zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 20, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 20, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Two Arrested Chinese Nationals Charged for Laundering USD 73 Million in Pig Butchering Scam
  • American Radio Relay League Cyberattack Takes Logbook of the World Offline
  • SEC Adds New Incident Response Rules for Financial Sector

Two Arrested Chinese Nationals Charged for Laundering USD 73 Million in Pig Butchering Scam

Source: https://thehackernews.com/2024/05/chinese-nationals-arrested-for.html

What happened: The U.S. Department of Justice has charged two Chinese individuals, arrested in April, for allegedly organizing and running a pig butchering scheme through which they laundered USD 73 million in cryptocurrency. The accused fraudulently induced several victims into transferring millions in U.S. dollars to accounts of dozens of shell companies. Why it matters: The two individuals have been money laundering and six substantive counts of international money laundering. If the court finds them guilty, the defendants face a maximum penalty of 20 years in prison on each count. Complex cryptocurrency scams, such as pig butchering, are on the rise and pose a clear threat to the financial infrastructure of the United States. According to an FBI report, victims in the United States suffered a cumulative loss of USD 2.6 billion in 2022 because of pig butchering scams and other cryptocurrency fraud.

American Radio Relay League Cyberattack Takes Logbook of the World Offline

Source: https://www.bleepingcomputer.com/news/security/arrl-cyberattack-takes-logbook-of-the-world-offline/

What happened: The American Radio Relay League (ARRL), a national amateur radio organization, confirmed a cyberattack that disrupted its IT systems and online operations, including email services and the Logbook of the World. The organization is responding to the incident, which involves unauthorized access to its network and headquarters-based systems. Services such as the ARRL Learning Center have also been affected. Why it matters: While credit card information and Social Security numbers are not stored in AARL’s systems, the attacker gained access to the member database, which contains publicly available information such as names, addresses, and call signs, along with ARRL-specific data like email preferences and membership dates.

SEC Adds New Incident Response Rules for Financial Sector

Source: https://www.darkreading.com/cyber-risk/sec-adds-new-incident-response-rules-for-financial-sector

What happened: The Securities and Exchange Commission (SEC) has announced new data breach reporting regulations for certain financial firms, updating Regulation S-P for the first time in 24 years. Why it matters: These amendments aim to address the evolving risks posed by technology and data breaches in the financial sector, requiring institutions to develop incident response programs and notify affected individuals promptly. Financial organizations are required to notify individuals of data breaches within 30 days, providing details of the incident and the type of data compromised, as well as guidance on how affected customers can safeguard themselves.

DEEP AND DARK WEB INTELLIGENCE

Threat actor attack | The untested threat actor "attack" advertised network access bundles to 9400 unnamed worldwide companies on the predominantly Russian language Dark Web forum "XSS." According to "attack" the access bundle is a list of entry points with login credentials. The sources were personal malware logs.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2020-6977: A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system.

Affected products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5.

Tags: DIB, tlp:green