Industry News
State-Sponsored Hackers Exploit Palo Alto Networks Zero-Day to Breach Networks
A critical zero-day vulnerability (CVE-2024-3400) in Palo Alto Networks firewalls has been exploited by suspected state-sponsored hackers since March 26 to breach internal networks, steal data, and credentials. The attackers installed a custom Python backdoor named 'Upstyle' to execute commands on compromised devices and pivot to internal networks. Volexity, who discovered the zero-day, believes the attackers are highly likely to be state-sponsored based on the resources required and the capabilities displayed.
LG Smart TV Vulnerabilities Allow Root Access and Command Injection
Researchers discovered vulnerabilities in LG webOS on smart TVs that enable authorization bypass and root access. The flaws, CVE-2023-6317 through CVE-2023-6320, impact webOS versions 4.9.7 to 7.3.1 and were patched in March 2024. Exploitation allows gaining elevated privileges and running arbitrary commands, potentially impacting over 91,000 internet-exposed devices primarily in South Korea, Hong Kong, and the U.S.
Raspberry Robin Malware Evolves to Use Highly Obfuscated Windows Script Files for Initial Infection
The Raspberry Robin Windows worm has updated its infection chain to deliver payloads via heavily obfuscated Windows Script Files (WSF). These scripts implement robust anti-analysis and virtual machine detection capabilities to evade security controls. The malware establishes device integrity checks before downloading its DLL payload, adds Microsoft Defender exclusions, and restarts execution to break debugger sessions.
GitHub Repositories Abused to Spread Keyzetsu Malware
Threat actors are using GitHub automation features and malicious Visual Studio projects to distribute a new variant of the Keyzetsu clipboard-hijacking malware, targeting cryptocurrency payments. The attackers create GitHub repositories with names optimized for search rankings and artificially boost their popularity using automated commits and fake accounts. Users downloading files from these repositories are infected with malware hidden within Visual Studio project files, which is stealthily executed during the build process.
Metasploit Meterpreter Installed via Vulnerable Redis Servers
Attackers are targeting misconfigured and outdated Redis 3.x servers to install Metasploit Stager malware and the PrintSpoofer privilege escalation tool. The Stager downloads the memory-resident Meterpreter backdoor from a C&C server, providing ongoing access. Organizations running Redis should update to the latest version, restrict external access to servers, and use endpoint protection to detect and block the malware.
AI & Security
Cybercrime Group Uses Likely AI Script to Load Info Stealer
Proofpoint researchers identified TA547 targeting German organizations with an email campaign delivering Rhadamanthys malware, an information stealer. The actor appeared to use a PowerShell script suspected to be generated by a large language model (LLM) to load the malware into memory without writing it to disk. While LLMs can assist threat actors, the potentially LLM-generated code did not change the malware's functionality or impact defenses against it.