zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – July 8, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – July 8, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on July 5, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Kimsuky Using TRANSLATEXT Browser Extension to Steal Sensitive Data

What happened: A North Korea-linked group named Kimsuky has deployed a malicious web browser extension called TRANSLATEXT to target South Korean academia studying North Korean politics. The extension, disguised as a legitimate translation tool, steals sensitive information such as emails, passwords, and browser screenshots by bypassing security measures.

Threat Actors Target Multiple Arabian Entities Citing Political Reasons for the Attacks

What happened: ZeroFox has observed threat actor SN_Blackmeta claiming to target prominent entities in the United Arab Emirates (UAE), including two banks, a news agency, and a news channel. In a second wave of attacks, the same actor claimed to have targeted two more UAE companies, a bank and a telecommunications company. Meanwhile, threat actor Anonymous KSA has claimed to have carried out cyberattacks against several websites of Saudi Arabian ministries, including communications, economy, defense, sports, and civil service. Both of the threat actors have cited their support for Palestine as the motive for these cyberattacks.

Latest Intel CPUs Impacted by New Indirector Side-Channel Attack

What happened: Researchers have discovered a new type of high-precision Branch Target Injection (BTI) attack dubbed “Indirector” affecting modern Intel processors, including chips from the Raptor Lake and the Alder Lake generations. It exploits vulnerabilities in the Indirect Branch Predictor (IBP) and Branch Target Buffer (BTB), two hardware components in modern Intel CPUs, to manipulate speculative execution and potentially steal sensitive data.

Tags: tlp:green