zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 7, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 7, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russia Arrests U.S.-Sanctioned Cryptex Founder, 95 Other Linked Suspects
  • Hurricane Helene Disinformation Fuels Division and Distrust amid Recovery Efforts
  • Stealthy Malware Has Infected Thousands of Linux Systems for Years

Russia Arrests U.S.-Sanctioned Cryptex Founder, 95 Other Linked Suspects

Source: https://www.bleepingcomputer.com/news/security/russia-arrests-us-sanctioned-cryptex-founder-95-other-linked-suspects/

What happened: Russian law enforcement apprehended nearly 100 suspects associated with the Cryptex cryptocurrency exchange and a range of online services engaged in illicit payments and the sale of stolen data. In a series of 148 raids, 96 individuals were charged with offenses including participation in a criminal organization, unauthorized access to computer information, and illegal financial activities

Why it matters: The recent sanctions, dismantling of services, and arrests by Russian law enforcement were crucial in disrupting the financial networks that enable cybercrime. Among those arrested is a key money launderer who was recently sanctioned by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC). The OFAC stated that the adversary’s services—UAPS, PinPays, and PM2BTC—were vital in processing hundreds of millions of dollars for ransomware actors, darknet marketplace vendors, initial access brokers, and other cybercriminals over the past two decades, facilitating activities that threaten security in both digital and financial realms. The seizure of over RUB 1.5 billion (approx. USD 15 million) in assets and luxury items reveals the significant financial resources involved in these illegal activities.

Hurricane Helene Disinformation Fuels Division and Distrust amid Recovery Efforts

Source: https://www.reuters.com/world/us/us-officials-struggle-quash-hurricane-helene-conspiracy-theories-2024-10-05/

What happened: False rumors spread on social media following Hurricane Helene, with claims that disaster funds were misused and that the storm was engineered to mine lithium. High-profile figures, including prominent political personalities, amplified these claims, prompting local and federal officials to counteract the misinformation. The Federal Emergency Management Agency (FEMA) has set up a dedicated rumor-response page.

Why it matters: Last month, CISA issued warnings about cyber threats, including “social media pleas,” that will likely take advantage of the interests and tensions surrounding Hurricane Helene to target U.S. citizens. Misleading narratives politicizing disaster response complicate emergency services and will likely divert attention from the recovery process, potentially discouraging victims from seeking critical help. With the presidential election approaching, disinformation continues to intensify political divisions and threaten the security of the electoral processes.

Stealthy Malware Has Infected Thousands of Linux Systems for Years

Source: https://www.wired.com/story/perfctl-stealthy-malware-infected-linux-systems/

What happened: Thousands of Linux machines have been infected by a new malware strain called Perfctl. This malware strain is known for its stealth, ability to exploit numerous misconfigurations, and wide range of malicious activities. Perfctl is observed to remain on infected machines even after reboots or attempts to remove core components.

Why it matters: Perfctl’s ability to reportedly disguise itself with legitimate-looking names makes it difficult for users and security teams to identify the infection. Its versatility in performing various malicious activities, from data exfiltration to deploying additional payloads, makes Perfctl a destructive tool that can disrupt organizational and individual systems, leading to financial loss, compromised security, and operational instability. The malware’s persistence and ability to evade detection also make it challenging to remove, allowing it to spread more easily and remain active for extended periods. Perfctl will likely become more widespread, causing further disruptions to critical infrastructure and business operations.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user RedEagleCrew: Threat actor group RedEagleCrew has claimed to have leaked a database associated with the Paper Deals, an India-based paper manufacturer. The leaked database includes name, email, phone number, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-42417: Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

  • Affected product: DIAEnergie Versions v1.10.01.008 and prior

Tags: DIB, tlp:green