zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 18, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 18, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Assessment - Physical and Cyber Threats to Olympic Games Paris 2024
  • West African Crime Syndicate Taken Down by Interpol Operation
  • Actor Leaks Data Allegedly Associated with Family Location Tracker App Users

ZeroFox Intelligence Assessment - Physical and Cyber Threats to Olympic Games Paris 2024

Source: https://www.zerofox.com/advisories/24513/

What happened: The Olympic Games Paris 2024 (also referred to as the Olympics, Paris 2024, and the Games) is a highly visible, worldwide event that could be targeted by various actors, both domestic and international, to bring attention to their causes. Physical disruption via strikes or protests is the major on-the-ground threat to the Games; cyberattacks sponsored by Russia are the major cybersecurity threat.

Why it matters: Russian cyber threat actors are likely to react to the strong showing of support for Ukraine at the Games, as well as previous bans of Russian athletes, by targeting the IOC. This is likely to take the form of DDoS attacks, data compromises, and scams carried out by Russian threat actor groups. On June 23, 2024, the “People’s Cyber Army” (PCA) posted a call to action on its Telegram channel and associated “RCAT chat” private group, urging cyber fighters to target France with cyberattacks. Mobile applications present security risks, and cyber threat actors are very likely attempting to exploit enthusiasm for the Games to carry out scams utilizing them. Threat actors can use mobile app credentials to access user accounts, potentially reselling tickets and manipulating personal information associated with paris2024[.]org and olympics[.]com users.

West African Crime Syndicate Taken Down by Interpol Operation

Source: https://www.darkreading.com/cybersecurity-operations/west-african-crime-syndicate-taken-down-by-interpol-operation

What happened: A global INTERPOL operation (Operation Jackal III) recently took down hundreds of criminals, seized assets amounting to USD 3 million, and blocked more than 700 accounts. One of the major groups it took down was Black Axe which has been attributed to criminal activities like cyber fraud, human trafficking, drug smuggling, and other violent crimes.

Why it matters: Operation Jackal III has been one of the essential global law enforcement efforts in combating global cybercrime. Portuguese criminal police dismantled a Nigerian network involved in money mule recruitment and laundering funds from online financial fraud victims across Europe, identifying more than 25 syndicate members. Seized data revealed large transfers to Nigerian bank accounts, cryptocurrency transactions, and sophisticated money laundering operations. INTERPOL headquarters assisted by facilitating intelligence exchange and the identification and apprehension of suspects, making this operation a crucial step forward in fighting cybercrime and recovering illicit funds.

Actor Leaks Data Allegedly Associated with Family Location Tracker App Users

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67293

What happened: ZeroFox intelligence has observed threat actor “emo” claiming to leak a database allegedly leaking personal information of over half a million users of Life360, a family safety and location-sharing app, on the dark web.

Why it matters: The actor claims that the dataset includes email addresses, names, and phone numbers, seemingly sourced from a data breach targeting the app in March 2024. The impacted Life360 users are at risk of phishing emails and SMS phishing. The stolen data can facilitate social engineering attacks, where attackers manipulate individuals into revealing further personal information or financial details. Adversaries are likely to use the information for account takeovers, unauthorized transactions, and creating fake identities. Moreover, the data is actively being shared in Telegram groups and on Russian-speaking cybercrime forums, increasing the likelihood of widespread malicious activities and potentially affecting thousands of users. Additionally, the ability to push alerts and transfer device ownership can lead to significant disruptions and privacy invasions.

DEEP AND DARK WEB INTELLIGENCE

Russian hacking group “FIN7”: The FIN7 hacking group has been observed selling its custom "AvNeutralizer" tool reportedly on corporate networks. The tool enables users to evade detection by “killing” enterprise endpoint protection software.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-28995: This directory transversal vulnerability in SolarWinds Serv-U allows access to read sensitive files on the host machine. It was added to CISA’s Known Exploited Vulnerabilities Catalog on July 17.

Affected products: SolarWinds Serv-U 15.4.2 HF 1 and previous versions

CVE-2024-20419: Cisco has resolved this critical vulnerability in its Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers. This flaw could let attackers reset the passwords of any users, including administrators.

Affected products: Cisco SSM On-Prem and Cisco Smart Software Manager Satellite (SSM Satellite)

Tags: DIB, tlp:green