zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – October 7, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – October 7, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on October 4, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

DoJ Charges 18 in a Deadly Global Counterfeit Drug Operation

What happened: The U.S. Department of Justice (DoJ) has charged 18 individuals involved in a scheme selling counterfeit pills disguised as legitimate pharmaceutical products. The pills, primarily containing fentanyl and methamphetamine, were marketed through numerous fraudulent online pharmacies. Tens of thousands of unsuspecting victims purchased these counterfeit pills, resulting in at least nine fatalities due to narcotics poisoning. Law enforcement agencies seized nine website domains, counterfeit tablets, and substantial quantities of raw narcotics and manufacturing equipment at various pill mills. The drug trafficking operation—which spanned multiple countries, including the United States, the Dominican Republic, and India—had an extensive reach and a large scale of impacts and consequences.

NCA Unveils LockBit Affiliates and Sanctions 16 Evil Corp Members

What happened: The United Kingdom (UK)’s National Crime Agency (NCA) has reactivated the seized “LockBit” darknet site to provide crucial updates on recent developments in its ongoing investigations. Among the revelations, the NCA identified Aleksandr Ryzhenkov as a member of the Russian cybercrime group “Evil Corp” and also as a LockBit affiliate known as "Beverley." Ryzhenkov is believed to have created over 60 variants of LockBit ransomware and to have attempted to extort at least USD 100 million from various victims. The agency also announced the arrest of a significant actor within the LockBit network, alongside multiple arrests in the UK connected to this cybercrime operation. Britain imposed sanctions on 16 members of Evil Corp, citing their involvement in operations directed by Russian intelligence against NATO allies.

U.S. Charges Individuals in Cyberattacks Targeting Electoral Campaigns

What happened: The DoJ has unsealed charges against three individuals allegedly linked to the Islamic Revolutionary Guard Corps (IRGC) that are accused of hacking into accounts of current and former U.S. officials to steal campaign material in order to influence the 2024 election. According to the Department of Public Affairs, the activity was part of Iran’s continuing efforts to stoke discord, erode confidence in the U.S. electoral process, and unlawfully acquire information relating to current and former U.S. officials that could be used to advance the malign activities of the IRGC—including ongoing efforts to avenge the death of Qasem Soleimani, the former commander of the IRGC – Qods Force (IRGC-QF). The announcement comes days after U.S. authorities accused Iranian actors of hacking into the accounts of officials associated with former President Donald Trump’s campaign and attempting to share exfiltrated information with President Joe Biden’s campaign staff.

Tags: tlp:green