zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 18, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 18, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Fake Tether Cryptocurrency Tokens Announced For Sale
  • CISA Warns of Actively Exploited D-Link Router Vulnerabilities
  • U.S. AI Experts Targeted in SugarGh0st RAT Campaign

ZeroFox Intelligence Flash Report: Fake Tether Cryptocurrency Tokens Announced For Sale

Source: https://www.zerofox.com/advisories/23556/

What happened: Since the beginning of May 2024, two advertisements for the sale of fake Tether ERC20 (also known as USDT) have been offered in deep and dark web (DDW) forums. Such announcements are historically uncommon, though there is a roughly even chance that demand for these services is increasing.

Why it matters: Threat actors seeking to acquire fake Tether ERC20 coins most likely intend to leverage them in malicious, fraudulent activity such as exchange or investment scams. These are often conducted via the establishment of a webpage imitating a legitimate cryptocurrency or investment platform. If threat actors are continually successful in leveraging fake cryptocurrencies for malicious purposes, it is likely that additional purchasing options will become available in DDW forums. This would very likely lead to an increased threat to both individuals and organizations that are either involved in cryptocurrency trading or accept it as tender.

CISA Warns of Actively Exploited D-Link Router Vulnerabilities

Source: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html

What happened: CISA has added two security flaws impacting D-Link routers to its Known Exploited Vulnerabilities (KEV) catalog, including a CSRF vulnerability (CVE-2014-100005) affecting DIR-600 routers and an information disclosure flaw (CVE-2021-40655) in DIR-605 routers.

Why it matters: These actively exploited vulnerabilities pose significant risks to affected routers, enabling attackers to manipulate configurations and access sensitive login credentials. Moreover, CVE-2014-100005's impact on end-of-life (EoL) legacy D-Link products signifies that any future vulnerabilities discovered in these routers will not be patched, leaving them exposed to further cyberattacks. Organizations are advised to retire and replace these devices to maintain cybersecurity resilience.

U.S. AI Experts Targeted in SugarGh0st RAT Campaign

Source: https://www.darkreading.com/cyberattacks-data-breaches/us-ai-experts-targeted-in-sugargh0st-rat-campaign

What happened: Threat actors suspected to have ties with China are targeting artificial intelligence experts in U.S. companies, government agencies, and academia by using a newly discovered variant of the Gh0st RAT malware, dubbed as SugarGh0st to steal AI secrets.

Why it matters: Researchers suspect that the threat actor may be targeting AI experts to gain non-public information about generative AI. SugarGh0st who is a likely China-linked threat actor which could mean that China is resorting to cybertheft of AI secrets to counter partial U.S. restrictions placed on China’s access to generative AI technologies.

DEEP AND DARK WEB INTELLIGENCE

Threat actor rapelord | On May 9, 2024, threat actor “rapelord” from Rape Ransomware announced that it is looking for partners who are familiar with obtaining access to enterprise windows networks, on the well-known carding forum, “CrdPro." The threat actor stated that it does not work with healthcare or non-profit organizations.

Tags: DIB, tlp:green