ZeroFox Cyber Intelligence Daily Brief - September 10, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 10, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Polish Security Neutralizes Sabotage Attempts Linked to Russia and Belarus
- Payment Gateway Data Breach Affects 1.7 Million Credit Card Owners
- “TIDrone” Cyberattackers Target Taiwan's Drone Manufacturers
Polish Security Neutralizes Sabotage Attempts Linked to Russia and Belarus
What happened: Polish security services have successfully neutralized a cyber sabotage mission originating in Russia and Belarus, reportedly aimed at destabilizing Poland. Saboteurs—allegedly based in Belarus and collaborating with Russia—infiltrated local and central government institutions, including state-owned companies that handle military contracts. The development comes at a time when cyberattacks targeting states and entities supporting Ukraine in the Russia-Ukraine war have increased.
Why it matters: Russian state-sponsored cyberattacks targeting its adversarial states have increased amid heightened concerns about the ongoing Russia-Ukraine war, likely as an alternative response strategy to traditional warfare. Allegedly Russia-born attacks targeting Poland, including the sabotage operation, are also very likely linked to the role of Poland in supplying aid to Ukraine. However, Russia has repeatedly denied these allegations. Reports suggest that the sabotage operation was designed to extort information, to blackmail individuals or companies, and “to wage a de facto cyberwar.” In June, Poland declared ffunds of over 3 billion zlotys (USD 760 million) to strengthen its cybersecurity following a suspected Russian cyberattack on the state news agency PAP. Russia-linked attacks against EU allies of Ukraine are not uncommon. Germany, another EU member, has also warned about a Russian military-linked cyber group, UNC2589, targeting NATO and EU nations with cyberattacks. Collaborating with U.S. agencies, the warning echoes the increasing threat from Russian espionage and sabotage activities.
Payment Gateway Data Breach Affects 1.7 Million Credit Card Owners
What happened: Slim CD, a payment gateway provider, experienced a data breach affecting 1.7 million individuals. In its notification to affected clients, the company revealed that its network had been compromised by hackers for nearly a year, spanning from August 2023 to June 2024.
Why it matters: Slim CD has identified that the breach may have impacted personal information such as names, addresses, credit card numbers, and card expiration dates. While the credit card verification values (CVVs) were not exposed, there remains a risk of credit card fraud and identity theft. As payment gateway providers like Slim CD are increasingly relied upon for online transactions, this breach could lead to a higher likelihood of fraudulent transactions and potential financial losses for users. Individuals affected, who likely interacted with businesses using Slim CD’s payment services rather than the company directly, should stay alert for any signs of suspicious activity. They are urged to promptly report any suspicious activity to their card issuers.
“TIDrone” Cyberattackers Target Taiwan's Drone Manufacturers
Source: https://www.darkreading.com/ics-ot-security/tidrone-cyberattackers-taiwan-drone-manufacturers
What happened: Drone manufacturers in Taiwan are being targeted by a Chinese threat group dubbed as “TIDrone.” The group is also reportedly deploying malware toward military and satellite targets globally. They are observed distributing their proprietary malware through enterprise resource planning (ERP) software.
Why it matters: TIDrone poses a significant threat to their targets. Once they have compromised a device, it takes specific measures like deploying user account control (UAC) bypass techniques to disable antivirus products, making mitigations and detection potentially challenging. The group’s targets are vulnerable to a range of cyberattacks such as GPS spoofing, command and control (C2) interception, and signal jamming. The group’s continuous improvement of its attack chain and use of anti-analysis techniques likely show a growing sophistication that necessitates organizations and individuals to track and counter this group’s activities.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user LulzSec: Pro-Palestine threat actor group LulzSec Black claimed to have accessed documents and PDF files associated with the City of Moraine, the United States.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2016-3714: This bug allows remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." CISA added it to its Known Exploited Vulnerabilities Catalog on September 9.
Affected product: ImageTragick
CVE-2024-40766: An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. Ransomware affiliates are actively exploiting this bug. SonicWall has released the patch for the bug and has urged users to urgently deploy the patch.
Affected products: SonicWall Firewall Gen 5 and Gen 6 devices; SonicWall Firewall Gen 7 devices running SonicOS 7.0.1-5035 and older versions
Tags: DIB, tlp:green