ZeroFox Weekly Intelligence Brief – July 29, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – July 29, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on July 26, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
CrowdStrike-Related Outage Causes Global Chaos
What happened: On July 19, 2024, CrowdStrike released a Rapid Response Content update for Windows sensors, which caused system crashes and the blue screen of death (BSOD) on systems running sensor version 7.11 and above. This update was meant to gather telemetry on new threat techniques but contained an undetected error. The problematic content was mistakenly validated and deployed due to a bug in the Content Validator. Upon loading, it caused an out-of-bounds memory read, leading to crashes. In an alert posted for customers soon after the outage, CrowdStrike said it was aware of “reports of crashes.” CrowdStrike's engineering team identified the content deployment related to this issue and reverted those changes. ZeroFox notes that threat actors may seek to exploit the ongoing outages, including by taking advantage of stretched security infrastructure and performing attacks against targets that may otherwise draw quick attention and be identified. Scammers may also leverage the outage as a lure in social-engineering attacks. Attackers may continue targeting high-profile victims who have removed their endpoint detection and response (EDR) suite in response to the outage, thereby leaving them vulnerable. Meanwhile, ZeroFox Intelligence has observed threat actor "USDoD" claiming to leak a database associated with CrowdStrike’s “entire threat actor list” on the predominantly English-language dark web forum BreachForums. The list allegedly contains 250 million scrapped Indicators of Compromise (IOCs) and will be released in two parts. The data includes aliases, target industries, target countries, and more.
NCA Infiltrates World's Most Prolific DDoS-for-Hire Service
What happened: The UK National Crime Agency (NCA), along with other law enforcement (LE) agencies, infiltrated and disabled digitalstress[.]su, a major DDoS-for-hire service responsible for numerous global attacks. The agency disabled the actual site and created a mirror site, which directed users to a page that announced that their data had been collected by law enforcement.
New ICS Malware Targeting Critical Infrastructure
What happened: An energy company in Lviv, Ukraine, experienced a disruptive cyberattack early this year that used a new type of Industrial Control Systems (ICS)-focused malware dubbed “FrostyGoop.” This malware is notable for being the first to employ Modbus TCP communications to target operational technology (OT) networks. FrostyGoop can manipulate ICS devices by reading and writing to their registers, affecting inputs, outputs, and configuration data.
Tags: tlp:green