zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 22, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 22, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackers
  • Russian Propaganda Reportedly Behind Fake Hit-and-Run News About VP Kamala Harris
  • ZeroFox Intelligence Flash Report - New Exploitation of Existing Vulnerability Announced for Sale

U.S. Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackers

Source: https://www.justice.gov/usao-wdpa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state

What happened: The U.S. Department of Justice (DOJ) announced the successful disruption of a botnet comprising over 200,000 consumer devices, which were infected by state-sponsored hackers from the People’s Republic of China, operating through a company known as Integrity Technology Group. Meanwhile, Europol, Australian Federal Police (AFP), and global law enforcement agencies have shut down Ghost, an encrypted communication platform used by criminal networks worldwide, and arrested an individual accused of creating and managing the platform.

Why it matters: This botnet disruption reveals the ongoing threat from state-sponsored cyber actors, particularly from China, who exploit consumer devices for large-scale malicious activities. The malware linked thousands of infected devices into a botnet controlled by Integrity Technology Group, enabling harmful actions disguised as normal internet traffic. A law enforcement operation took control of the hackers' infrastructure and issued disabling commands to the malware, despite a failed DDoS attack aimed at disrupting these efforts. By disrupting the botnet, law enforcement not only reduced immediate risks but also demonstrated international cooperation among cybersecurity agencies. In the Ghost takedown operation, the AFP infiltrated Ghost and tampered with regular software updates sent by the administrator, effectively planting malware that allowed it to access and monitor the content on the devices in Australia. Information from this led to raids across four Australian states, resulting in 38 arrests, seizure of weapons, and prevention of drug distribution.

Russian Propaganda Reportedly Behind Fake Hit-and-Run News About VP Kamala Harris

Source: https://www.reuters.com/world/us/fake-kamala-hit-and-run-story-is-work-russian-propaganda-group-microsoft-says-2024-09-17/

What happened: Cybersecurity researchers have associated Russia with a disinformation operation falsely claiming that Vice President and Democratic Presidential candidate Kamala Harris left a child paralyzed in a hit-and-run incident in San Francisco in 2011. Russian group Storm-1516 reportedly created a video featuring an actor posing as the alleged victim. This video spread through a fake news website, "KBSF-TV," and was shared widely on social media, gaining millions of views.

Why it matters: State-sponsored disinformation campaigns, especially the ones targeting the Presidential candidates, aim to sow division, create mistrust among the electorate, and exacerbate existing political divides. By fabricating stories and using actors to impersonate victims, such tactics can effectively manipulate public opinion, making it difficult for individuals to discern truth from misinformation. Besides, Russia has intensified its effort to interfere in the U.S. elections, which will play a crucial role in shaping the geopolitical landscape of the near future. As an adversarial state, Russia is likely attempting to influence voter opinions, and thereby manipulate election results to favor its standing in the West. The most recent disinformation operation also aligns with broader Russian strategies to undermine U.S. support for Ukraine and exploit political divisions.

ZeroFox Intelligence Flash Report - New Exploitation of Existing Vulnerability Announced for Sale

Source: https://www.zerofox.com/advisories/26120/

What happened: On September 6, 2024, an actor known as “skng” posted in the dark web forum xss advertising a new malicious script that is allegedly designed to target Fortinet software solutions. The product allegedly enables the exploitation of an existing critical vulnerability known as CVE-2022-40684, which was discovered in early October 2022.

Why it matters: If successfully exploited, CVE-2022-40684 can allow the attacker to gain access to privileged administrative interfaces without being in possession of legitimate credentials. Shortly after the vulnerability’s discovery, mitigating software patches were released alongside customer advisory notices. The vast majority of network exploitation leverages old or existing vulnerabilities that have since been remedied by software manufacturers. Threat actors are able to both capitalize on the users that have not conducted the appropriate software updates and leverage malicious Deep and Dark Web services that specialize in uncovering and monetizing new methods of exploiting existing and patched vulnerabilities, such as the script offered by skng.

Tags: DIB, tlp:green