zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Geopolitical and Cyber Risks of Iranian Attack on Israel
  • Kapeka Backdoor Spotted in Eastern Europe
  • U.S. Treasury Targets Hamas UAV Unit Officials and Cyber Actor

ZeroFox Intelligence Flash Report - Geopolitical and Cyber Risks of Iranian Attack on Israel

On April 13, Iran launched a massive, yet calibrated, attack on Israel in retaliation for an earlier Israeli strike on an Iranian consulate in Syria. Negative economic, geopolitical, and supply chain effects have been muted because markets already factored in the strike, which came with a two-week warning and deliberately avoided mass casualties. An immediate Israeli response that would widen the Israel-Hamas war is unlikely, but limited strikes against military positions belonging to Iranian allies across the Middle East are well within the realm of possibility. Ahead of the retaliation, ZeroFox identified cyber threat actors forming alliances with both Israel and Iran, which could escalate to cyberattacks on organizations on each side of the conflict. An Israeli-backed cyberattack on Iran is less likely, as Israel has historically focused its targeting on threats to its physical security.

Kapeka Backdoor Spotted in Eastern Europe

Kapeka backdoor, a previously undocumented malware strain linked to Russian threat group Sandworm, is targeting East European Countries including Estonia and Ukraine. Kapeka is a flexible backdoor that can be deployed for early-stage reconnaissance and long-term access to compromised systems. Kapeka is reported to use a dropper that installs and activates a backdoor on the victim's machine before removing itself. The backdoor then gathers information about the system and user, sending this data to the threat actor for further actions or updates to the backdoor's configuration.

U.S. Treasury Targets Hamas UAV Unit Officials and Cyber Actor

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) and the European Union are imposing sanctions on Hamas leaders involved in cyber and unmanned aerial vehicle (UAV) operations. This joint action aims to disrupt Hamas's ability to conduct further attacks, through cyber warfare and the production of UAVs. The property and interests in the United States of the designated leaders are blocked and transactions involving them are prohibited. Non-U.S. financial institutions and other individuals engaging in certain transactions or activities with sanctioned entities and individuals may expose themselves to sanctions risk or be subject to an enforcement action.

Tags: DIB, tlp:green