zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – August 19, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – August 19, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on August 16, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Donald Trump's Campaign Alleges Email Hack, FBI Launches Investigation

What happened: Former President Donald Trump's campaign has reported a hack, alleging that Iranian actors were responsible for the theft and dissemination of sensitive internal documents. The Trump campaign attributed the hack to "foreign sources hostile to the United States," suggesting Iranian involvement (which Iran has denied) and the FBI is investigating the matter. Meanwhile, a political media outlet reported receiving internal documents from Donald Trump's campaign via an anonymous AOL account named "Robert." Additionally, a recent threat intelligence report revealed that in June, Iranian government-linked hackers attempted to breach the account of a high-ranking U.S. presidential campaign official.

Law Enforcement Operations Tackle Cybercriminals

What happened: Over the past week, law enforcement (LE) operations have disrupted operations of ransomware group Dispossessor (alias Radar), arrested the creator of Ransom Cartel and Reveton ransomware operations, and put out arrest warrants for two individuals from Florida involved in illicit Dark Web activities. Authorities dismantled three U.S. servers, three United Kingdom servers, 18 German servers, eight U.S.-based criminal domains, and one German-based criminal domain associated with the Dispossessor ransomware operations. The creator of Ransom Cartel and Reveton ransomware operations is being extradited to the United States to face charges for creating the operation and a malvertising campaign. The operations ran their schemes across many years to distribute malware onto the computers of millions of internet users globally. The two individuals from Florida have been charged with conspiracy for trafficking in unauthorized access devices and the possession of 15 or more unauthorized access devices. Authorities have arrested one of the charged and are on the lookout for the other one.

GPS Spoofers Target Commercial Airlines

What happened: A recent surge in GPS spoofing has raised significant concerns about flight safety. Research indicates a 400 percent increase in GPS spoofing incidents affecting commercial airliners in recent months. Many of these incidents reportedly involve illicit ground-based GPS systems, particularly around conflict zones, where they broadcast incorrect positions to the surrounding airspace in an attempt to confuse incoming drones or missiles.

Tags: tlp:green