zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • White House Releases Roadmap to Enhance Internet Routing Security
  • Chinese Influence Operation Escalates Ahead of U.S. Presidential Election, Targeting Political Divides
  • North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks

White House Releases Roadmap to Enhance Internet Routing Security

Source: https://www.whitehouse.gov/oncd/briefing-room/2024/09/03/press-release-white-house-office-of-the-national-cyber-director-releases-roadmap-to-enhance-internet-routing-security/

What happened: The White House Office of the National Cyber Director (ONCD) released an advisory to better secure internet routing addressing a key security vulnerability associated with the Border Gateway Protocol (BGP), the protocol that supports information routed across networks. The advisory makes recommendations to improve routing security throughout the internet ecosystem.

Why it matters: Several aspects of the internet’s architecture and ecosystem, including the principal technology used to route traffic across the thousands of independent networks that comprise the internet, do not provide adequate security for current cyber threats. This advisory aims to increase the adoption of technologies that address critical vulnerabilities associated with the BGP and drive improvements in internet inter-domain routing security and resilience. Additionally, vulnerabilities in the BGP can lead to BGP hacking where threat actors can maliciously reroute internet traffic. BGP hacking can cause internet traffic to be monitored or intercepted leading users to potentially malicious sites in an attempt to access their credentials and other sensitive data. Critical infrastructure, and communications, are especially vulnerable to malicious actors aiming to exploit these BGP vulnerabilities and can cause disruptive and damaging changes in the routing of internet traffic.

Chinese Influence Operation Escalates Ahead of U.S. Presidential Election, Targeting Political Divides

Source: https://www.reuters.com/world/us/us-voters-targeted-by-chinese-influence-online-researchers-say-2024-09-03/

What happened: A Chinese state-linked influence operation, known as "Spamouflage" or "Dragonbridge," is impersonating U.S. voters and spreading divisive content targeting both major political parties ahead of the November 5 presidential election. The operation, active since 2017, has recently intensified, using thousands of accounts across over 50 platforms to push propaganda and incite political tensions.

Why it matters: Spamouflage is a testimony to evolving foreign efforts designed to interfere with the U.S. elections, wherein operations directly exploit and deepen existing political and societal divisions in the country. Unlike its past attempts, Spamouflage is increasingly successful at engaging real Americans, especially supporters of former President Trump. Additionally, operations like Spamouflage make it harder for voters to discern truth from misinformation. The dissemination of misleading content, the reach of the campaigns, and the deceptive strategies employed—including impersonation and viral video manipulation— are likely to mislead voters and influence public opinion. Besides, such operations are likely to complicate efforts to maintain a fair and transparent electoral system and potentially sway outcomes.

North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks

Source: https://www.ic3.gov/Media/Y2024/PSA240903

What happened: The FBI has issued an advisory warning about North Korea’s sophisticated social engineering campaigns targeting employees in the decentralized finance (DeFi) and cryptocurrency sectors. These attacks are designed to deploy malware and steal cryptocurrency. The advisory details North Korean social engineering tactics, indicators of such activity, recommended mitigations, and steps to take in case of a suspected North Korea-linked social engineering attack.

Why it matters: North Korean cyber actors use complex social engineering schemes to target cryptocurrency and DeFi sectors, including cryptocurrency exchange-traded funds (ETFs). Their sophisticated tactics and extensive research on targets suggest a high level of threat to companies with significant cryptocurrency assets. These state-sponsored actors are known for their elaborate and technical approach, making them a significant threat even to those well-versed in cybersecurity practices. The advisory provides essential information on identifying and mitigating these attacks, helping organizations protect valuable cryptocurrency assets. By understanding and preparing for these threats, companies can better safeguard their networks and reduce the risk of significant financial losses. This approach is vital in defending against the persistent and evolving strategies employed by North Korean cyber actors.

DEEP AND DARK WEB INTELLIGENCE

Telegram user RipperSec: Religiously motivated hacktivist group RipperSec claims to have formed an alliance with Garuda Error System and Nomercy Black Hat groups. ZeroFox has observed several threat actor groups forming alliances with other groups. For example, pro-Russia hacktivist group DoubleFace claims to have formed an alliance with Cyber Army of Russia. The alliances are likely a strategic move to bolster their combined resources and extend their influence.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7261: Zyxel has issued patches to fix an operating system (OS) command injection vulnerability found in certain versions of their access points (APs) and security router versions. This flaw, caused by improper neutralization of special elements in the "host" parameter of the CGI program, could allow unauthenticated attackers to execute OS commands by sending a specially crafted cookie to a vulnerable device.

Affected products: The affected products and versions have been listed by Zyxel in this security update.

Tags: DIB, tlp:green