zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – July 22, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – July 22, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on July 19, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

WazirX Cryptocurrency Exchange Loses USD 230 Million in Major Security Breach

What happened: WazirX, one of India’s leading cryptocurrency exchanges (owned by Binance), experienced a security breach involving one of its multi-signature (multisig) wallets. This breach led to the temporary suspension of both Indian rupee and cryptocurrency withdrawals. Approximately USD 230 million worth of assets were transferred suspiciously from the affected wallet.

IDF Computer Chief: Three Billion Cyberattacks Against Israel Since Beginning of War

What happened: The Israel Defense Forces’ (IDF) cloud-computing network experienced over three billion cyberattacks following the outbreak of war between Israel and Hamas on October 7, 2023, but all of the attacks were successfully intercepted and reportedly did not result in significant damage. These attacks targeted operational cloud systems used by troops during combat, aiming to disrupt information-sharing and reveal the location of forces. Despite the intensity and volume of these attacks, IDF's defenses remained uncompromised. The IDF had to manage system overloads due to increased usage from reservists and the need for additional computing resources, leading to the establishment of an extra data center.

Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyberattacks

What happened: Iran-linked “MuddyWater” has been observed deploying a new backdoor dubbed BugSleep in its recent campaigns. The group conducts phishing campaigns and establishes persistence by deploying legitimate remote monitoring and management (RMM) software. The use of legitimate software has now reportedly been replaced by a new backdoor that can help threat actors evade detection by “blending in with legitimate network traffic.”

Tags: tlp:green