zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Iranian State-Sponsored Hackers Conduct Social Engineering Campaign Mimicking Journalists
  • Android Malware Campaign Uses Spoofing to Breach Bank Accounts in Finland
  • Amnesty International Cites Indonesia as a Spyware Hub

Iranian State-Sponsored Hackers Conduct Social Engineering Campaign Mimicking Journalists

Source: https://www.cyberdaily.au/security/10505-iranian-hackers-impersonate-journalists-in-social-engineering-campaign

What happened: Cybersecurity researchers have found hackers from APT42, an Iranian state-sponsored cyberespionage group, impersonating journalists and human rights activists to exfiltrate data and steal cloud operations credentials through spearphishing attacks.

Why it matters: Reports suggest that APT42, affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO), has been targeting Western and Middle Eastern NGOs, media organizations, academia, legal services, and activists. With rising tensions in the Middle East, especially between Iran and Israel amid the Israel-Hamas war, cyber threats to organizations in this region are likely to be imminent as state-sponsored hackers try to exfiltrate sensitive data.

Android Malware Campaign Uses Spoofing to Breach Bank Accounts in Finland

Source: https://www.bleepingcomputer.com/news/security/finland-warns-of-android-malware-attacks-breaching-bank-accounts/

What happened: Finland's Transport and Communications Agency (Traficom) has warned the public of an ongoing Android malware campaign that tricks victims into downloading malware disguised as a popular antivirus.

Why it matters: The malware delivered in the campaign allows threat actors to log into a victim's bank account and access all the money stored. A victim of this campaign has lost USD 102,000.

Amnesty International Cites Indonesia as a Spyware Hub

Source: https://www.darkreading.com/cybersecurity-operations/amnesty-international-cites-indonesia-as-spyware-hub

What happened: Amnesty International's recent research highlights Indonesia's emergence as a hub for surveillance tools and suppliers, with evidence indicating the sale and shipment of intrusive spyware and surveillance technologies from countries like Israel, Greece, Singapore, and Malaysia to Indonesia.

Why it matters: Amnesty International has also uncovered various malicious domain names and network infrastructures associated with spyware platforms targeting individuals within Indonesia. These domain names often imitate political parties and media outlets, though the specific targets remain ambiguous. Government agencies have employed spyware in the past to monitor journalists. These findings further highlight the country’s weak civil rights protection system.

DEEP AND DARK WEB INTELLIGENCE

  • New Ransomware Group F Society: On May 3, ZeroFox identified a new leak site called F Society with four victims listed on it. The list includes Bitfinex— the second largest Bitcoin exchange platform— besides Rutgers University and others. ZeroFox also observed the group's activity on an underground forum, Spyhackerz, operating as threat actor FSOCIETYGROUP.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-4516: Affected by this issue is some unknown functionality of the file /view/timetable.php. The manipulation of the argument grade leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products: Campcodes Complete Web-Based School Management System 1.0

  • CVE-2024-4511: This affects an unknown part of the component Message Handler. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used.

Affected products: Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4

Tags: DIB, tlp:green