ZeroFox Cyber Intelligence Daily Brief - August 2, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 2, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: AI-Powered Tool to Target Cryptocurrency Wallets in Development
- DDoS Attacks: Could Hinder Access to Election Information, Would Not Prevent Voting
- UK Takes Down Major “Russian Coms” Caller ID Spoofing Platform
ZeroFox Intelligence Flash Report: AI-Powered Tool to Target Cryptocurrency Wallets in Development
Source: https://www.zerofox.com/advisories/24975/
What happened: On July 25, 2024, untested threat actor “Michelangelo” posted in a dark web forum advertising a new artificial intelligence (AI)-powered malicious tool designed to facilitate attacks targeting cryptocurrency wallets.
Why it matters: The tool lists an array of features that enable various methods of obtaining passwords associated with victims’ cryptocurrency wallets. An emphasis is also placed upon user convenience, flexibility, and management of attack processes. While tools with brute-forcing and password-mining capabilities are not new, this tool allegedly contains innovative features that reflect an appetite amongst cybercriminals to develop and commercialize malicious techniques able to target the growing cryptocurrency economy.
DDoS Attacks: Could Hinder Access to Election Information, Would Not Prevent Voting
Source: https://www.ic3.gov/Media/Y2024/PSA240731
What happened: The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an announcement to raise awareness that Distributed Denial of Service (DDoS) attacks on election infrastructure, or adjacent infrastructure that support election operations, could hinder public access to election information but would not impact the security or integrity of election processes.
Why it matters: These low-level attacks, expected to continue as the 2024 U.S. general election approaches, could disrupt the availability of some election-related functions, like voter look-up tools or unofficial election night reporting, during the election cycle but will not impact voting itself. Threat actors may falsely claim that DDoS attacks indicate a compromise related to the elections process as they seek to undermine confidence in U.S. elections. If foreign actors or cyber criminals conduct DDoS attacks against election infrastructure or other infrastructure supporting election administration, the underlying data and internal systems would remain uncompromised, and anyone eligible to vote would still be able to cast a ballot.
UK Takes Down Major “Russian Coms” Caller ID Spoofing Platform
What happened: The United Kingdom’s law enforcement agency has recently taken down a Russia-linked caller ID spoofing service. This service is reportedly responsible for allowing hundreds of threat actors to carry out more than a million scam calls.
Why it matters: Russian Comms offered threat-actor buyers with services like the ability to make encrypted calls, web phone, voice changing services, international calls, and 24/7 support. According to the UK’s National Crime Agency (NCA), cyber criminals were able to hide their identity behind the fake identities of financial institutions, telecommunications companies, and law enforcement agencies. Since 2021, the financial loss has been suspected of amounting to tens of millions across 170,000 victims in the UK. In social engineering attacks like this one, threat actors are likely to use the information for account takeovers, unauthorized transactions, and further creating fake identities. Impersonating genuine institutions and companies makes it easy for adversaries to trick people into divulging sensitive information and carrying out actions that they normally would not. In this case, scammers also convinced victims through impersonation to steal funds for goods which were never delivered and also gained full access to bank accounts.
DEEP AND DARK WEB INTELLIGENCE
Telegram user SN_Blackmeta: Threat actor SN_Blackmeta has claimed to have conducted a DDoS attack targeting the Europol website. The actor claims that the attack has lasted for more than two hours.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-32931: This medium severity bug in exacqVision Web Service can expose authentication token details within communications under certain circumstances.
Affected products: exacqVision Web Service Versions 24.03 and prior
Tags: DIB, tlp:green