zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 26, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 26, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity
  • ZeroFox Intelligence Flash Report - Israel-Hamas War: Increased Risk to Brands From Doxxing
  • Winter Vivern Exploits Roundcube Web-mail Servers to Steal Government Emails
  • Data broker / initial-access broker / hacktivist group: KillNet and Team_insane_Pakistan
  • Vulnerabilities: CVE-2023-43615 and CVE-2023-0003
  • Exploits: CVE-2023-21839 and CVE-2023-32315
  • Data Breach: Credit Card Data Breach

ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity

Iranian state-affiliated advanced persistent threat (APT) groups APT33 and APT34 have conducted an increasing number of targeted cyberattacks in recent months. These APTs will likely continue to play a key role in the Israel-Hamas war to support Iran and Hamas’ mis-and disinformation campaigns and other cyber espionage and intelligence operations. The groups have a standing mandate to conduct cyber espionage on behalf of the Iran regime, and it is very likely these groups will mirror or exceed Iran’s operational pace vis-à-vis the conflicts in which Iran finds itself with its near-peer and regional geopolitical rivals.

ZeroFox Intelligence Flash Report - Israel-Hamas War: Increased Risk to Brands From Doxxing

ZeroFox warns of an increase in doxxing incidents tied to an individual or company’s perceived stance on the Israel-Hamas war. Individuals are being doxxed for alleged participation in the glorification of terrorism, defacing posters, or being identified as a member of a politically-motivated group. The public nature of these allegations has resulted in reputational harm to organizations with which the individual is associated, spurring discussion around what should constitute a breach of employment contract or a violation of a company’s organizational policy on such matters.

Winter Vivern Exploits Roundcube Web-mail Servers to Steal Government Emails

Russian hacking group Winter Vivern (TA473) has been exploiting a Roundcube email zero-day in attacks targeting European government entities since October 11, 2023. The group lured targets with emails purporting to be from the Outlook team, which contained malicious SVG documents for remote arbitrary Javascript injection. The Roundcube team issued patches to fix the Stored Cross-Site Scripting (XSS) vulnerability (CVE-2023-5631) on October 16, 2023. The attack only requires victims to open the message, with no other manual actions. Winter Vivern is known to target government entities such as NATO and nations such as India, Italy, Lithuania, Ukraine, and the Vatican through attacks on Zimbra and Roundcube email servers.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-43615:: Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
  • CVE-2023-0003:: A file disclosure bug in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.

EXPLOITS

BREACHES

Tags: DIB, tlp:green