# 29th September – Threat Intelligence Bulletin

September 29, 2020

https://research.checkpoint.com/2020/29th-september-threat-intelligence-bulletin/

For the latest discoveries in cyber research for the week of 29th September 2020, please download our [Threat Intelligence Bulletin](https://research.checkpoint.com/wp-content/uploads/2020/09/Threat_Intelligence_News_2020-09-29.pdf).

**Top Attacks and Breaches**

- Following last week’s emergency [directive](https://us-cert.cisa.gov/ncas/current-activity/2020/09/18/cisa-releases-emergency-directive-microsoft-windows-netlogon) issued by CISA, Microsoft has [warned](https://www.bleepingcomputer.com/news/microsoft/microsoft-hackers-using-zerologon-exploits-in-attacks-patch-now/) that attackers are actively exploiting the critical Zerologon vulnerability (CVE-2020-1472) to attack Microsoft Windows servers using publicly available PoC exploits.

_Check Point IPS blade provides protection against this threat_ _ (Microsoft Netlogon Elevation of Privilege (CVE-2020-1472))_

- Tyler Technologies, the largest provider of software and technology services to the United States public sector, has suffered a [cyberattack](https://krebsonsecurity.com/2020/09/govt-services-firm-tyler-technologies-hit-in-apparent-ransomware-attack/) most likely involving the RansomExx ransomware. Tyler has [warned](https://www.zdnet.com/article/suspicious-logins-rats-reported-after-ransomware-attack-on-us-govt-contractor/) that its credentials were used for remote access to several of its clients and advised for password reset.
- $150 million have been [stolen](https://securityaffairs.co/wordpress/108771/cyber-crime/kucoin-cryptocurrency-exchange-hack.html) from several hot wallets of the Singapore-based cryptocurrency exchange KuCoin. KuCoin stated that hackers obtained private keys to its wallets, and promised to reimburse affected users and publish the wallet address of the hacker and the list of stolen funds.
- Another DDoS attack hits financial institutions; several Hungarian banks and telecommunication services were [disrupted](https://www.reuters.com/article/hungary-cyber/hungary-hit-by-large-cyber-attack-from-asia-magyar-telekom-idINKBN26H0C5) by a distributed attack originating from servers in Russia, China and Vietnam.
- The network of an unspecified US federal agency has been recently [compromised](https://us-cert.cisa.gov/ncas/analysis-reports/ar20-268a), according to a CISA report. The threat actor behind the attack used compromised O365 credentials to implant malware, evaded the agency’s anti-malware protection and gained persistent access to the network.
- A major data breach in an Indian government COVID-19 tracking app has [exposed](https://www.hackread.com/india-covid-19-surveillance-tool-exposed-user-data/) personal data of more than 8 million citizens. The exposed data included full names, gender, age, residential address, and contact numbers of everyone who had tested COVID-19 positive in the Indian state of Uttar Pradesh.
- Luxottica, the world’s largest eyewear company, has been [hit](https://www.bleepingcomputer.com/news/security/ray-ban-owner-luxottica-confirms-ransomware-attack-work-disrupted/) by a ransomware attack, leading to the shutdown of its operations in Italy and China. Experts suspect the source of the breach was a Citrix ADX controller device, vulnerable to the critical (CVE-2019-19781) flaw.

**Vulnerabilities and Patches**

- Check Point Research has [exposed](https://research.checkpoint.com/2020/instagram_rce-code-execution-vulnerability-in-instagram-app-for-android-and-ios/) a vulnerability (CVE-2020-1895) in the iOS and Android versions of Instagram. The high severity vulnerability resides in the open source JPEG format decoder, Mozjpeg, and could have enabled attackers to access victim’s camera, microphone and other components.

_Check Point SandBlast Mobile provides protection against this threat_

- Cisco Systems has [released](https://threatpost.com/cisco-patches-bugs/159537/) a series of fixes in a wide range of products. Twenty nine of the patched vulnerabilities are rated high severity.
- Google has [released](https://threatpost.com/google-chrome-attack/159466/) a new version of Chrome, fixing ten security flaws.  The successful exploitation of the most severe of these could allow an attacker to execute arbitrary code by getting the victim to visit a specially crafted webpage.
- Apple has [patched](https://securityaffairs.co/wordpress/108809/security/apple-macos-vulnerabilities.html) four vulnerabilities affecting macOS Catalina, High Sierra and Mojave.

**Threat Intelligence Reports**

- Facebook has removed accounts and pages of several [Russian](https://about.fb.com/news/2020/09/removing-coordinated-inauthentic-behavior-russia/), [Chinese and Philippine](https://about.fb.com/news/2020/09/removing-coordinated-inauthentic-behavior-china-philippines/) disinformation networks conducting coordinated inauthentic behavior (CIB). The Chinese [operations](https://techcrunch.com/2020/09/22/facebook-gans-takes-down-networks-of-fake-accounts-originating-in-china-and-the-philippines/) were engaged in US elections and China’s interests in the Philippines and Southeast Asia. The Russian networks were involved in creating factious media entities and amplify their content.
- Microsoft has published that earlier this year it [removed](https://arstechnica.com/information-technology/2020/09/microsoft-boots-apps-used-by-china-sponsored-hackers-out-of-azure/) 18 Azure Active Directory applications that were used by the Chinese APT-40 threat actor group as part of their multistage infection chain.
- Researchers report a Russian speaking threat-actor, OldGremlin, has been linked to at least nine ransomware [attacks](https://thehackernews.com/2020/09/russian-ransomware-hack.html) this year on medical labs, banks, manufacturers, and software developers in Russia. A large Russian medical company hit by the actor received ransom demands of $50K in cryptocurrency.
- Researchers have [exposed](https://thehackernews.com/2020/09/cyberattack-indian-army.html) an ongoing cyber espionage operation against Indian defense units. The operation, active for more than a year, has been attributed to the Pakistani Transparent Tribe APT group.
- CISA and the FBI have [issued](https://www.bleepingcomputer.com/news/security/fbi-warns-of-disinformation-campaigns-about-hacked-voter-systems/) a joint statement warning of threat actors actively spreading false information about compromised voting systems and voter registration databases in order to discredit the electoral process. According to CISA, attempts to compromise election infrastructure could only slow down but not prevent voting efforts.
