zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Data of Millions of mSpy Customers Leaked Online
  • ZeroFox Intelligence Assessment - Physical and Cyber Threats to Olympic Games Paris 2024
  • West African Crime Syndicate Taken Down by INTERPOL Operation

Data of Millions of mSpy Customers Leaked Online

Source: https://www.securityweek.com/data-of-millions-of-mspy-customers-leaked-online/

What happened: Hacktivists have reportedly stolen and leaked more than 300 GB of data from spyware maker mSpy. The breached data includes 142 GB of user data and support tickets, 176 GB of attachments, 2.4 million unique email addresses, and more. The data leak reportedly occurred as a result of a breach in a specific account linked to a customer-support system.

Why it matters: mSpy is a “parental control application” which allows users to monitor and log the activity of specific device users. The recent data leak exposed a decade's worth of data that showed the application's notorious use in surveillanceware by actors to monitor individuals secretly in real time without their consent or knowledge. The leaked data exposed data linked to civilians, “senior-ranking U.S. military personnel, a serving U.S. federal appeals court judge, a U.S. government department’s watchdog, and an Arkansas county sheriff’s office seeking a free license to trial the app.” Sensitive data leaked at this scale places vulnerable entities like children and other individuals exposed to stalkers, which endangers them to kidnappings and further monitoring. With the collected data, threat actors can conduct targeted surveillance, monitor communications, and track physical movements, posing significant risks to privacy and security.

ZeroFox Intelligence Assessment - Physical and Cyber Threats to Olympic Games Paris 2024

Source: https://www.zerofox.com/advisories/24513/

What happened: The Olympic Games Paris 2024 is a highly visible, worldwide event that could be targeted by various actors, both domestic and international, to bring attention to their causes. Physical disruption via strikes or protests is the major on-the-ground threat to the Games; cyberattacks sponsored by Russia are the major cybersecurity threat.

Why it matters: Russian cyber threat actors are likely to react to the strong showing of support for Ukraine at the Games, as well as to “avenge” previous bans of Russian athletes, by targeting the IOC. This is likely to take the form of DDoS attacks, data compromises, and scams carried out by Russian threat actor groups. On June 23, 2024, the “People’s Cyber Army” (PCA) posted a call to action on its Telegram channel and associated “RCAT chat” private group, urging cyber fighters to target France with cyberattacks. Mobile applications present security risks, and cyber threat actors are very likely attempting to exploit enthusiasm for the Games to carry out scams utilizing them. Threat actors can use mobile app credentials to access user accounts, potentially reselling tickets and manipulating personal information associated with paris2024[.]org and olympics[.]com users.

West African Crime Syndicate Taken Down by INTERPOL Operation

Source: https://www.darkreading.com/cybersecurity-operations/west-african-crime-syndicate-taken-down-by-interpol-operation

What happened: A global INTERPOL operation (Operation Jackal III) recently took down hundreds of criminals, seized assets amounting to USD 3 million, and blocked more than 700 accounts. One of the major groups it took down was Black Axe, which has been attributed to criminal activities like cyber fraud, human trafficking, drug smuggling, and other violent crimes.

Why it matters: Operation Jackal III has been one of the essential law enforcement efforts in combating global cybercrime. Portuguese criminal police dismantled a Nigerian network involved in money mule recruitment and laundering funds from online financial fraud victims across Europe, identifying more than 25 syndicate members. Seized data revealed large transfers to Nigerian bank accounts, cryptocurrency transactions, and sophisticated money laundering operations. INTERPOL headquarters assisted by facilitating intelligence exchange and the identification and apprehension of suspects, making this operation a crucial step forward in fighting cybercrime and recovering illicit funds.

Tags: DIB, tlp:green