zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – September 9, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – September 9, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on September 6, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Chinese Influence Operation Targeting Political Divides Escalates Ahead of U.S. Presidential Election

What happened: A Chinese state-linked influence operation known as "Spamouflage" or "Dragonbridge" is impersonating U.S. voters and spreading divisive content targeting both major political parties ahead of the November 5 U.S. presidential election. The operation, active since 2017, has recently intensified and is using thousands of accounts across over 50 platforms to push propaganda and incite political tensions. Earlier this year, researchers discovered the same operation using artificial intelligence (AI) and social media to amplify chaos narratives, such as "civil war" or the collapse of democracy, and depicting both President Biden and former President Trump in negative, aggressive lights. The posts lack clear partisan bias but criticize both leaders regarding the same parameters. The long-running campaign likely aims to sow deep distrust among the voter community by portraying the United States as beset by social issues like urban decay, homelessness, drug abuse, and gun violence.

Global Malware Campaign “Voldemort” Mimics Tax Authorities to Spread Malware

What happened: A global malware campaign named "Voldemort" has been targeting organizations with phishing emails that primarily impersonate tax authorities across Europe, Asia, and the United States. This custom C backdoor malware is designed for data exfiltration and deploying additional malicious payloads. This malicious campaign has reportedly impacted numerous organizations globally, with over 20,000 phishing messages documented since it first emerged on August 5.

FBI Seizes Russian-Led Disinformation Network Ahead of U.S. Elections

What happened: The U.S. Department of Justice recently announced that the Federal Bureau of Investigation (FBI) seized 32 web domains used by the “Doppelgänger” network, a Russian-linked influence operation that was running a disinformation campaign targeting the American public ahead of this year's presidential election. According to court documents, the Doppelgänger network is connected to Russian companies like Social Design Agency (SDA), Structura National Technology (Structura), and ANO Dialog, which are all believed to be under the control of the Russian presidential administration. The network used these domains (managed via the Vesta open-source hosting control panel) to spread Russian government propaganda aimed at promoting pro-Russian policies. This included attempts to reduce international support for Ukraine and influence elections not only in the United States but also in Germany, Mexico, Israel, and other nations. This operation highlights the continued threat of foreign interference in democratic processes and the spread of disinformation.

Tags: tlp:green