ZeroFox Cyber Intelligence Daily Brief - September 1, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- UserSec and People's CyberArmy Claim to DDoS French Websites
- CISA and Partners Release Advisory on Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
- Hackers Use Rare Stealth Techniques to Down Asian Military, Govt Orgs
UserSec and People's CyberArmy Claim to DDoS French Websites
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/69131
What happened: Pro-Russian threat actor group UserSec announced a series of cyberattacks (in collaboration with People's CyberArmy) against the websites of various entities in France as a response to the arrest of Telegram CEO Pavel Durov.
Why it matters: DDoS has traditionally been associated with hacktivism and is often a method to advertise their stand for causes. Pavel Durov’s arrest (and subsequent bail for an amount of USD 55,39,475) comes after accusations of serious illegal activities like drug trafficking and child porn on the Telegram. It is likely that further investigations may be in place to begin to weed out threat actors and other criminals proliferating so far under the protection Telegram seemingly offered them. Hacktivists have been observed to conduct high-visibility attacks to amplify the cause of their supported ideology. With law enforcement cracking down on the Telegram co-founder, such groups—with evolving disruptive capacities—are likely to increase their activities. Amidst the situation surrounding the arrest, the United Arab Emirates (UAE) had announced that the government is in touch with both French authorities and representatives of Durov (who reportedly holds several citizenships, including UAE).
CISA and Partners Release Advisory on Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
What happened: CISA and the FBI released an advisory warning that Iranian cyber actors, known in the private sector as “Pioneer Kitten,” are targeting and exploiting U.S. and foreign organizations across multiple sectors in the United States. The FBI previously observed these actors attempt to monetize their access to victim organizations on cyber marketplaces. A significant percentage of the group’s U.S.-focused cyber activity is in furtherance of obtaining and maintaining technical access to victim networks to enable future ransomware attacks.
Why it matters: The FBI assesses a significant percentage of these threat actors’ operations against U.S. organizations intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors to be associated with the Government of Iran (GOI) and—separate from the ransomware activity—they are known to conduct computer network exploitation activity in support of the GOI (such as intrusions enabling the theft of sensitive technical data against organizations in Israel and Azerbaijan).
Hackers Use Rare Stealth Techniques to Down Asian Military, Govt Orgs
What happened: A new cyberattack campaign is targeting key organizations in Southeast Asia using two advanced techniques that are not widely known. The first technique, called GrimResource, allows hackers to inject malicious code into a tool used to manage a widely used operating system. The second method, AppDomainManager Injection, involves inserting harmful files in a more streamlined way than traditional methods.
Why it matters: Although these techniques have existed in the past—reportedly used by Iran-linked threat actors, China, penetration testers, and others—they are not often seen in campaigns in the wild. A group of hackers has been observed using these methods to launch attacks on the IT systems of Taiwanese government agencies, the Philippine military, and energy companies in Vietnam. Their objective appears to be gaining control over these systems, endangering national data, personally identifiable information (PII), civilian safety, and resources.
Tags: DIB, tlp:green