOS prior to 13.16.0.
- CVE-2023-5344:: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
EXPLOITS
- CVE-2023-34960: Msf::Exploit::Remote
- CVE-2023-31497: Seqrite Endpoint Security Client (<=7.6) - Local Privilege Escalation
BREACHES
- Telegram: ' 850 LOGS JUNE.rar' Botnet Breach: (33,390 Records) Email Address and Password
- '788.rar' Botnet Breach: (1,868 Records)| Email Address and Password
Tags: DIB, tlp:green