zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Attackers Hijack Facebook Pages, Promote Malicious AI Photo Editor
  • Scammers Disguising as Cryptocurrency Exchanges, FBI Warns
  • Cybercriminals Target Venezuelan President Website in DDoS Attack

Attackers Hijack Facebook Pages, Promote Malicious AI Photo Editor

Source: https://www.darkreading.com/cyberattacks-data-breaches/attackers-hijack-facebook-pages-promote-malicious-ai-photo-editor

What happened: Attackers have hijacked Facebook pages to promote a fake artificial intelligence (AI) photo editor, leading victims to download an endpoint management utility disguised as the editor. This utility installs the Lumma stealer, which steals sensitive information such as credentials and browser data.

Why it matters: The malvertising campaign has resulted in over 17,000 downloads across various systems, demonstrating how attackers exploit popular trends like AI technology and leverage social media platforms to deceive users. As social media platforms continue to grow, threat actors could increasingly use these channels for sophisticated phishing, social engineering, and other malicious activities, making it crucial for users to be vigilant. The Lumma stealer's ability to harvest sensitive information, including credentials, system details, and browser data, poses significant security risks. Threat actors could potentially extend this approach by targeting other popular technologies and platforms, employing similar tactics to exploit trending topics and widely-used services. This could involve using fake promotions for other utilities, leveraging emerging technologies, or adapting to new social media trends to increase their reach and effectiveness. To avoid falling victim to malicious campaigns exploiting social media, users are advised to enable multi-factor authentication (MFA), use strong and unique passwords, and monitor accounts for unusual activity.

Scammers Disguising as Cryptocurrency Exchanges, FBI Warns

Source: https://www.ic3.gov/Media/Y2024/PSA240801

What happened: The FBI has warned about scammers impersonating cryptocurrency exchange employees to steal funds. Scammers contact victims through unsolicited calls or messages, create a sense of urgency, and deceive victims into revealing login credentials. The scammers then access victims' accounts and steal their cryptocurrency.

Why it matters: This scam can cause significant harm by exploiting trust and urgency to steal sensitive information. Victims, believing they are securing their accounts, provide login details to scammers, who then access and drain their cryptocurrency holdings. The financial losses can be substantial, as stolen digital assets are difficult to recover. It can also lead to corrosion of trust in legitimate cryptocurrency exchanges, making people wary of engaging in the crypto market and potentially hindering its growth and adoption. The FBI's advisory stresses the importance of verifying identities and avoiding unsolicited communications to protect digital assets. Besides, the tactic of disguising as legitimate cryptocurrency exchanges indicates broader trends of cybercriminals exploiting new avenues to steal cryptocurrency. In June, the FBI issued another advisory, warning people about scammers creating fake jobs with a complicated pay system that tricked victims into making cryptocurrency payments to earn more money or access work. These payments, of course, ended up going straight to the scammer.

Cybercriminals Target Venezuelan President’s Website in DDoS Attack

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67931

What happened: Threat actor group CyberHunters claimed to have conducted a distributed denial-of-service (DDoS) attack against Venezuelan President Nicolas Maduro’s website in response to the presidential elections, which saw Maduro win a controversial third term.

Why it matters: On July 29, President Nicolás Maduro declared himself the winner of the presidential elections. Since then, there have been mass protests across the country, and in recent days, there has been an uptick in state-backed violence against protesters. The protests have subsequently rolled on to the digital realm, with threat actors like CyberHunters conducting cyberattacks in support of protesters calling for Maduro to step down. The group has also declared its intent to conduct future attacks. At the time of reporting, the targeted website does not seem to be loading.

DEEP AND DARK WEB INTELLIGENCE

Exploit user “huyase”: On July 30, the untested threat actor "huyase" advertised an auction for personally identifiable information (PII) of 5,000 U.S. citizens on the predominantly Russian language Dark Web forum "Exploit." According to huyase, the data includes photo, social security number (SSN), name, address, date of birth, driver license of people living in the state of Tennessee. The starting bid for the PII data was USD 1,000, with a minimum bid of USD 200 and an instant purchase price of USD 3,000.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-5143: A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 up to 20151231. This issue affects some unknown processing of the file /log/webmailattach.php. The manipulation of the argument table_name leads to an unknown weakness. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240239. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected products: D-Link DAR-7000 to 20151231

Tags: DIB, tlp:green