zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Email Addresses and Other Information of Several European Politicians on Dark Web
  • New V3B Phishing Kit Targets Customers of 54 European Banks
  • ZeroFox Intelligence Flash Report - Advertised Malicious Tool Targets Gmail Accounts

Email Addresses and Other Information of Several European Politicians on Dark Web

Source: https://www.securityweek.com/information-of-hundreds-of-european-politicians-found-on-dark-web/

What happened: Researchers found email addresses, dates of birth, addresses, and social media accounts of British and EU politicians on the dark web. The data leak — compromising about 900 email addresses — impacted British politicians the most, including senior government and opposition figures.

Why it matters: Among the email addresses exposed, researchers matched 697 of them with plain-text passwords. If any politician reused one of these compromised passwords for their official email account, it could pose a significant security risk. Moreover, with the UK and the EU elections on the horizon, malicious threat actors are likely to use the exposed data in targeted phishing attacks, extortion scams, influence campaigns, and intimidation efforts.

New V3B Phishing Kit Targets Customers of 54 European Banks

Source: https://www.bleepingcomputer.com/news/security/new-v3b-phishing-kit-targets-customers-of-54-european-banks/

What happened: Threat actors are advertising a new phishing kit, V3B, on Telegram, targeting customers of 54 major financial institutions across Europe. Priced between USD 130 and USD 450 per month, it boasts advanced features like obfuscation, localization, OTP/TAN/2FA support, live chat with victims, and evasion mechanisms.

Why it matters: The emergence of V3B represents a significant advancement in phishing-as-a-service (PhaaS) platforms, offering sophisticated tools to facilitate cybercrime. Phishing kits like V3B can be utilized not only to harvest banking credentials and credit card details but also to facilitate broader follow-on cyberattacks. Moreover, the real-time interaction capability via the admin panel allows for customized phishing attempts, such as obtaining one-time passwords (OTPs), enhancing the kit's effectiveness in evading detection and perpetrating cybercrime. Its ability to evade detection by anti-phishing measures heightens the risk of successful phishing attacks, potentially leading to substantial financial losses and compromised personal information.

ZeroFox Intelligence Flash Report - Advertised Malicious Tool Targets Gmail Accounts

Source: https://www.zerofox.com/advisories/23677/

What happened: On May 20, 2024, untested actor “Plifal” announced a new malicious tool named Plifal Software on the Russian-speaking dark web forum Exploit. The tool allegedly bypasses Google application programming interfaces (APIs) and policies, enabling threat actors to exploit session cookies and illicitly access Gmail user accounts.

Why it matters: While the advertisement offers no further detail surrounding the capabilities of Plifal Software, illicit access to an individual or business Gmail account can enable a threat actor to conduct a myriad of malicious activities. Software tools targeting widespread and diverse software solutions that are becoming increasingly prominent in the workplace are almost certainly a coveted target for threat actors seeking to gain illicit access and conduct subsequent malicious activity.

Tags: DIB, tlp:green