ZeroFox Cyber Intelligence Daily Brief - October 4, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 4, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Cyber Threats to the U.S. Elections
- International Counter Ransomware Initiative 2024 Joint Statement
- United States Seizes Russian Spy Domains in Major Cyber Espionage Crackdown
ZeroFox Intelligence Brief - Cyber Threats to the U.S. Elections
Source: https://www.zerofox.com/advisories/26721/
What happened: The cyber risks to the upcoming U.S. presidential elections illustrate the increasing interconnectivity of the cyber and geopolitical domains. Threat actors are using malicious tools to cause disruption or breach networks and steal data, either as a part of espionage campaigns or in pursuit of financially or ideologically motivated objectives. Legitimate tools are also being leveraged, with threat actors using social media platforms and online forums as vehicles to deliver payloads of mis-, dis-, and malinformation (MDM).
Why it matters: In the coming weeks, it is very likely that the tempo and potency of cyber activity that actively targets or otherwise exploits the election will increase. While this will likely culminate on November 5, malicious cyber activity will very likely continue for as long as associated elements remain sufficiently topical for use in malicious activities. Social media platforms, online forums, alternative media platforms, synthetic media, and a growing skepticism toward traditional media outlets have created a fertile ground in which actors can exaggerate, misconstrue, or synthesize a deliberate narrative that can assist them in achieving a given end-state. International actors have also been observed propagating false information regarding the election. The United States’ geopolitical stature and international presence ensures that both friendly and opposing states have a continued interest in the country’s leader, foreign affairs, and domestic policies.
International Counter Ransomware Initiative 2024 Joint Statement
What happened: The 68 members of the International Counter Ransomware Initiative (CRI) gathered to develop collective resilience to ransomware, and support members if they are faced with a ransomware attack.
Why it matters: This initiative aims at collaboration among those involved at both a policy and operational level to counter ransomware threats and hold perpetrators of these malicious attacks accountable. The members reaffirmed their joint commitment to develop collective resilience to ransomware, support members if they are faced with a ransomware attack, pursue the actors responsible for ransomware attacks and not allow safe haven for these actors to operate within their jurisdictions, counter the use of virtual assets as part of the ransomware business model, partner with the private sector to advise and support CRI members, and forge international partnerships so they are collectively better equipped to counter the prevalence ransomware incidents.
United States Seizes Russian Spy Domains in Major Cyber Espionage Crackdown
What happened: A collaborative operation has taken down over 100 internet domains linked to the Russian ColdRiver hacking group, responsible for spear-phishing attacks targeting U.S. government entities, defense contractors, and nonprofits to steal sensitive information.
Why it matters: The charges present a significant disruption in the operations of a Russian cyber-espionage group within the FSB known as “Callisto Group,” whose ongoing operations targeted crucial U.S. and NATO personnel. By dismantling these domains, the United States aims to mitigate a direct threat to government agencies and civil society entities that are lucrative targets for sensitive data exfiltration. Besides, such law enforcement operations to block state-sponsored attacks ahead of the upcoming U.S. elections are crucial to uphold the integrity of the electoral processes.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user IntelBroker: Well-regarded threat actor "IntelBroker" claimed to have leaked a database associated with SmartBuy, a Jordan-based retailer of consumer electronics and home appliances, on the predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-41988: This critical RCE bug in the TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint, potentially leading to MPFS File System binary image upload without authentication.
Affected product: Opera Plus FM Family Transmitter Version 35.45
CVE-2024-43699: This critical bug in Delta Electronics DIAEnergie is an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to retrieve records or cause a denial of service.
Affected products: DIAEnergie Versions v1.10.01.008 and prior
Tags: DIB, tlp:green