ZeroFox Cyber Intelligence Daily Brief - September 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- FTC: Large Social Media and Video Streaming Companies Have Inadequate Safeguards for Minors
- Europol Dismantles Phishing Network That Claimed 480,000 Victims Globally
- Phishing Espionage Attack Targets U.S.-Taiwan Defense Conference
FTC: Large Social Media and Video Streaming Companies Have Inadequate Safeguards for Minors
What happened: A Federal Trade Commission (FTC) report reveals that major social media and video streaming platforms are engaged in extensive surveillance of consumers, collecting vast amounts of personal data to monetize through targeted advertising. These companies are not only retaining large amounts of user data indefinitely but also sharing it broadly, raising concerns about their data handling controls.
Why it matters: The staff report concluded that the social media and video streaming services did not adequately protect children and teens on their sites. The report cited research that found social media and digital technology contributed to negative mental health impacts on young users. The platforms' prioritization of profit over privacy raises concerns about user consent, control over personal data, and potential exploitation. With vast amounts of sensitive information being gathered, there is an increased risk of misuse, such as unauthorized data sharing, security breaches, and targeted manipulation through advertising. For vulnerable groups, particularly minors, this can exacerbate privacy violations and online exploitation. The findings call for stricter regulations and better transparency to ensure the protection of users’ rights and data privacy.
Europol Dismantles Phishing Network That Claimed 480,000 Victims Globally
Source: https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16319#
What happened: An international law enforcement operation, "Operation KAERB," dismantled a criminal network using the iServer phishing-as-a-service platform to unlock stolen or lost mobile phones. The phishing network targeted 483,000 victims globally, primarily Spanish-speaking individuals, by harvesting credentials to unlock stolen phones. Operation KAERB, initiated in 2022, led to the arrest of 17 suspects in multiple countries and the seizure of 921 items.
Why it matters: Automated phishing platforms that operate as services enable even low-skilled criminals to abuse stolen devices. The iServer network targeted over 1.2 million phones, severely impacting victims by bypassing security measures. By phishing their targets, attackers collected all the necessary information to unlock phones, such as device passwords, user credentials, and personal details, allowing them to bypass "Lost Mode" and unlawfully disconnect devices from their rightful owners. It allowed stolen phones to be resold or further exploited by other criminals. Such a vast crimeware service, deploying a single platform and accessible to thousands of criminals, demonstrates the scalability of these malicious operations. Victims of such campaigns are very likely to face privacy breaches and long-term financial repercussions from threat actors abusing the exposed data.
Phishing Espionage Attack Targets U.S.-Taiwan Defense Conference
Source: https://www.darkreading.com/cyberattacks-data-breaches/espionage-attack-us-taiwan-defense-conference
What happened: A phishing attack targeting the 23rd U.S.-Taiwan Defense Industry Conference was thwarted after the U.S.-Taiwan Business Council received a malicious forgery of its own registration form, which contained fileless malware designed to execute in memory. The attack aimed to compromise the council's systems through a deceptive email from an impersonator.
Why it matters: This incident reveals the persistent cyber threats faced by organizations involved in defense and national security, particularly in the context of U.S.-Taiwan relations. The 23rd U.S.-Taiwan Defense Industry Conference will gather influential figures from government, defense, academia, and commercial sectors to discuss critical topics such as U.S. defense cooperation with Taiwan, defense procurement processes, and Taiwan’s national security needs. A successful phishing attack could have jeopardized sensitive discussions and compromised valuable insights shared among these key stakeholders, potentially undermining strategic collaborations and trust. The use of sophisticated fileless malware indicates a growing sophistication among cyber adversaries, potentially linked to state-sponsored actors. Effective countermeasures, like the council's diligent anti-phishing preparations, are essential in safeguarding against these evolving threats, ensuring that defense collaborations can proceed without disruption.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user IntelBroker: Well-known threat actor "IntelBroker" claimed to be selling access to several crypto exchanges in Thailand, Japan, and China for USD 400 million on BreachForums. The alleged access includes Azure Vault, databases, AMQP, AWS S3, AWS SES, AWS Cognito, IBM HPSB, Redis, GitHub, FireBlocks, KeyPairs, and CI/CD pipelines.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-6404: Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.
Affected products: Telenium Online Web Application versions 8.3 and prior
Tags: DIB, tlp:green