ZeroFox Cyber Intelligence Daily Brief - August 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Kremlin Critics Worldwide Targeted in Hacking Campaigns
- Massive Cyberattack Causes Mass Disruption to Iranian Banking Systems
- UK Royal Family, Prime Minister Deepfakes Make Rounds on Meta
Kremlin Critics Worldwide Targeted in Hacking Campaigns
What happened: Researchers have identified cybercriminals linked to Russian Intelligence targeting critics of the Kremlin around the globe with phishing emails. The phishing campaign is reportedly a part of a sweeping internet espionage operation.
Why it matters: The discovery of the phishing campaign comes as U.S. officials are actively monitoring computer networks to counter cyber threats to the upcoming U.S. elections. Additionally, the campaign indicates a significant escalation in cyber espionage efforts from Russian hacking groups, including Cold River and the newly identified Coldwastrel. The adversaries are employing sophisticated techniques to compromise targets by impersonating trusted contacts. Besides, the targeting of Russian opposition figures-in-exile, former U.S. officials, and nonprofit staff suggests political motivations to infiltrate and disrupt influential networks. The potential access to sensitive information within Russia and abroad raises serious concerns about the broader implications of such cyber espionage activities amid ongoing geopolitical tensions.
Massive Cyberattack Causes Mass Disruption to Iranian Banking Systems
Source: https://securityaffairs.com/167066/hacking/cyberattack-central-bank-of-iran.html
What happened: According to reports, a major cyberattack has hit the Central Bank of Iran and several other Iranian banks, causing widespread disruptions in countrywide banking systems. Initial investigations have reportedly indicated that this could be one of the largest cyberattacks Iranian critical infrastructure has ever faced.
Why it matters: The cyberattack potentially represents a significant escalation in cyber warfare amid escalated geopolitical tensions in the Middle East, especially between Israel and Iran. Even though there was no evidence of any political motive behind the attack at the time of reporting, it is important to note that Iran has been facing intensified scrutiny from international communities. Besides, the attack's scale and targets will likely directly impact the public, who might experience restricted access to their financial resources, leading to distress.
UK Royal Family, Prime Minister Deepfakes Make Rounds on Meta
Source: https://www.darkreading.com/vulnerabilities-threats/uk-royal-family-prime-minister-deepfakes-meta
What happened: Deepfake videos of UK Prime Minister Keir Starmer and Prince William are circulating on Meta platforms, promoting a fraudulent cryptocurrency platform called Immediate Edge. The AI-generated videos falsely portray Starmer endorsing the platform as legitimate, while deepfakes of Prince William supposedly offer the Royal Family's support. The scam aims to deceive viewers by promising substantial financial gains, leveraging the credibility of high-profile figures to lure victims.
Why it matters: A study reveals that since the United Kingdom’s July surprise election, 250 AI-powered disinformation ads promoting a crypto scam have appeared on Meta platforms like Facebook and Instagram. These ads have reached nearly 892,000 people, leading to a collective spend of GBP 21,053. Researchers warn that some ads are still circulating, highlighting the growing threat of AI-generated disinformation campaigns on social media platforms. Stricter content moderation measures are needed, and viewers should remain cautious.
DEEP AND DARK WEB INTELLIGENCE
Exploit/XSS user kiberphant0m: The untested threat actor "kiberphant0m" advertised network access to an unnamed Ukrainian government research server on the predominantly Russian-language Dark Web forums Exploit and XSS.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-34133: Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Additionally, Adobe has released several other security updates to address multiple vulnerabilities in Adobe software including this vulnerability.
Affected products: Illustrator versions 28.5, 27.9.4 and earlier
Tags: DIB, tlp:green