zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 26, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • North Korea Cyber Group Conducts Global Espionage Campaign to Advance Malicious Activities
  • Meta Nukes Massive Instagram Sextortion Network of 63,000 Account
  • U.S. Accuses Telco IT Pro of Decade-Long Spying campaign for China

North Korea Cyber Group Conducts Global Espionage Campaign to Advance Malicious Activities

Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a

What happened: CISA and other agencies have released an advisory to highlight cyber espionage activity associated with the Democratic People’s Republic of Korea (DPRK’s) Reconnaissance General Bureau (RGB) 3rd Bureau. The RGB 3rd Bureau includes a DPRK state-sponsored cyber group known publicly as Andariel, Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa.

Why it matters: The authoring agencies believe the group and the cyber techniques remain an ongoing threat to various industry sectors worldwide, including but not limited to entities in their respective countries, as well as in Japan and India. RGB 3rd Bureau actors fund their espionage activity through ransomware operations against U.S. healthcare entities. The authoring agencies encourage critical infrastructure organizations to apply patches for vulnerabilities in a timely manner, protect web servers from web shells, monitor endpoints for malicious activities, and strengthen authentication and remote access protections.

Meta Nukes Massive Instagram Sextortion Network of 63,000 Account

Source: https://www.bleepingcomputer.com/news/security/meta-nukes-massive-instagram-sextortion-network-of-63-000-accounts/

What happened: Meta recently removed 63,000 Instagram accounts from Nigeria involved in sextortion scams, including a coordinated network of 2,500 accounts linked to 20 individuals targeting primarily adult men in the United States. Additionally, 1,300 Facebook accounts, 200 Facebook Pages, and 5,700 Facebook Groups associated with Nigerian scammers were also deleted. The group responsible, known as "Yahoo Boys," is a prominent Nigerian cybercrime network.

Why it matters: This crackdown is significant because it disrupts a major cybercrime network engaged in sextortion, a form of blackmail where scammers coerce victims into sending explicit content and then threaten to release it unless a ransom is paid. Sextortion can cause severe emotional distress and financial loss, so removing these accounts helps protect vulnerable users. Scammers, often using fake identities, build trust by feigning romantic interest before coercing victims into sharing intimate photos. Victims of sextortion are advised to promptly report the crime through the FBI’s tips portal. Additionally, Meta has also implemented measures to block scammers from creating new accounts. In a digital age where online trust can be deceptively easy to build, sextortion scams exploit this vulnerability, turning personal connections into tools for manipulation and extortion.

U.S. Accuses Telco IT Pro of Decade-Long Spying campaign for China

Source: https://www.theregister.com/2024/07/25/us_it_pro_spying_charge/

What happened: A Chinese immigrant, who is a U.S. citizen, is charged with acting as an agent for China's Ministry of State Security (MSS). The indictment accuses him of supplying the MSS with information on U.S. cybersecurity incidents, details about his telecommunications employer, and data on individuals associated with the Falun Gong religious movement. The alleged espionage activities took place from 2012 to 2022.

Why it matters: The prosecution of the accused individual highlights the ongoing concerns about foreign espionage and its impact on U.S. national security. If proven, it underscores vulnerabilities in critical industries, such as telecommunications and IT, and raises questions about the effectiveness of current counterintelligence measures. The allegations also reflect broader geopolitical tensions and the challenges of safeguarding sensitive information against sophisticated state-sponsored actors. The information allegedly shared by the accused could have significant impacts on U.S. national security and economic interests. Details about cybersecurity incidents might aid Chinese state-sponsored actors in refining their cyberattacks, potentially targeting critical infrastructure or sensitive data. Information about his telecommunications and IT employers could expose vulnerabilities in key industries, undermining trust and operational security. Additionally, intelligence on individuals linked to Falun Gong could jeopardize the safety of political dissidents and affect diplomatic relations between the United States and China.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user "USDoD": Threat actor "USDoD" claimed to leak a database associated with CrowdStrike’s “entire threat actor list” on the predominantly English-language dark web forum BreachForums. Threat actor claimed that the list contains 250 million scrapped IOCs (indicators of compromises) and will be releasing it in two parts. The data includes the following: alias, target industries, target countries, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

ServiceNow flaws: Three ServiceNow flaws are reportedly being exploited by threat actors targeting government agencies, data centers, energy providers, and more. The company has made fixes available for all three vulnerabilities: CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217.

Affected products: For affected products, refer to this advisory.

AI-Networking Vulnerabilities: Nvidia has deployed patches for vulnerabilities (CVE-2024-0108, CVE-2024-0101, and CVE-2024-0104) affecting its artificial intelligence and networking products.

Affected products: For affected products, refer to two of these advisories.

Tags: DIB, tlp:green