zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hamas Hackers Deploy Stealthy Spyware Across Egypt and Palestine
  • ZeroFox Intelligence Flash Report - New Malicious Tool Advertises Comprehensive Personal Information
  • CDK Global Investigating Cyber Incident

Hamas Hackers Deploy Stealthy Spyware Across Egypt and Palestine

Source: https://www.darkreading.com/cyberattacks-data-breaches/hamas-hackers-stealthy-spyware-egypt-palestine

What happened: Arid Viper, a Hamas-linked APT group, has been observed targeting users across Egypt and Palestine with AridSpy Android spyware distributed via Trojanized messaging apps.

Why it matters: The use of Trojanized apps and multistage payloads makes detection and mitigation challenging. Victims In Palestine were tricked by ads posing as a fake Palestinian Civil Registry app, while in Egypt, spyware was embedded in an app named LapizaChat and job scams on third-party sites. Once installed, AridSpy conducts multistage data exfiltration, capturing extensive personal data and giving the cybercriminals the ability to record. With the collected data, threat actors can conduct targeted surveillance, monitor communications, and track physical movements, posing significant risks to privacy and security. The ability to record audio and take pictures enhances their capability for espionage, potentially enabling blackmail, extortion, or further infiltration into sensitive networks or personal lives.

ZeroFox Intelligence Flash Report - New Malicious Tool Advertises Comprehensive Personal Information

Source: https://www.zerofox.com/advisories/23756/

What happened: A positive-reputation actor known as “spam_assistant” has announced a new tool called Data Fusion in the dark web forum Exploit. According to the advertisement, Data Fusion is capable of providing buyers with a significant amount of both personally identifiable information (PII) pertaining to individuals and organizational tax data.

Why it matters: Unlike similar deep and dark web (DDW) services offering the sale of PII, Data Fusion is allegedly capable of creating bespoke background reports that summarize the requested data. PII such as that advertised by spam_assistant is an integral aspect of many forms of cyberattack. Personal details are used to inform and enhance sophisticated social engineering attacks, such as spear phishing and business email compromise, or to enable fraudulent activity like identity theft and tax-related scams.

CDK Global Investigating Cyber Incident

Source: https://www.reuters.com/technology/cybersecurity/cdk-global-investigating-cyber-incident-briefly-shut-all-systems-2024-06-19/

What happened: CDK Global temporarily shut down all its systems to investigate a recent cyber incident. The company has restored its core dealer management system and digital retailing solutions since the incident.

Why it matters: CDK is a car dealership software-as-a-service provider, and a cyber incident on its systems may have a likely impact on its clients. Clients may especially be vulnerable since they configure an always-on VPN to their SaaS provider's data centers, enabling their locally installed applications to access the platform, which could allow threat actors to access its networks. The company is currently conducting investigations to assess if the cyber incident has had any bearing on its clients as well.

Tags: DIB, tlp:green