zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 8, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 8, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • White House Releases Roadmap to Enhance Internet Routing Security
  • North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks
  • Revival Hijack Method Abuses Abandoned PyPI Packages

White House Releases Roadmap to Enhance Internet Routing Security

Source: https://www.whitehouse.gov/oncd/briefing-room/2024/09/03/press-release-white-house-office-of-the-national-cyber-director-releases-roadmap-to-enhance-internet-routing-security/

What happened: The White House Office of the National Cyber Director (ONCD) released an advisory to better secure internet routing addressing a key security vulnerability associated with the Border Gateway Protocol (BGP), the protocol that supports information routed across networks. The advisory makes recommendations to improve routing security throughout the internet ecosystem.

Why it matters: Several aspects of the internet’s architecture and ecosystem, including the principal technology used to route traffic across the thousands of independent networks that comprise the internet, do not provide adequate security for current cyber threats. This advisory aims to increase the adoption of technologies that address critical vulnerabilities associated with the BGP and drive improvements in internet inter-domain routing security and resilience. Additionally, vulnerabilities in the BGP can lead to BGP hacking where threat actors can maliciously reroute internet traffic. BGP hacking can cause internet traffic to be monitored or intercepted leading users to potentially malicious sites in an attempt to access their credentials and other sensitive data. Critical infrastructure, and communications, are especially vulnerable to malicious actors aiming to exploit these BGP vulnerabilities and can cause disruptive and damaging changes in the routing of internet traffic.

North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks

Source: https://www.ic3.gov/Media/Y2024/PSA240903

What happened: The FBI has issued an advisory warning about North Korea’s sophisticated social engineering campaigns targeting employees in the decentralized finance (DeFi) and cryptocurrency sectors. These attacks are designed to deploy malware and steal cryptocurrency. The advisory details North Korean social engineering tactics, indicators of such activity, recommended mitigations, and steps to take in case of a suspected North Korea-linked social engineering attack.

Why it matters: North Korean cyber actors use complex social engineering schemes to target cryptocurrency and DeFi sectors, including cryptocurrency exchange-traded funds (ETFs). Their sophisticated tactics and extensive research on targets suggest a high level of threat to companies with significant cryptocurrency assets. These state-sponsored actors are known for their elaborate and technical approach, making them a significant threat even to those well-versed in cybersecurity practices. The advisory provides essential information on identifying and mitigating these attacks, helping organizations protect valuable cryptocurrency assets. By understanding and preparing for these threats, companies can better safeguard their networks and reduce the risk of significant financial losses. This approach is vital in defending against the persistent and evolving strategies employed by North Korean cyber actors.

Revival Hijack Method Abuses Abandoned PyPI Packages

Source: https://www.darkreading.com/application-security/revival-hijack-on-pypi-disguises-malware-with-legitimate-file-names

What happened: Cybersecurity researchers have discovered a method called “Revival Hijack” to abuse the PyPI package repository by re-registering previously removed package names to distribute malicious code. Attackers can take over these abandoned packages, upload their malicious versions, and disguise them as legitimate updates, tricking organizations into downloading them.

Why it matters: According to researchers, Revival Hijack potentially threatens almost 120,000 susceptible packages on PyPI. The technique does not rely on user error and can bypass traditional defenses, making it difficult to detect and prevent. Attackers can infiltrate development environments and compromise the integrity of software supply chains, likely leading to widespread malware distribution in enterprise environments through systems that assume updates are safe. Even with precautions, nearly 200,000 downloads of intentionally empty packages demonstrate the prevalence of outdated or liable scripts.

Tags: DIB, tlp:green