zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 5, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Cracks Down on Russian Disinformation Before 2024 Election
  • Revival Hijack Method Abuses Abandoned PyPI Packages
  • Planned Parenthood Confirms Cyberattack as RansomHub Threatens to Leak Data

U.S. Cracks Down on Russian Disinformation Before 2024 Election

Source: https://www.bleepingcomputer.com/news/security/us-cracks-down-on-russian-disinformation-before-2024-election/

What happened: The U.S. Department of Justice (DOJ) reported that the FBI has seized 32 web domains associated with the Doppelgänger network, an influence operation involved in spreading disinformation to influence public opinion ahead of the U.S. elections. Reports indicate that Doppelgänger is connected to Russian entities controlled by the Russian Presidential Administration.

Why it matters: The FBI's seizure of 32 domains linked to the Doppelgänger network is a critical step in protecting the upcoming U.S. presidential election. This network's disinformation campaign, which utilized fake news sites and deceptive social media strategies, aimed to undermine U.S. democracy by disseminating pro-Russian propaganda. By targeting U.S. voters as well as influencing elections in Germany, Mexico, and Israel, Doppelgänger sought to manipulate public opinion and affect electoral outcomes. The widespread use of counterfeit media and misleading tactics demonstrates the ongoing threat of foreign interference in democratic processes. Combating these tactics is vital to preserving the integrity and fairness of elections both in the United States and globally. The DOJ indicted two Russian nationals for running a USD 10 million scheme with a state-controlled media outlet, distributing pro-Russia propaganda through nearly 2,000 YouTube videos, seen over 16 million times, and also sharing content on TikTok, Instagram, and X (formerly Twitter).

Revival Hijack Method Abuses Abandoned PyPI Packages

Source: https://www.darkreading.com/application-security/revival-hijack-on-pypi-disguises-malware-with-legitimate-file-names

What happened: Cybersecurity researchers have discovered a method called “Revival Hijack” to abuse the PyPI package repository by re-registering previously removed package names to distribute malicious code. Attackers can take over these abandoned packages, upload their malicious versions, and disguise them as legitimate updates, tricking organizations into downloading them.

Why it matters: According to researchers, Revival Hijack potentially threatens almost 120,000 susceptible packages on PyPI. The technique does not rely on user error and can bypass traditional defenses, making it difficult to detect and prevent. Attackers can infiltrate development environments and compromise the integrity of software supply chains, likely leading to widespread malware distribution in enterprise environments through systems that assume updates are safe. Even with precautions, nearly 200,000 downloads of intentionally empty packages demonstrate the prevalence of outdated or liable scripts.

Planned Parenthood Confirms Cyberattack as RansomHub Threatens to Leak Data

Source: https://www.theregister.com/2024/09/04/planned_parenthood_cybersecurity_incident/

What happened: Investigations are currently underway at Planned Parenthood after a cyberattack targeted the company. The ransomware group RansomHub claimed responsibility for the breach, claiming that it has stolen 93 GB of data and is threatening to leak it unless a ransom is reportedly paid within seven days. In response, Planned Parenthood has initiated its incident response protocols, including taking parts of its network offline as a precautionary security measure. The organization is working to assess the extent of the breach and mitigate any potential damage.

Why it matters: Planned parenthood is a non profit organization that provides healthcare services including abortions and treatment for sexually transmitted diseases. Any type of leaked data can be extremely sensitive given the anonymity preferred by individuals seeking such services. Such data if leaked can have other threat actors contacting victims in possibly blackmail and extortion campaigns where the victim will likely have very little choice in paying the bad actor’s demands to protect their identities. Individuals who have sought services at the clinic could become targets of harassment, doxxing, or even violence likely for hacktivist groups or individuals opposed to abortion. This breach not only threatens the privacy of those affected but also raises concerns about their personal safety in a political landscape where the right to have abortions is heavily opposed by many.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user Dark Storm Team: Pro-Palestine threat actor group Dark Storm Team has claimed to have conducted a DDoS (distributed denial-of-service) attack against the website of Emirates Post in the United Arab Emirates.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-20469: A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on an affected device.

  • Affected products: Cisco Identity Services Engine (ISE)

Tags: DIB, tlp:green