SAN MATEO, CA, May 27, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Brought to you by NetworkTigers.
Chinese hackers use compromised devices to evade detection
China-backed threat actors are turning to a “vast proxy server network” of virtual private servers and compromised devices to remain hidden while they conduct cyberespionage campaigns. The proxy networks are referred to as operational relay box (ORB) networks and are “administered by independent cybercriminals that provide access to multiple state-sponsored actors (APTs).” The use of ORB networks makes tracking threat actors difficult, as the attacker doesn’t control the infrastructure. Hackers can also “cycle through nodes distributed over a broad geography,” making attribution and detection especially hard. Cybersecurity firm Mandiant has been tracking a number of ORBs, two of which are used by threat actors linked to China. Called ORB3/SPACEHOP and ORB2/FLORAHOX, both use different topologies to obscure activity. Read more.
Individual behind Incognito drug market arrested
Incognito Market, a marketplace for the buying and selling of illicit drugs that has raked in more than $100 million, has been active since 2020. However, a Taiwanese national suspected of running and owning the site has been arrested at New York’s JFK airport. Rui-Sang Lin is accused of making millions of dollars selling cocaine, methamphetamine, fake prescription medications, and potentially deadly fentanyl. Once signed up on the site, drug dealers paid Lin a 5% fee for any transactions that took place. Incognito Market also had its own bank where members could deposit cryptocurrency to keep transactions anonymous. Lin is facing multiple life sentences. Read more.
Threat actors exploit FileZilla and GitHub to spread malware
Recorded Future’s Insikt Group has reported that a “multi-faceted campaign” is underway that abuses services such as GitHub and FileZilla to spread a combination of malware and banking trojans that include Atomic (aka AMOS), Vidar, Lumma (aka LummaC2), and Octo. To trick its victims, the campaign impersonates legitimate software products such as 1Password, Bartender5, and Pixelmator Pro. The activity is tracked as “GitCaught” and, according to Insikt Group, “the presence of multiple malware variants suggests a broad cross-platform targeting strategy, while the overlapping C2 infrastructure points to a centralized command setup — possibly increasing the efficiency of the attacks.” The criminals behind the campaign appear to be Russian and use fake profiles and repositories on GitHub to host fake versions of popular software designed to steal data. Read more.
Healthcare company WebTPA latest to confirm breach
Texas-based company WebTPA, an organization that provides health insurance and benefit plans, has disclosed that it experienced a data breach affecting nearly 2.5 million people. The company has stated that an investigation into a December 2023 security incident “concluded that the unauthorized actor may have obtained personal information between April 18 and April 23, 2023.” This means that eight months elapsed between the breach and the company noticing it. According to the company’s statement, “the information that was impacted may have included name, contact information, date of birth, date of death, Social Security number, and insurance information.” WebTPA says that no improper use of customer data has yet to be detected. Read more.
Hackers exploit Chrome, EoL D-Link bugs
CISA is warning that threat actors are leveraging two security vulnerabilities in D-Link routers and one in Google Chrome. The Chrome flaw, CVE-2024-4761, is an “out of bounds write vulnerability in Chrome’s V8 JavaScript engine that executes JS code in the browser, and its severity rating is high.” The first vulnerability affecting D-Link DIR-600 routers, CVE-2014-100005, is a decade-old cross-site request forgery (CSRF) issue still being exploited. “It allows attackers to hijack administrator authentication requests to the device’s web admin panel, create their own admin accounts, change the configuration, and take control of the device.” The second is CVE-2021-40655, which allows an attacker to “grab the admin’s username and password via a specially crafted request sent to the /getcfg.php page without authentication.” Read more.
UserPro WordPress plugin flaw allows account takeover
UserPro, a WordPress plugin used on more than 20,000 sites, is harboring a flaw in its password reset mechanism that can let unauthenticated users change the passwords of other users. Tracked as CVE-2024-35700, the vulnerability is caused by “improper handling of a ‘secret key’ during the password reset. The function failed to properly verify the key, enabling attackers to exploit this oversight and gain unauthorized access to user accounts.” The flaw exists in all versions of UserPro up to version 5.1.8. A patch released on April 29, 2024, resolves the issues, and all users are urged to update their plugins to at least version 5.1.9 as soon as possible. Read more.
Microsoft Exchange Server flaws allow keylogger deployment
Microsoft Exchange Server exploitations continue to take place, with cybersecurity firm Positive Technologies identifying more than 30 agencies across the public and private sectors that have fallen victim to the deployment of keylogger malware attacks. The attack chain begins with the exploitation of ProxyShell flaws that were patched in 2021. After successful exploitation, a threat actor can “bypass authentication, elevate their privileges, and carry out unauthenticated, remote code execution.” Positive Technologies cannot attribute the campaign to a specific threat actor at this time. Attacks thus far have targeted organizations in Russia, the UAE, Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, and Lebanon. Users should update their instances of Microsoft Exchange Server to the latest version immediately. Read more.
Ivanti Endpoint Manager critical security flaws fixed
Multiple exploitable security flaws within Ivanti’s Endpoint Manager have been patched by the company. Ten vulnerabilities have been addressed in total, with six of them relating to “SQL injection flaws that allow an unauthenticated attacker within the same network to execute arbitrary code.” The other four are similar, “with the only change being that they require the attacker to be authenticated.” Ivanti states that no flaws have been exploited in the wild, nor were they “introduced into our code development process maliciously.” Users of Endpoint Manager should update immediately, as attackers are sure to jump at the opportunity to take advantage of those slow to patch. Read more.
US to bolster healthcare cyber resilience
In light of recent attacks on major healthcare industry organizations, the Advanced Research Projects Agency for Health (ARPA-H) pledged $50 million to “bring together hospital IT staff, equipment managers, and cybersecurity experts to create software that helps hospitals become cyber-resilient.” The Biden administration created ARPA-H for “investing in breakthrough technologies in the medical and healthcare field.” The Universal Patching and Remediation for Autonomous Defense (Upgrade) program is designed to automate cybersecurity through a platform that can “adapt to any hospital environment across a wide array of common devices.” It is meant to allow providers to focus on patient care as opposed to cyber threats. It aspires to accommodate the diversity between hospital systems and the care they provide to lessen the delays in response time that leave devices and information exposed to attack. Read more.
Hotel check-in computers host leaky spyware
A consumer-grade spyware app called pcTattletale has been found on the check-in systems of at least three Wyndham-owned hotels in the US. pcTattletale “allows whoever controls it to remotely view the target’s Android or Windows device and its data from anywhere in the world.” A bug within the spyware itself, however, makes the screenshots of customer data it takes visible to anyone who understands how the flaw works well enough to exploit it. Able to run “invisibly” in the background, the spyware cannot be detected. The software is marketed as a way to monitor employees, and it is not yet known if it was installed accidentally or intentionally by hotel owners. Apps such as pcTattletale are often referred to as “stalkerware” because they can be used to track people without their knowledge or consent. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles brought to you by NetworkTigers
