zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Content Farm Impersonating Over 60 Prominent English Media Outlets
  • ZeroFox Intelligence Flash Report: LockBit and ALPHV Activity Likely Consistent with Exit Scams
  • BEC-Specialized Hackers Mimic U.S. Government Entities to Steal Sensitive Information

Content Farm Impersonating Over 60 Prominent English Media Outlets

Cybersecurity researchers have come across a content farm impersonating over 60 prominent English-language media outlets based in the United States and the United Kingdom. The research has identified over 60 domains reposting articles from credible media and research organizations without proper attribution and traced the websites’ proprietor in India. The proprietor has been observed spamming comments sections of various websites with backlinks to the domains to improve their credibility. Some of the comments also appear to be advertisements for the sale of slots for press releases and product reviews, starting at USD 50 per post or a "bulk deal" priced at USD 1000.

ZeroFox Intelligence Flash Report: LockBit and ALPHV Activity Likely Consistent with Exit Scams

Operators behind both the LockBit and ALPHV ransomware and digital extortion (R&DE) operations are exhibiting behavior likely consistent with imminent exit scams against their affiliates, at the time of writing. Both operations have claimed to be continuing operations following recent law enforcement (LE) activities, consistently downplaying the impact of disruptive action despite a significant reduction in observed activity. While ZeroFox can neither confirm nor deny the veracity of claims of scamming made by alleged LockBit and ALPHV affiliates, similar activity has been conducted by other notable ransomware collectives in the days preceding the cessation of their operations. Victims of outstanding or ongoing extortion attacks by LockBit and ALPHV are unlikely able to assume their stolen data will be deleted following payment of ransom demands. Regardless of whether they choose to pay ransom demands, victims are at an increased risk of stolen data not being deleted and, instead, sold on the deep and dark web (DDW) to the highest bidders.

BEC Specialized Hackers Mimic U.S. Government Entities to Steal Sensitive Information

TA4903, a hacker group specializing in business email compromise (BEC) attacks, has been impersonating several U.S. government agencies to deliver files with malicious links that redirect targets to fake bidding processes. Cybersecurity researchers have observed the threat actor masquerading as the U.S. Department of Transportation, the U.S. Department of Agriculture (USDA), and other federal departments. TA4903 carries out these financially motivated attacks to reportedly steal corporate credentials, infiltrate mailboxes, and conduct follow-on business email compromise (BEC) activity.

Tags: DIB, tlp:green