zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 17, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 17, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukraine Dismantles Pro-Russia Spyware Operation Amid Rising Cybersecurity
  • Smishing Triad Expands to Pakistan, Targeting Users with Fake Delivery Scams
  • Phishing Attack at L.A. County Public Health Agency Exposes Over 200,000 Personal Info

Ukraine Dismantles Pro-Russia Spyware Operation Amid Rising Cybersecurity

Source: https://www.theregister.com/2024/06/14/ukraine_sim_farm_bust/

What happened: The Security Service of Ukraine (SSU) dismantled infrastructure used by two pro-Russia Ukraine residents to hack soldiers' devices and deploy spyware. Ukrainian authorities discovered thousands of mobile numbers and Telegram accounts under the control of SIM farm–resembling entities which were abused by Russian intelligence services.

Why it matters: Spyware installation in soldiers’ devices is likely to compromise data and battlefield communications, posing significant security risks. Moreover, this operation's use for spreading pro-Kremlin propaganda shows the multifaceted cyber warfare strategies employed by Russia amid the ongoing Russia-Ukraine war. To curb further such attacks, prosecutors at the International Criminal Court are reportedly investigating alleged Russian attacks on Ukrainian civilian infrastructure and their potential classification as war crimes. Some of these cyberattacks, such as those disrupting power, water, emergency services, and air raid warnings in Ukraine, have endangered lives.

Smishing Triad Expands to Pakistan, Targeting Users with Fake Delivery Scams

Source: https://thehackernews.com/2024/06/grandoreiro-banking-trojan-hits-brazil.html?m=1

What happened: Pakistan has become the latest target of the Smishing Triad, a threat actor previously active in the European Union, Saudi Arabia, United Arab Emirates, and the United States. The threat actor was observed sending malicious iMessage and SMS messages on behalf of Pakistan Post, Pakistan's primary and largest postal operator, to steal personal and financial information.

Why it matters: Smishing Triad expanding into new regions beyond its usual target areas indicates its evolving sophistication and reach. The group's modus operandi includes leveraging stolen databases from the dark web to send fake SMS messages about failed package deliveries. Recipients are tricked into clicking links and entering financial information on counterfeit websites, supposedly for redelivery service fees. The adversary exploits human trust by targeting users expecting legitimate packages, making its tactics more effective.

Phishing Attack at L.A. County Public Health Agency Exposes Over 200,000 Personal Info

Source: http://publichealth.lacounty.gov/phcommon/public/media/mediapubhpdetail.cfm?prid=4732

What happened: The Los Angeles County Department of Public Health has disclosed that between February 19 and February 20, 2024, the healthcare organization experienced a phishing attack where a hacker obtained login credentials from 53 employees. This breach potentially exposed the personal identifiable information (PII) of over 200,000 clients, employees, and other individuals.

Why it matters: This incident at the Los Angeles County Department of Public Health is significant due to the scale and sensitivity of the data compromised. Personal information (such as names, dates of birth, medical details, Social Security numbers, and financial details) can be exploited for identity theft, fraud, and other malicious activities. Following the phishing attack, the department took immediate mitigation measures, including disabling compromised email accounts, resetting affected devices, blocking phishing-related websites, quarantining suspicious emails, distributing awareness notifications to staff, notifying law enforcement, and launching an investigation.

DEEP AND DARK WEB INTELLIGENCE

  • Threat actor group Hunt3r Kill3rs: Threat actor group Hunt3r Kill3rs claims to have infiltrated the servers of the CUPS system (a standards-based, open-source printing system developed by Apple for iOS, iPadOS, and macOS) and disrupted “important configurations and information.” The attack was supposedly in retaliation for Apple's support to Israel in the ongoing war.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-3080: A flaw with a critical CVSS score of 9.8 has been identified in ASUS devices that allows unauthenticated remote attackers to seize control of the device. ASUS recommends immediate firmware updates and suggests strengthening account and WiFi passwords for those unable to update right away.

Affected products: Router models: XT8 (ZenWiFi AX XT8), XT8_V2 (ZenWiFi AX XT8 V2), RT-AX88U, RT-AX58U, RT-AX57, RT-AC86U, and RT-AC68U.

Tags: DIB, tlp:green