zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Pro-Russia Actors Threaten Paris Olympics
  • USDoD Releases CrowdStrike Data in Retaliation to “Direct Attack”
  • PKFail Secure Boot Bypass Issue Compromises Millions of Devices

ZeroFox Intelligence Flash Report: Pro-Russia Actors Threaten Paris Olympics

Source: https://www.zerofox.com/advisories/24911/

What happened: ZeroFox has observed politically-motivated, primarily pro-Russian threat actors overtly threatening the Paris 2024 Olympic Games in the run-up to the event. The majority of these are hacktivist collectives aiming to disrupt the event by leveraging distributed denial-of-service (DDoS) attacks or discredit the Olympics’ reputation via disinformation campaigns.

Why it matters: Pro-Russian hacktivists are likely to conduct low impact attacks targeting Olympics-related events and states that oppose Russia’s participation in the Games. Russian-aligned actors will likely try to undermine the International Olympic Committee (IOC) via disinformation campaigns. These efforts may result in disruption to the event, dissuade spectators from attending, and create fear among attendees and athletes, leading to reputational damage of the host (France), the IOC, and, by extension, the West. Malicious Pro-Russian cyber activities are likely part of a broader strategic initiative seeking to undermine both France’s security, credibility, and ability to host such a large-scale international event, as well as that of the IOC.

USDoD Releases CrowdStrike Data in Retaliation to “Direct Attack”

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67694

What happened: On July 29, the threat actor “USDoD” claimed to have leaked a list of 100,000 Indicator of Compromise (IOC) associated with CrowdStrike on the predominantly English-language dark web forum BreachForums. The leaked data includes IOCs, types, malware families, actors, kill chains, and other proprietary CrowdStrike intelligence.

Why it matters: The threat actor USDoD, on July 24, 2024, had warned of leaking CrowdStrike’s Indicator of Compromise (IoC) list after they had scrapped it earlier. An almost neutral CrowdStrike article about the threat actor supposedly instigated them to release data that was already available to possibly a larger audience. This disclosure might affect CrowdStrike’s business dealings with its clients and compromise the exclusiveness of the curated data. Making proprietary data public can also help threat actors better avoid detection. The threat actor also claimed access to CrowdStrike’s “report on threat intel” which they seem to be withholding, at the time of writing, as potential blackmail material.

PKFail Secure Boot Bypass Issue Compromises Millions of Devices

Source: https://www.theregister.com/2024/07/29/infosec_roundup/

What happened: A critical security vulnerability named “PKFail” in the Secure Boot process had made millions of Intel and ARM microprocessor-based computing systems vulnerable. Attackers can potentially bypass the Secure Boot process because of misused test Platform Keys (PK) in production devices.

Why it matters: The exposure of private keys will likely make the systems vulnerable to low-level malware attacks that would go undetected by OS-level antimalware protections. An attacker could leverage the vulnerability to trick the Windows UEFI framework into accepting a malicious OS installation as genuine and replace the existing OS with one filled with malware. However, the attacker would first need full system access, meaning they would already have control of the machine. This vulnerability primarily facilitates persistent attacks, enabling long-term access even after thorough anti-malware efforts and a re-install. Users have been advised to update their firmware and follow security best practices to prevent the initial breach needed for such an attack.

Tags: DIB, tlp:green