ZeroFox Cyber Intelligence Daily Brief - August 10, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 10, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Researchers Report Iran Hackers Targeting U.S. Officials Before Election
- University Professors Targeted by North Korean Cyber Espionage Group
- U.S.-Based Security Systems Provider Suffers Breach Exposing 30,000 Customers’ Data
Researchers Report Iran Hackers Targeting U.S. Officials Before Election
What happened: Iranian government-linked hackers attempted to breach the account of a high-ranking U.S. presidential campaign official in June, following a previous attack on a county-level U.S. official's account in May. The hackers employed a "password spray operation" to compromise the county official's account and used spear-phishing tactics against the campaign official.
Why it matters: With the upcoming U.S. presidential elections, cyberattackers are ramping up their efforts, intensifying attacks and influence campaigns to sway public opinion and disrupt the electoral process. Interference from foreign threat actors is anticipated to be a significant factor in the upcoming U.S. election. By exploiting existing societal divisions and undermining trust in democratic institutions, the threat actors aim to disrupt the electoral process and favor specific outcomes. The targeting of high-level campaign officials and county government employees suggests a strategic move to gain intelligence on political campaigns and potentially manipulate election outcomes. The creation of deceptive news sites further indicates a broader strategy to sow political discord and influence public opinion across the political spectrum. Russia-linked accounts have also been observed spreading divisive content targeting U.S. audiences.
University Professors Targeted by North Korean Cyber Espionage Group
Source: https://thehackernews.com/2024/08/university-professors-targeted-by-north.html
What happened: The North Korea-linked threat actor Kimsuky has been linked to a new wave of attacks aimed at university staff, researchers, and professors to gather intelligence. These attacks utilize compromised hosts to deploy an obfuscated version of the Green Dinosaur web shell, which is then used for file operations. The access gained is further exploited to upload phishing pages that mimic legitimate login portals for several universities, enhancing their phishing efforts to steal sensitive information from targeted individuals.
Why it matters: The operation reportedly revealed Kimsuky's deployment of a custom tool called SendMail used to send phishing emails from compromised accounts. These emails were aimed at tricking recipients into divulging their login credentials, advancing Kimsuky's espionage objectives. Researchers recommend users enable phishing-resistant multi-factor authentication (MFA) and carefully examine URLs before logging in to mitigate the risk of such attacks.
U.S.-Based Security Systems Provider Suffers Breach Exposing 30,000 Customers’ Data
Source: https://www.securityweek.com/physical-security-firm-adt-confirms-hack-and-data-breach/
What happened: ADT, a U.S.-based provider of alarm and other physical security systems for homes and small businesses, was targeted in a data breach where hackers stole over 30,000 customer records. On August 1, ZeroFox intelligence observed threat actor "netnsher" claiming to have leaked an ADT-linked database, containing 30,812 records.
Why it matters: The company stated that the attack did not compromise customers’ home security systems or personally sensitive information such as credit card details or banking information. However, it did expose some databases containing customer order information. Meanwhile, netnsher claims the leaked database includes unique emails, addresses, user IDs, and products bought. The exposed personal data creates opportunities for identity theft and fraud, potentially causing financial harm to affected individuals. Additionally, threat actors might leverage the stolen data for future cyberattacks, including phishing scams and targeted malware distribution, exploiting the compromised information to gain unauthorized access to accounts or perpetuate further breaches.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user "HikkI-Chan" : Threat actor HikkI-Chan claimed to have leaked a database associated with Israel's Ministry of Defence on the predominantly English-language dark web forum BreachForums. The actor claims to possess tens of thousands of documents, emails, and images, including communications, financial and purchase details, technical information, and more. The threat actor did not disclose the source or method of the data breach.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-32113: It is a critical (CVSS score: 9.8/10.0) path traversal vulnerability in Apache OFBiz that could allow remote code execution. CISA has warned that this bug is being exploited in the wild.
Affected products: Apache OFBiz versions before 18.12.13
Tags: DIB, tlp:green