zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 27, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Transnational Organized Crime Rewards Program Offers for Two Russian Nationals and Sanctions on Illicit Russian Virtual Currency Exchanges and Cybercrime Facilitator
  • Kia Dealer Portal Flaw Could Let Attackers Hack Millions of Cars
  • CISA Warns of Hurricane-Related Scams

Transnational Organized Crime Rewards Program Offers for Two Russian Nationals and Sanctions on Illicit Russian Virtual Currency Exchanges and Cybercrime Facilitator

Source: https://www.state.gov/transnational-organized-crime-rewards-program-offers-for-two-russian-nationals-and-sanctions-on-illicit-russian-virtual-currency-exchanges-and-cybercrime-facilitator/

What happened: The Department of State is rewarding USD 10 million for the information leading to the arrests and/or convictions of two Russian nationals for participating in transnational organized crime. The Department of the Treasury is sanctioning one of the individuals and Russia-operating virtual currency exchange Cryptex, and issuing an order that identifies PM2BTC as being of “primary money laundering concern” in connection with Russian illicit finance.

Why it matters: These actions are part of a coordinated international effort to disrupt Russian cybercrime services and are being taken in conjunction with actions by other U.S. government agencies and international law enforcement partners. This effort targets key actors and infrastructure facilitating Russian-linked cybercrime. The sanctions aim to disrupt cybercriminal networks and cut off their financial source that they rely on to continue other illicit activities. The targeting of actors who have provided money laundering services for top-tier cybercriminals for nearly two decades, aims to disrupt their ability to operate freely. Without reliable money-laundering services, cybercriminals face increased difficulty in converting illicit gains into usable assets, potentially slowing down their operations. These actions have been successful in the past in the effort to counter cybercrime, and to monitor and disrupt financial systems supporting cybercriminals globally.

Kia Dealer Portal Flaw Could Let Attackers Hack Millions of Cars

Source: https://thehackernews.com/2024/09/hackers-could-have-remotely-controlled.html

What happened: Security researchers identified critical vulnerabilities (now patched) in Kia's dealer portal that could enable hackers to find and potentially steal millions of Kia vehicles made after 2013 using only the license plate number. These flaws allow unauthorized individuals to remotely control affected cars in less than 30 seconds.

Why it matters: These vulnerabilities exposed sensitive personal information of Kia owners, including names, phone numbers, email addresses, and physical addresses. With access to this data, malicious actors could engage in identity theft, phishing attacks, and more. Moreover, the ability to add themselves as a second user on the targeted vehicles without the owners' consent increases the risk of unauthorized control.

CISA Warns of Hurricane-Related Scams

Source: https://www.cisa.gov/news-events/alerts/2024/09/25/cisa-warns-hurricane-related-scams

What happened: CISA has warned about threat actors that will likely take advantage of the interests and tensions surrounding Hurricane Helene to entrap U.S. citizens in scams, like spear phishing, fraud schemes, and business email compromise (BEC)-enabled attacks.

Why it matters: Fraudulent emails and social media messages—often containing malicious links or attachments—are common after major natural disasters. Individuals and organizations will likely see emails with hurricane-related subject lines, attachments, or hyperlinks. In addition, malicious actors are likely to post social media pleas, send texts, or even conduct door-to-door solicitations relating to severe weather events. CISA has urged users to be wary and remain vigilant of such activities.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Stormous: Threat actor group Stormous announced that its official channel, previously used to communicate their objectives, had allegedly been taken down by unspecified entities.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-9166: Successful exploitation of this critical (CVSS score: 9.3) OS command injection vulnerability could allow an unauthorized attacker to execute system commands with elevated privileges.

Affected products: Atemio AM 520 HD TitanNit versions 2.01 and prior

Tags: DIB, tlp:green