ZeroFox Weekly Intelligence Brief – September 2, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – September 2, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on August 30, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Iranian Hackers Posing as Recruitment Firms in Sophisticated Espionage Campaign
What happened: Cybersecurity researchers have uncovered a sophisticated espionage operation linked to a threat actor with alleged ties to the Iranian Revolutionary Guard that used a fake professional recruiting business to ensnare national security officials from Iran, Syria, and Lebanon. The threat actor, identified as loosely connected to “APT42” or “Charming Kitten,” has been engaging in this operation since at least 2017 and is involved in creating several counterfeit Human Resources (HR) companies, such as VIP Human Solutions and Optima HR, to lure military and intelligence personnel. These fronts were promoted through fake profiles across social media platforms like Telegram, X (formerly Twitter), and Virasty. The aim was to identify individuals willing to collaborate with Israel and Western governments. The Federal Bureau of Investigation (FBI) is investigating APT42’s broader efforts to influence the 2024 U.S. election.
Telegram Channels Propagating Deepfake Pornographic Material Terrorize South Korean Women
What happened: Numerous Telegram chat rooms in South Korea have recently been discovered creating and distributing deepfake pornographic material featuring doctored photos of women, including minors, students, teachers, and military personnel. Many of these chat rooms, some with over 133,000 members, are organized by university names and linked to social media platforms where perpetrators illicitly obtain victim photos. Police investigations have revealed that these groups share bot programs for generating deepfake videos.
Secret Service and FBI Collaboration Places USD 2.5 Million Bounty on Information on Prolific Cybercriminal
What happened: The Secret Service, in collaboration with the U.S. Department of State, has announced a reward of up to USD 2.5 million for information instrumental in arresting or convicting a Belarusian national suspected of several cybercrimes. The individual is reportedly involved in a decade-long malvertising scheme that deployed malware via online ads, compromising millions of devices. In addition to deploying the Angler Exploit Kit (AEK) and other forms of malware, the individual also allegedly engaged in "scareware" ad campaigns. These ads were reportedly aimed at tricking internet users by displaying alarming false messages that claimed to have detected a virus or other critical issue on their devices.
Tags: tlp:green