ZeroFox Cyber Intelligence Daily Brief - August 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- UK Royal Family, Prime Minister Deepfakes Make Rounds on Meta
- South Korea Says North Korea Hackers Stole Spy Plane Technical Data
- Fake X Content Warnings on Earthquakes and War Lure Users to Scam Sites
UK Royal Family, Prime Minister Deepfakes Make Rounds on Meta
Source: https://www.darkreading.com/vulnerabilities-threats/uk-royal-family-prime-minister-deepfakes-meta
What happened: Deepfake videos of UK Prime Minister Keir Starmer and Prince William are circulating on Meta platforms, promoting a fraudulent cryptocurrency platform called Immediate Edge. The AI-generated videos falsely portray Starmer endorsing the platform as legitimate, while deepfakes of Prince William supposedly offer the Royal Family's support. The scam aims to deceive viewers by promising substantial financial gains, leveraging the credibility of high-profile figures to lure victims.
Why it matters: A study reveals that since the United Kingdom’s July surprise election, 250 AI-powered disinformation ads promoting a crypto scam have appeared on Meta platforms like Facebook and Instagram. These ads have reached nearly 892,000 people, leading to a collective spend of GBP 21,053. Researchers warn that some ads are still circulating, highlighting the growing threat of AI-generated disinformation campaigns on social media platforms. Stricter content moderation measures are needed, and viewers should remain cautious.
South Korea Says North Korea Hackers Stole Spy Plane Technical Data
What happened: South Korea’s ruling party People Power Party (PPP) has called for additional security measures to strengthen national security after reports of North Korea stealing key information about certain spy planes. Reportedly, a South Korean defense contractor that produces manuals for military equipment including the two spy planes was hacked, endangering details about technology, upgrades, operation capabilities, and other data.
Why it matters: The PPP has called for a revision of existing criminal law to include foreign countries in the application of its espionage laws. Data leaked about the military units (including the spy planes) has a likely chance of North Korea strategically upgrading its arsenal to better evade military surveillance and improve its tactics against South Korea. It is worth noting that in the past South Korea observed several breaches into defense companies allegedly conducted by North Korea-linked threat actors like Lazarus, Andariel, and Kimsuky. South Korea’s companies have been under significant threat at least since 2022, according to South Korea’s National Police Agency. These breaches have reportedly occurred thanks to weak network protection as well as inadequate security precautions like reusing passwords, making it vital for South Korea to invest in mechanisms to not only better track suspicious cyber activities but also anticipate and identify DPRK’s cyberattacks as they happen.
Fake X Content Warnings on Earthquakes and War Lure Users to Scam Sites
What happened: Through fake content warnings on X posts, seemingly regarding the Ukraine war and earthquake warnings in Japan, scammers are luring users into clicking their way to scam adult sites, malicious browser extensions, and shady affiliate sites.
Why it matters: The fake content warnings on posts with sensational information are images with malicious links. By exploiting users' trust in urgent, seemingly credible information, like news about the Ukraine war or Japanese earthquake warnings, these tricks, though not new, can cause serious harm. By luring people into clicking fake content warnings, scammers can redirect them to malicious sites that could steal personal information, install harmful software, or trick them into buying counterfeit services. The implications likely include financial loss, privacy breaches, or device exposure to other malicious adversaries. Additionally, users will likely lose trust in genuine content warnings on social media, making it harder to discern real threats from scams.
Tags: DIB, tlp:green