ZeroFox Cyber Intelligence Daily Brief - July 7, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 7, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- New SnailLoad Attack Exploits Network Latency to Reveal User Web Activity Remotely
- Brain Cipher Ransomware Gang Targets Indonesian Ministry of Communications and Informatics
- ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised
New SnailLoad Attack Exploits Network Latency to Reveal User Web Activity Remotely
Source: https://thehackernews.com/2024/06/new-snailload-attack-exploits-network.html
What happened: Cybersecurity researchers have demonstrated a new side-channel attack called SnailLoad. Threat actors leveraging this attack can remotely infer a user’s web activity by exploiting latency bottlenecks without an adversary-in-the-middle position or physical proximity to the target.
Why it matters: SnailLoad is a novel method for adversaries to deduce a user’s online behavior, such as the websites they visit or videos they watch, by merely analyzing network latency. Threat actors trick users into loading harmless assets from a malicious server and measure the latency variations to infer network activity without user interaction or code execution, thereby bypassing security measures. Additionally, the security flaws in router firmware handling NAT (Network Address Translation) mapping call for rigorous inspection of network packets to prevent TCP (Transmission Control Protocol) connection manipulation, which can let attackers conduct denial-of-service. These security flaws are currently under inspection, which reflects mitigation efforts.
Brain Cipher Ransomware Gang Targets Indonesian Ministry of Communications and Informatics
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66665
What happened: On July 2, ZeroFox Intelligence observed that the Brain Cipher ransomware group listed Indonesia’s Ministry of Communications and Informatics (also known as Kominfo) as a victim on its leak site.
Why it matters: Within a short time of its emergence, Brain Cipher has claimed attacks on notable Indonesian entities, including a massive data breach into Indonesia's temporary National Data Center that made headlines last month as one of the worst cyberattacks the country has suffered in recent years. Targeting government entities without political motives depicts the group’s efforts to establish its legitimacy as a new group in the cyber underworld. Moreover, such attacks could disrupt crucial government operations, compromise sensitive citizen data, and erode public trust in the government's ability to protect its digital infrastructure.
ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised
Source: https://www.zerofox.com/advisories/24155/
What happened: Untested actor “enryu” advertised a new extended validation (EV) code signing service on the primarily Russian-speaking dark web forum Exploit. According to the advertisement, illicit validation certificates can be purchased, which allow malicious webpages to bypass security protocols such as SmartScreen, Windows User Account Control, and Windows Defender, as well as some antivirus (AV) software provided by third parties.
Why it matters: Illicit validation certificates offer cyber threat actors the ability to augment a wide array of malicious activities, such as the deploying of disruptive malware to target networks, enhanced social engineering attacks, or data theft resulting in operational disruption, extortion or fraud. Given the versatility offered by initial network access, services such as these are very likely to appeal to a wide range of threat actors with varying intents and motivations, leading to their continued development, competitiveness, and innovation.
Tags: DIB, tlp:green