ZeroFox Cyber Intelligence Daily Brief - May 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 26, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Two Arrested Chinese Nationals Charged for Laundering USD 73 Million in Pig Butchering Scam
- ZeroFox Intelligence Flash Report - First Potential BreachForums Successor Announced
- State Hackers Turn to Massive ORB Proxy Networks to Evade Detection
Two Arrested Chinese Nationals Charged for Laundering USD 73 Million in Pig Butchering Scam
Source: https://thehackernews.com/2024/05/chinese-nationals-arrested-for.html
What happened: The U.S. Department of Justice has charged two Chinese individuals, arrested in April, for allegedly organizing and running a pig butchering scheme through which they laundered USD 73 million in cryptocurrency. The accused fraudulently induced several victims into transferring millions in U.S. dollars to accounts of dozens of shell companies.
Why it matters: The two individuals have been charged with money laundering and six substantive counts of international money laundering. If the court finds them guilty, the defendants face a maximum penalty of 20 years in prison on each count. Complex cryptocurrency scams, such as pig butchering, are on the rise and pose a clear threat to the financial infrastructure of the United States. According to an FBI report, victims in the United States suffered a cumulative loss of USD 2.6 billion in 2022 because of pig butchering scams and other cryptocurrency fraud.
ZeroFox Intelligence Flash Report - First Potential BreachForums Successor Announced
Source: https://www.zerofox.com/advisories/23575/
What happened: On May 16, threat actor “USDoD” announced on X (formerly Twitter) their intent to launch a new, open-source data breach forum named Breach Nation.
Why it matters: USDoD stated their intent for Breach Nation to serve as a successor to BreachForums, which was severely disrupted on May 15, by a law enforcement (LE) operation that seized the forum’s [.]st domain, a [.]onion domain, and a Telegram channel. There is a roughly even chance that Breach Nation will become a popular tool for threat actors seeking to discuss techniques, tactics, and procedures (TTPs) related to data breach attacks, publicize results, and sell stolen information. It is likely that, in the coming months, other BreachForums members, moderators, and staff will seek to capitalize upon its disruption by creating and advertising new forums.
State Hackers Turn to Massive ORB Proxy Networks to Evade Detection
What happened: China-linked actors are evading detection by relying on operational relay box (ORB) networks to conduct cyberespionage campaigns. ORBs are proxy server networks managed by independent cybercriminals who provide access to multiple state-sponsored actors.
Why it matters: The increasing use of ORBs make it more difficult for defenders to detect, attribute, and effectively identify indicators of compromise. This is concerning because these threat actors have targeted critical infrastructure, government agencies, and other prominent entities.
Tags: DIB, tlp:green