zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 27, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • UserSec and People's CyberArmy Claim to DDoS French Websites
  • Telegram Channels Propagating Deepfake Pornographic Material Terrorize South Korean Women
  • AMD’s Internal Data Listed for Sale on Dark Web

UserSec and People's CyberArmy Claim to DDoS French Websites

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/69131

What happened: Pro-Russian threat actor group UserSec announced a series of cyberattacks (in collaboration with People's CyberArmy) against the websites of various entities in France as a response to the arrest of Telegram CEO Pavel Durov.

Why it matters: DDoS has traditionally been associated with hacktivism and is often a method to advertise their stand for causes. Pavel Durov’s arrest comes after several serious illegal activities like drug trafficking and child porn were unveiled. It is likely that further investigations may be in place to begin to weed out threat actors and other criminals proliferating so far under the protection Telegram seemingly offered them. Hacktivists have been observed to conduct high-visibility attacks to amplify the cause of their supported ideology. With law enforcement cracking down on the Telegram co-founder, such groups—with evolving disruptive capacities—are likely to increase their activities.

Telegram Channels Propagating Deepfake Pornographic Material Terrorize South Korean Women

Source: https://m-en.yna.co.kr/view/AEN20240826009600315

What happened: Numerous Telegram chat rooms in South Korea are creating and distributing deepfake pornographic material featuring doctored photos of ordinary women. These chat rooms, some with over 133,000 members, target women from various age groups and backgrounds, including middle school, high school, and university students, teachers, and even military personnel.

Why it matters: The chat rooms are categorized by the names of different South Korean universities and the perpetrators used popular social media platforms to illicitly save photos of victims that were used to create AI-generated deepfakes. South Korean authorities have been tackling similar cases, which seem to be on the rise with increasing ease of access to AI tools. Social media posts exposing the matter claim that several victims of the chat room and those who are speaking against the deepfakes are now being doxxed on several platforms, where their identities and personal information are being exposed. It could lead to serious physical threats, as individuals with malicious intent are likely to seek out such sensitive details to deploy in targeted operations.

AMD’s Internal Data Listed for Sale on Dark Web

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/69121

What happened: ZeroFox Intelligence observed IntelBroker, in conjunction with EnergyWeaponUser, leaking a database allegedly associated with Advanced Micro Devices (AMD), a well-known U.S.-based semiconductor manufacturing company, on BreachForums. The actor claims that AMD suffered a data breach earlier this week, leading to the exposure of information related to its internal communications. The actor also claimed that the data came from multiple sources, including “idmprod.xilinx[.]com" and "amdsso.okta[.]com."

Why it matters: Attacks on semiconductor companies are significant because these firms produce key components used in a wide range of technology, from everyday gadgets to critical defense systems. Given the semiconductor industry's role, stolen internal communications can be leveraged for various malicious activities, including sabotaging supply chains, stealing cutting-edge technology, threatening national security, undermining market positions, and manipulating financial markets. Additionally, this data can be used for corporate espionage, phishing attacks, operational disruption, or ransom demands. The alleged data from various sources suggests a more extensive and damaging breach, offering a broader view of an organization’s operations and vulnerabilities. IntelBroker was previously also observed targeting AMD a few months ago, marking it as a repeated and ongoing target.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user IntelBroker: Well-known and established threat actor "IntelBroker" has claimed to have leaked a database associated with South Africa's official eTender website on the predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7965: Google patched its tenth zero-day vulnerability of 2024. It is a high-severity flaw in Chrome's V8 JavaScript engine that allows remote exploitation via crafted HTML pages.

Affected products: Chrome 128.0.6613.84 (Linux) 128.0.6613.84/.85( Windows, Mac)

CVE-2024-31214: Traccar, an open-source GPS tracking system, has a critical vulnerability (CVSS score: 9.7) in versions 5.1 through 5.12 that allows arbitrary file uploads via the device image upload API. Attackers can fully control the file contents, directory, and file extension, and partially control the file name. Although existing files cannot be overwritten, attackers can create new files with chosen names and extensions anywhere on the file system, potentially leading to remote code execution, XSS, or DOS attacks. This issue is exacerbated by Traccar's default settings, which enable self-registration and run with root/system privileges, increasing the risk of exploitation. Version 6.0 addresses this vulnerability, and disabling self-registration by default can significantly reduce the severity of such vulnerabilities.

Affected products: Traccar versions 5.1 to 5.12

Tags: DIB, tlp:green