ZeroFox Cyber Intelligence Daily Brief - September 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Scammers Target Former President Trump Digital Trading Cards in Phishing Scheme
- Experts Identify Three Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia
- Russian and Kazakhstani Men Indicted for Running Dark Web Criminal Marketplaces, Forums, and Trainings
Scammers Target Former President Trump Digital Trading Cards in Phishing Scheme
Source: https://hackread.com/fake-domains-trump-supporters-trading-card-scam/
What happened: Scammers are targeting collectors of former President Donald Trump‘s digital trading cards through fake websites, domain typosquatting, email phishing, and social engineering to exfiltrate sensitive information or install malware. The counterfeit sites mimic the official URL of the trading card website with subtle variations, tricking users into falling for fraudulent schemes.
Why it matters: In this operation, scammers lure and mislead victims with fake URLs such as trumpdigitaltradingcards[.]xyz and collecttrunpcards[.]com by mimicking legitimate sites with subtle spelling differences. With the rise of digital assets, scams targeting high-profile projects, especially those tied to political figures, have significant consequences. As the U.S. elections approach, cybercriminals will leverage the heightened political intensity and voter interests in presidential candidates—including former President Trump—in financially motivated scams. Such attacks can not only compromise sensitive personal data, but can also erode public trust in digital platforms, especially those involved directly or indirectly in electoral processes, such as campaigning or fundraising. Besides, eroding public confidence in legitimate platforms will likely motivate other similar malicious actors to conduct further attacks targeting electoral campaigns.
Experts Identify Three Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia
Source: https://thehackernews.com/2024/09/experts-identify-3-chinese-linked.html
What happened: The Crimson Palace espionage campaign, linked to China, has expanded its operations across Southeast Asia, targeting more government organizations in the region. This cluster of state-sponsored intrusion sets involves three threat activity clusters, using compromised public service and organizational networks to deliver malware and tools disguised as trusted access points.
Why it matters: The Crimson Palace campaign is observed to involve targeting entities with multi-cluster attacks, which allows Chinese state-sponsored actors to infiltrate and remain undetected in sensitive government systems. This method enables attackers to infiltrate sensitive government systems undetected, increasing the reach and impact of their espionage activities while deepening their hold in Southeast Asian nations. By using compromised organizational networks as command and control (C2) relay points and leveraging tools, attackers can stage longer and more covert operations. This allows the threat actors to steal sensitive government data, manipulate public service networks, and have a likely influence on geopolitical outcomes in Southeast Asian nations where these operations are focused. The potential for long-term access and data exfiltration poses significant national security risks for the targeted countries.
Russian and Kazakhstani Men Indicted for Running Dark Web Criminal Marketplaces, Forums, and Trainings
What happened: A Russian and a Kazakhstani individual were indicted for operating WWH Club, a dark web marketplace used for illegal activities like selling stolen personal information and disseminating cyber fraud techniques. The site reportedly had approximately 353,000 users globally, adding to the individuals’ earnings from membership fees, tuition fees, and advertising.
Why it matters: By dismantling WWH Club, authorities disrupt a major hub that provided tools and knowledge to a global network of cybercriminals, potentially preventing further financial damage and identity theft for countless individuals. The sale and trade of stolen personal identifying information (PII), credit card, and bank account data likely exposed millions of people to identity theft, financial fraud, and other forms of compromise. These dark web marketplaces usually provide both emerging and experienced cybercriminals resources and additional information to refine and expand their operations, potentially coming up with more sophisticated methods for conducting cyberattacks, evading law enforcement, and causing reputational and personal harm.
Tags: DIB, tlp:green