zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 5, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto
  • China-Nexus APT Steals Documents from and Spies on Taiwanese Research Institute
  • APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure

Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto

Source: https://www.bleepingcomputer.com/news/cryptocurrency/cryptonator-seized-for-laundering-ransom-payments-stolen-crypto/

What happened: U.S. and German law enforcement (LE) seized the domain of Cryptonator, a cryptocurrency wallet platform, and indicted its operator on charges of money laundering and running an unlicensed money service business. The seizure of Cryptonator's primary domain at "cryptonator[.]com" follows its use by ransomware gangs and darknet marketplaces. The Department of Justice (DOJ) alleges that the operator allowed illicit activities on the platform and failed to comply with know-your-customer (KYC) regulations.

Why it matters: The seizure of Cryptonator by LE and partners highlights the growing crackdown on platforms facilitating illegal activities in the cryptocurrency space. By targeting entities linked to ransomware, darknet markets, and other illicit services, authorities aim to disrupt financial networks supporting cybercrime and terrorism. The case emphasizes the importance of stringent KYC regulations and the need for compliance in financial transactions. Additionally, the indictment and potential penalties serve as a warning to other operators of unregulated cryptocurrency services.

China-Nexus APT Steals Documents from and Spies on Taiwanese Research Institute

Source: https://www.darkreading.com/threat-intelligence/chinas-apt41-targets-taiwan-research-institute-for-cyber-espionage

What happened: APT41, a China-linked cyber threat group, has reportedly compromised a Taiwanese government-affiliated research institute in a cyber espionage attack that started in July 2023. The adversary used ShadowPad RAT, Cobalt Strike, and a custom loader exploiting a vulnerability in a popular operating system (CVE-2018-0824) to deploy malware.

Why it matters: China has been at odds against various Southeast Asian countries over territory disputes in the South China Sea. Besides, the new Taiwanese administration's perceived stance on independence has led to an escalation of the geopolitical tensions between Taiwan and China, causing repercussions in the cyber realm as well. China-nexus actors have targeted Taiwanese organizations in cyber espionage campaigns and malicious attacks. The scale and targets of the attacks suggest strategic interference, potentially aimed at gaining political and economic intelligence. Besides, the attack against the research institute also involves the alleged exfiltration of some documents. There might be an additional financial motive fuelling the attack, where the adversary could encrypt the stolen data and place a ransom on the decryption key, as other state-linked actors have previously done. In June, researchers came across threat actors with suspected ties to China and North Korea conducting ransomware attacks as the last stage of their operations for financial gain, misattribution, or evidence removal.

APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure

Source: https://thehackernews.com/2024/08/apt28-targets-diplomats-with-headlace.html

What happened: The Russian threat actor APT28 has been observed using a new phishing campaign where they advertised a car for sale to distribute the HeadLace backdoor malware. This campaign, likely targeting diplomats, began as early as March 2024.

Why it matters: APT28 reportedly has been using diplomatic-car-for-sale themes in their phishing lures, a tactic that has proven effective in getting diplomats to click on malicious content. By capitalizing on the interest of diplomats in such advertisements, APT28 increases the likelihood of successfully infecting their targets with malware. The attacks are characterized by the use of legitimate services such as webhook[.]site and Mocky, which are services used to host a malicious HTML pages.

DEEP AND DARK WEB INTELLIGENCE

Hacktivist group WeRedEvils: Israeli hacktivist group WeRedEvils has reportedly claimed responsibility for an ongoing internet outage in Iran, asserting they infiltrated Iranian computer systems, stole data, and caused widespread disruptions. The group, which emerged in October 2023 following the Gaza war, reported that they had shared the stolen information with the Israeli government. They pointed to the shutdown of Iranian government websites, including ict[.]gov[.]ir, as evidence of their successful attack.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-6242: This vulnerability identified in Rockwell Automation products impacts the Trusted® Slot feature in ControlLogix® controllers. This flaw allows a threat actor to bypass security measures, potentially gaining the ability to execute CIP commands that can alter user projects and/or modify device configurations on any affected module within a 1756 chassis.

Affected product: Versions of ControlLogix, GuardLogix, and 1756 ControlLogix I/O Modules are affected.

CVE-2024-7029: This vulnerability affects Avtech AVM1203 IP cameras with firmware versions FullImg-1023-1007-1011-1009 and earlier. It may also impact other cameras and NVRs from the same company. Exploiting this flaw could enable an attacker to inject and execute commands with the same privileges as the running process owner.

Affected product: Avtech AVM1203 IP cameras with firmware versions FullImg-1023-1007-1011-1009 and earlier

Tags: DIB, tlp:green