ZeroFox Cyber Intelligence Daily Brief - August 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- APT28 Targets Diplomats with HeadLace Malware via Car-Sale Phishing Lure
- ZeroFox Intelligence Flash Report - Malicious Stealer Log Marketplace Advertised for Sale
- Threat Actor Targets Iranian Entities in Politically Motivated Attacks
APT28 Targets Diplomats with HeadLace Malware via Car-Sale Phishing Lure
Source: https://thehackernews.com/2024/08/apt28-targets-diplomats-with-headlace.html
What happened: The Russian threat actor APT28 has been observed using a new phishing campaign where they advertised a car for sale to distribute the HeadLace backdoor malware. This campaign, likely targeting diplomats, began as early as March 2024.
Why it matters: APT28 reportedly has been using diplomatic-car-for-sale themes in their phishing lures, a tactic that has proven effective in getting diplomats to click on malicious content. By capitalizing on the interest of diplomats in such advertisements, APT28 increases the likelihood of successfully infecting their targets with malware. The attacks are characterized by the use of legitimate services such as webhook[.]site and Mocky, which are services used to host malicious HTML pages.
ZeroFox Intelligence Flash Report - Malicious Stealer Log Marketplace Advertised for Sale
Source: https://www.zerofox.com/advisories/25125/
What happened: On July 30, 2024, user “2Easy.Shop” (which is almost certainly synonymous with the official handle of the malicious marketplace 2EasyShop) announced in a deep and dark web (DDW) forum that the stealer log marketplace is available for purchase.
Why it matters: 2EasyShop—described by the poster as a “ready-made, configured, highly profitable business”—is a DDW marketplace that specializes in advertising and selling stealer logs, which are compilations of information that have been stolen from devices and networks infected with malware. Given the very likely growing demand among various types of cyber threat actors for the information contained within stealer logs, it is likely that a sale will take place. If the auction fails, there is a roughly even chance that the site will remain closed until a sale occurs. A successful deal at the asking price would very likely reinvigorate 2EasyShop, resulting in more reliable service, an increased supply of logs, and higher volume of sales that almost certainly pose a threat to individuals and organizations.
Threat Actor Targets Iranian Entities in Politically Motivated Attacks
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/68100
What happened: Threat actor group Anonymous KSA claimed to have compromised the Iranian Foreign Ministry's service distributor and Iran's military and civil aviation data. The leaked data allegedly includes IP addresses, names, and personnel movements.
Why it matters: Anonymous KSA cited the attack on the Iranian entities as a “response to the negative Iranian position” regarding the death of Hamas’ political chief Ismail Haniyeh. The leaked data will likely attract the attention of more actors with the same political motivations to target affected individuals in malicious attacks. It can also incite politically opposed threat actors to retaliate. Anonymous KSA group has previously targeted several entities in Saudi Arabia, driven by its political inclination towards the pro-Palestinian cause. Tensions between Israel and Iran have further escalated since the deaths of Haniyeh and a senior Hezbollah official, Fuad Shukr, amid the ongoing Israel-Hamas war. These conflicts continue to have repercussions in the cyber world, with various politically inclined actors declaring their support for either side and conducting attacks to further their agenda.
Tags: DIB, tlp:green