ZeroFox Cyber Intelligence Daily Brief - August 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cybercriminal Duo Charged After Their Lavish Lifestyles Prompted FBI Investigation
- “Digital Arrest” Scams Threaten Indians
- Ransom Cartel, Reveton Ransomware Owner Arrested and Charged
Cybercriminal Duo Charged After Their Lavish Lifestyles Prompted FBI Investigation
What happened: Two individuals have been charged with conspiracy for trafficking in unauthorized access devices and the possession of 15 or more unauthorized access devices. One of the charged individuals has been arrested, and the authorities are on the lookout for the other one.
Why it matters: The duo individuals had sought and gained asylum after they arrived in Florida. However, soon after gaining asylum, the duo started leading a lavish lifestyle, which prompted an FBI investigation. The investigation revealed that the duos’ unusually large spendings were funded by illicit activities on Dark Web platforms like WWH Club and its related forums, Skynetzone, Opencard, and Center-Club. They were orchestrating a sophisticated operation trafficking in unauthorized access devices and financial data. The platforms they were operating in let cybercriminals buy, sell, and trade login credentials, malware, financial credentials, sensitive information, and more.
“Digital Arrest” Scams Threaten Indians
Source: https://www.theregister.com/2024/08/13/india_digital_arrest_scams/
What happened: Scammers are extorting Indians by posing as officers from the Central Bureau of Investigation (CBI) and asking victims to pay a certain sum to drop alleged charges. The police have arrested three individuals who were involved in one of these scams, where they coerced a Delhi resident into paying over USD 2,000.
Why it matters: By posing as law enforcement officers, scammers tapped into deep-seated fears, such as by coercing a woman into paying a substantial sum to secure her husband's release. Such scams also point to a more sinister threat where malicious actors leverage sensitive personal information and weaponize social engineering and psychological manipulation for financial gain. A similar case occurred in May this year, where scammers in India posing as police officers forced an individual to pay almost USD 120,000 over a period of two months. Notably, with the rise of AI-driven deepfakes and fake payment portals mimicking official websites, cybercriminals will turn to more sophisticated extortion campaigns. Meanwhile, a noted surge in digital spam and phishing calls has prompted India's telecom watchdog to direct service providers to stop all promotional calls from unregistered callers and blacklist them.
Ransom Cartel, Reveton Ransomware Owner Arrested and Charged
What happened: The creator of Ransom Cartel and Reveton ransomware operations is being extradited to the United States to face charges for the creation of the operation as well as for a maladvertising campaign. The operations ran their scheme across many years to distribute malware onto the computers of millions of internet users globally.
Why it matters: Law enforcement activity in taking down key ransomware group operators are instrumental in limiting global cyber activities that cause millions of losses and reputational damage. The Angler Exploit Kit (AEK) itself, deployed in maladvertising campaigns, used in malware campaigns reportedly incurred the perpetrators USD 34 million having infected approximately 100,000 devices. The operation’s owner is to potentially face charges for crimes like wire fraud, computer fraud, computer fraud and abuse, aggravated identity theft, and access device fraud.
DEEP AND DARK WEB INTELLIGENCE
- RAMP/XSS user blackfield: On August 12, moderately credible threat actor "blackfield" advertised a data breach impacting Israel Defense Forces, on the predominantly Russian language Dark Web forums "RAMP" and "XSS."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-38189: A remote code execution flaw in Microsoft Project is being exploited via maliciously rigged Microsoft Office Project files on a system where the “Block macros from running in Office files from the Internet policy” is disabled and “VBA Macro Notification Settings” are not enabled allowing the attacker to perform remote code execution. Microsoft has released this month’s Patch Tuesday and includes six zero-day vulnerabilities reportedly being exploited in the wild.
Affected product: Microsoft Project
CVE-2024-41730: In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability. SAP has released its security advisory for August 2024 and addresses 17 vulnerabilities.
Affected products: SAP BusinessObjects Business Intelligence Platform versions 430 and 440
Tags: DIB, tlp:green