zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian and Kazakhstani Men Indicted for Running Dark Web Criminal Marketplaces, Forums, and Trainings
  • North Korean Actors Utilize Networking Sites for COVERTCATCH Malware Attacks
  • Russian Media Outlet Accused of Using U.S. and Other Personalities to Sway 2024 Election

Russian and Kazakhstani Men Indicted for Running Dark Web Criminal Marketplaces, Forums, and Trainings

Source: https://www.justice.gov/usao-mdfl/pr/russian-and-kazakhstani-men-indicted-running-dark-web-criminal-marketplaces-forums-and

What happened: A Russian and a Kazakhstani individual were indicted for operating WWH Club, a dark web marketplace used for illegal activities like selling stolen personal information and disseminating cyber fraud techniques. The site reportedly had approximately 353,000 users globally adding to the individuals’ earnings from membership fees, tuition fees, and advertising.

Why it matters: By dismantling WWH Club, authorities disrupt a major hub that provided tools and knowledge to a global network of cybercriminals, potentially preventing further financial damage and identity theft for countless individuals. The sale and trade of stolen personal identifying information (PII), credit card, and bank account data likely exposed millions of people to identity theft, financial fraud, and other forms of compromise. These dark web marketplaces may have given emerging and experienced cybercriminals resources and additional information to refine and expand their operations, potentially coming up with more sophisticated methods for conducting cyberattacks, evading law enforcement, and causing reputational and personal harm.

North Korean Actors Utilize Networking Sites for COVERTCATCH Malware Attacks

Source: https://thehackernews.com/2024/09/north-korean-threat-actors-deploy.html

What happened: North Korea-linked threat actors exploited a professional networking site to target developers with a fake job recruiting scheme. They initiated contact through a seemingly legitimate conversation and sent a ZIP file containing COVERTCATCH malware, disguised as a Python coding challenge. Once executed, malware initiates a multi-stage attack, compromising macOS systems by installing additional malicious payloads and establishing persistence.

Why it matters: This tactic exemplifies how cybercriminals manipulate professional networks for malicious ends, blurring the lines between genuine job opportunities and cyber threats. With the increasing pressure on individuals to secure employment, they are more likely to fall victim to scams, compromising their personal and professional security. Threat actors exploit this vulnerability by using job recruitment platforms as a prime avenue for their schemes. By infiltrating systems and maintaining long-term access, these attacks pose significant risks to both individual and organizational security. To protect from fake job scams, verify job offers through official company channels, withhold personal information until the offer’s authenticity is confirmed, and be vigilant about any requests for payment or sensitive details.

Russian Media Outlet Accused of Using U.S. and Other Personalities to Sway 2024 Election

Source: https://www.reuters.com/world/us/russia-china-iran-trying-influence-us-election-intelligence-official-says-2024-09-06/

What happened: Russian media outlet RT is reportedly using Western personalities to influence American voters, favoring former President Donald Trump over Vice President Kamala Harris in the presidential election. The United States has also charged two RT employees with money laundering, alleging their involvement in paying an American firm to produce divisive online content. Both Russia and RT have denied these accusations.

Why it matters: With the U.S. elections about two months away, there is a very likely increase in foreign influence campaigns trying to exploit the political divides affecting voter opinions. RT’s alleged campaign utilizes a blend of state and private actors and networks of American and other personalities to dissuade voters from supporting Vice President Harris and sway them to backing former President Trump. The tactics employed in the operation indicate increased sophistication in foreign electoral interference, which could destabilize electoral processes and erode public trust in election integrity. U.S. law enforcement authorities have discovered and disrupted several other foreign interference and influence efforts—including from China, Iran, and other Russian campaigns. Meanwhile, in response to allegations against RT, Russia has stated it would place restrictions on U.S. media outlets in Russia.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user IntelBroker: The well-known and established threat actor "IntelBroker" claimed to have leaked a database associated with Prime Healthcare in the United States on the predominantly English-language dark web forum BreachForums. The leaked data package allegedly contains information related to prescriptions, full names, email addresses, SSNs, phone numbers, addresses, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7591: This bug lets remote attackers, who have access to the management interface of LoadMaster, issue a carefully crafted http request that will allow arbitrary system commands to be executed. It has been given the highest CVSS score of 10.

Affected product: LoadMaster 7.2.60.0 and all prior versions; Multi-Tenant Hypervisor 7.1.35.11 and all prior versions

Tags: DIB, tlp:green