ZeroFox Cyber Intelligence Daily Brief - September 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Sanctions Key Players in Intellexa Consortium for Predator Spyware Distribution
- CISA Warns of Windows Flaw Used in Infostealer Malware Attacks
- Chinese National Charged for Multi-Year “Spear-Phishing” Campaign
U.S. Sanctions Key Players in Intellexa Consortium for Predator Spyware Distribution
Source: https://home.treasury.gov/news/press-releases/jy2581
What happened: The U.S. Treasury Department imposed sanctions on five individuals and one entity tied to the Intellexa Consortium, the developer of Predator spyware and manager of entities supplying Predator to foreign governments. The sanctions target the consortium's efforts to evade previous sanctions and continue selling the spyware through complex corporate structures.
Why it matters: Predator spyware, which can access sensitive data on targets' devices without user interaction, is likely deployed as part of political and strategic schemes against adversarial states. The sanctions imposed on Intellexa are a direct response to its illicit global operations, selling Predator to state actors and governments. Predator has been used to target journalists, politicians, and government officials across multiple countries, including within the U.S. government. Its capabilities for zero-click attacks likely allow it to silently infiltrate smartphones and maintain persistent access, threatening individual privacy and state security. Despite previous sanctions, Intellexa continues to sell the spyware. The U.S. government aims to disrupt the spyware economy and discourage technical talent from entering this exploitative industry.
CISA Warns of Windows Flaw Used in Infostealer Malware Attacks
Source: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461
What happened: U.S. federal agencies are being warned of a Windows spoofing zero-day bug (CVE-2024-43461) exploited by the Void Banshee APT group. The flaw has been patched in this month’s Microsoft Patch Tuesday.
Why it matters: CISA recently added this vulnerability to its known exploited vulnerability (KEV) catalog based on evidence of active exploitations. The vulnerability allows remote attackers to carry out arbitrary code on unpatched Windows systems by tricking the targets into visiting a malicious web page or into opening a malicious file. These types of vulnerabilities are reportedly frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. CISA urges both federal agencies and enterprises to implement the patch to limit further exposure to future attacks.
Chinese National Charged for Multi-Year “Spear-Phishing” Campaign
Source: https://www.justice.gov/usao-ndga/pr/chinese-national-charged-multi-year-spear-phishing-campaign
What happened: A Chinese national was indicted on charges of wire fraud and aggravated identity theft for a multi-year spear phishing campaign. He allegedly impersonated U.S.-based researchers and engineers to fraudulently obtain restricted computer software and source code from National Aeronautics and Space Administration (NASA), research universities, and private companies. The accused was employed as an engineer at Aviation Industry Corporation of China (AVIC)—one of the largest global defense contractors and a major manufacturer of both civilian and military aircraft—and conducted these activities while working there.
Why it matters: The theft of sensitive software from organizations like NASA and private companies poses a serious risk to national security and defense capabilities, given that the stolen technology could be used in advanced weapons and military applications. The involvement of AVIC raises concerns about potential industrial espionage and the misuse of technological advancements. The accused's emails sought access to specialized software and source code. This theft could enhance missile and weapon development, posing a serious threat to national security.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user "infamous" | Threat actor infamous claimed to be selling a database associated with the Thailand Police for USD 1,000 on the predominantly English-language dark web forum BreachForums. Allegedly, the leaked database contains information such as names, phone numbers, genders, and ID card numbers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-45694: The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. Additionally, D-Link has released updates for four more vulnerabilities in its three wireless router models that allow remote attackers to execute arbitrary code or access the devices using hardcoded credentials.
Affected products: DIR-X4860 A1 firmware version 1.00, 1.04
Tags: DIB, tlp:green