ZeroFox Weekly Intelligence Brief – August 12, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – August 12, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on August 9, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
INTERPOL Recovers over USD 40 Million Stolen in a BEC Attack
What happened: INTERPOL's global stop-payment mechanism, I-GRIP, enabled Singapore authorities to recover USD 42.3 million in the largest-ever business email compromise (BEC) scam recovery. A Singapore-based commodity firm fell victim to the scam after receiving a fraudulent email from a threat actor impersonating one of the firm’s suppliers. The email requested that a pending payment be sent to a new bank account in Timor Leste. Four days later, the firm realized its mistake when the real supplier reported non-payment. The Singapore Police initiated INTERPOL’s I-GRIP, coordinating with authorities to retrieve the stolen funds.
U.S. Department of State Seeking Information on Hacktivist-Led ICS Attack
What happened: The U.S. Department of State is offering a USD 10 million reward in exchange for information on senior officials of Iran’s Islamic Revolutionary Guard Corps’ Cyber-Electronic Command unit (IRGC-CEC), who are accused of being behind a hacker group named “Cyber Av3ngers” that has targeted industrial control systems (ICS). In November 2023, the Cybersecurity and Infrastructure Security Agence (CISA) released an advisory acknowledging the active exploitation of Unitronics programmable logic controllers (PLCs) used in the Water and Wastewater Systems (WWS) sector, including an identified Unitronics PLC at a U.S. water facility. In response to the attack, the affected municipality water authority had to take the system offline and switch to manual processes. In December, CISA released another advisory attributing the attack to self-proclaimed hacktivist group Cyber Av3ngers, which by then had also claimed responsibility. The IRGC-CEC-affiliated cyber actors had left a defacement image stating, “You have been hacked, down with Israel. Every equipment made in Israel is CyberAv3ngers legal target.” On February 2, 2024, the U.S. Department of the Treasury announced sanctions against the six IRGC-CEC officials for their malicious cyber activities.
French Police Probe Ransomware Attack on Grand Palais Olympic Venue
What happened: French cybercrime police are probing a ransomware attack on the Grand Palais Réunion des musées nationaux (Rmn) in Paris, where Olympic events like fencing and Taekwondo are being held. The central computer system (which also oversees data for 40 smaller museums) was targeted, but no disruption to the Olympic events occurred.
Tags: tlp:green