ZeroFox Cyber Intelligence Daily Brief - June 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- China-Linked Velvet Ant Cyber Espionage Exposed in Prolonged East Asia Attack
- Suspected Administrators of USD 430 Million “Empire Market” Charged in the U.S.
- Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine
China-Linked Velvet Ant Cyber Espionage Exposed in Prolonged East Asia Attack
Source: https://thehackernews.com/2024/06/china-linked-hackers-infiltrate-east.html
What happened: A suspected China-linked cyber espionage actor, dubbed Velvet Ant, conducted a three-year-long attack on an East Asian organization. The adversary exploited legacy F5 BIG-IP appliances to establish persistence and used these edge devices for internal command-and-control (C&C) to evade defense.
Why it matters: Velvet Ant's campaign displays sophisticated cyberattack tactics, including employing the PlugX backdoor and innovative methods to disable endpoint security and blend malicious traffic with legitimate network activity. The attack is likely to invite more threat actors to exploit vulnerable edge appliances—often intended to secure networks—to gain long-term persistence. Moreover, the incident aligns with broader patterns of China-linked cyber activities targeting sensitive information in Asia amid rising geopolitical tensions between China and its neighboring countries.
Suspected Administrators of USD 430 Million “Empire Market” Charged in the U.S.
Source: https://www.theregister.com/2024/06/17/empire_market_arrests/
What happened: Two of Empire Market’s administrators were indicted by the U.S. Department of Justice (DoJ) on grounds of drug trafficking, computer fraud, access device fraud, counterfeiting, and money laundering. Additionally, USD 75 million worth of cryptocurrency was seized from the market admins.
Why it matters: Empire Market was allegedly the hub for thousands of vendors that conducted illegal activities. Transactions occurred with cryptocurrencies where transactors were advised to use cryptocurrency mixers to avoid law enforcement detection.
Hamas Hackers Deploy Stealthy Spyware Across Egypt and Palestine
What happened: Arid Viper, a Hamas-linked APT group, has been observed targeting users across Egypt and Palestine with AridSpy Android spyware distributed via Trojanized messaging apps.
Why it matters: The use of Trojanized apps and multistage payloads makes detection and mitigation challenging. Victims In Palestine were tricked by ads posing as a fake Palestinian Civil Registry app, while in Egypt, spyware was embedded in an app named LapizaChat and job scams on third-party sites. Once installed, AridSpy conducts multistage data exfiltration, capturing extensive personal data and giving the cybercriminals the ability to record. With the collected data, threat actors can conduct targeted surveillance, monitor communications, and track physical movements, posing significant risks to privacy and security. The ability to record audio and take pictures enhances their capability for espionage, potentially enabling blackmail, extortion, or further infiltration into sensitive networks or personal lives.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user GlorySec: Hacktivist group GlorySec has claimed to have found a zero day exploit in the websites of China-based companies and gained admin panel access to 20,000 websites, under its ongoing operation #OPChina and #OPPRC.
VULNERABILITY AND EXPLOIT INTELLIGENCE
- CVE-2024-38396: Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal.
Affected products: Router models: iTerm2 versions 3.5.x before 3.5.2.
- CVE-2024-38313: In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address.
Affected products: Router models: Versions of Firefox for iOS before 12.
Tags: DIB, tlp:green