zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 31, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 31, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Pro-Russia Actors Threaten Paris Olympics
  • Indian APT Targeting Mediterranean Ports and Maritime Facilities
  • HealthEquity Data Breach Exposes Patient Information

ZeroFox Intelligence Flash Report - Pro-Russia Actors Threaten Paris Olympics

Source: https://www.zerofox.com/advisories/24911/

What happened: ZeroFox has observed politically-motivated, primarily pro-Russian threat actors overtly threatening the Paris 2024 Olympic Games in the run-up to the event. The majority of these are hacktivist collectives aiming to disrupt the event by leveraging distributed denial-of-service (DDoS) attacks or discredit the Olympics’ reputation via disinformation campaigns.

Why it matters: Pro-Russian hacktivists are likely to conduct low impact attacks targeting Olympics-related events and states that oppose Russia’s participation in the Games. Russian-aligned actors will likely try to undermine the International Olympic Committee (IOC) via disinformation campaigns. These efforts may result in disruption to the event, dissuade spectators from attending, and create fear among attendees and athletes, leading to reputational damage of the host (France), the IOC, and, by extension, the West. Malicious Pro-Russian cyber activities are likely part of a broader strategic initiative seeking to undermine both France’s security, credibility, and ability to host such a large-scale international event, as well as that of the IOC.

Indian APT Targeting Mediterranean Ports and Maritime Facilities

Source: https://www.securityweek.com/indian-apt-targeting-mediterranean-ports-and-maritime-facilities/

What happened: India-linked threat actor group “SideWinder” has been observed targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. Researchers observed that the group has updated its techniques and tactics over the past year and speculate that the group’s aim is espionage and intelligence gathering.

Why it matters: The group attacked these entities in a phishing campaign where malicious documents were deployed via spear-phishing emails, which then delivered malware. The documents lured users by masquerading as messages from trusted entities like the Port of Alexandria and the Port Authority of the Red Sea. Spear-phishing campaigns are thought to be more effective since they tend to not easily raise alarms and can better evade detection. The phishing emails were successful in luring users as they contained emotive wording that evoked fear and anxiety, forcing employees to click on links to find out more.

HealthEquity Data Breach Exposes Patient Information

Source: https://www.darkreading.com/cloud-security/cyberattackers-accessed-healthequity-customer-info-third-party

What happened: Hackers have breached a third-party data repository of HealthEquity, a Utah-based health savings account (HSA) provider, and exposed 4.5 million customers’ information.

Why it matters: The exposed data comprises personally identifiable information (PII) of the affected individuals, including name, address, phone number, employee ID, employer, Social Security number, and dependent information. The collection of sensitive details will likely attract malicious actors, who could target the victims in social engineering attacks, spear phishing campaigns, and financial scams. The company cut down the adversary’s dwell time by taking immediate action upon being alerted by the third-party vendor. With the healthcare industry under constant threat from hackers, CISA released a report last year highlighting various vulnerabilities in the healthcare sector that could be exploited by threat actors to breach systems and maintain persistent access. The HealthEquity attack comes at the heels of the prominent ransomware attacks targeting the healthcare industry. Moreover, the technique of breaching companies via third-party vendors is gaining more traction among threat actors, as was evident from the Snowflake-related breaches.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user SN_Blackmeta: On July 29, hacktivist group SN_Blackmeta claimed to have conducted a distributed denial of service (DDoS) attack against a Middle Eastern financial institution that lasted for six days. The cyberattack allegedly affected all ministerial and administrative entities, supposedly resulting in the disruption of over 2,960 service domains and more than 370 IP addresses.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • Apple Security Advisories: On Monday, Apple rolled out a significant batch of security updates to fix many vulnerabilities affecting a wide range of iOS and macOS devices, both old and new.

  • Affected products: Safari 17.6, iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Sonoma 14.6, macOS Ventura 13.6.8, macOS Monterey 12.7.6, watchOS 10.6, tvOS 17.6, and visionOS 1.3

Tags: DIB, tlp:green