ZeroFox Cyber Intelligence Daily Brief - August 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Iranian Hackers Disguise as Recruitment Firms in Sophisticated Espionage Campaign
- South Korean APT Exploits WPS Office Bug
- ZeroFox Intelligence Flash Report: Israeli Defense Organization Targeted in New Data Breach
Iranian Hackers Disguise as Recruitment Firms in Sophisticated Espionage Campaign
What happened: A sophisticated espionage operation linked to the Iranian Revolutionary Guard used a fake professional-recruiting business to ensnare national security officials from Iran, Syria, and Lebanon. The threat actor, identified as loosely connected to Iranian advanced persistent threat (APT) Charming Kitten (or APT42), has been engaging in this operation since at least 2017.
Why it matters: The threat actor created counterfeit HR companies to lure military and intelligence personnel. These fronts were promoted through fake profiles across social media platforms like Telegram, Twitter, and Virasty. The aim was to identify individuals willing to collaborate with Israel and Western governments. With the current geopolitical scenario dotted with increasing hostilities against Iran, pro-Iranian nation-state actors are increasingly turning to deceptive tactics to infiltrate sensitive networks and extract valuable intelligence. The operation is likely to aid Iran’s efforts in obtaining strategic intelligence for broader operations against states that oppose its ideologies. Moreover, the FBI is investigating the actor's alleged ally APT42’s wider efforts to influence the 2024 U.S. election, which makes the nexus between the two actors a likely part of APT42’s ongoing efforts to interfere with the elections.
South Korean APT Exploits WPS Office Bug
What happened: A critical-severity vulnerability was discovered in a highly popular office software application used in China called WPS Office. CVE-2024-7263 is being exploited in the wild reportedly by a South Korean APT to spy on high-level Chinese entities. In March 2024, a similar flaw (CVE-2024-7262) was exploited in the wild.
Why it matters: CVE-2024-7263 allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized, which leads to the execution of an arbitrary Windows library. The vulnerability has been patched. The WPS app is widely used across China, including in its government agencies, telecommunications companies, and other major entities. A breach into such an application has implications of wide-scale identity theft, sensitive data being leaked, and very likely ransomware attacks as threat actors could leverage confidential state secrets for financial gains and possibly blackmail.
ZeroFox Intelligence Flash Report: Israeli Defense Organization Targeted in New Data Breach
Source: https://www.zerofox.com/advisories/25629/
What happened: ZeroFox Intelligence has observed the Handala hacktivist collective targeting a company that is part of Israel’s military-industry infrastructure. Last week, the hacktivist collective “Handala” posted in deep and dark web (DDW) forums announcing a data breach targeting an Israel-based organization that specializes in the design and development of embedded electronic systems for industrial and military customers. On August 25, Handala posted a subsequent thread revealing a number of allegedly top-secret design schematics related to electronic equipment used by the “Zionist Air Force.”
Why it matters: According to the announcement, Handala successfully exfiltrated approximately 800 GB of source code correlating to “sensitive military systems.” If the stolen information is as described, it is very likely to attract interest from an array of threat actors, from politically impartial cybercriminals seeking to enhance their social engineering campaigns to state-aligned or state-associated actors able to exploit data relating to military hardware and pursue a strategic advantage. Since it was first observed in December 2023, Handala has conducted alleged attacks against a wide range of organizations based in Israel and other countries perceived as sympathetic to Israeli strategic objectives.
DEEP AND DARK WEB INTELLIGENCE
Kill Security ransomware Targets TJS | ZeroFox observed an update on the Kill Security ransomware leak site targeting TJS, a U.S.-based company that provides POS and RFID solutions for the diamond and jewelry industry.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-8255: Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability. Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution.
Affected products: DTN Soft: Version 2.0.1 and prior
CVE-2024-7986: A vulnerability exists in the affected products that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer service to read arbitrary files by creating a junction that points to the target directory.
Affected products:
- ThinManager ThinServer: Versions 11.1.0 to 11.1.7
- ThinManager ThinServer: Versions 11.2.0 to 11.2.8
- ThinManager ThinServer: Versions 12.0.0 to 12.0.6
- ThinManager ThinServer: Versions 12.1.0 to 12.1.7
- ThinManager ThinServer: Versions 13.0.0 to 13.0.4
- ThinManager ThinServer: Versions 13.1.0 to 13.1.2
- ThinManager ThinServer: Versions 13.2.0 to 13.2.1
Tags: DIB, tlp:green