zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 8, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 8, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - October 7 Anniversary Report
  • U.S. Utility Company Forced to Take Billing Systems Offline Due to Cyberattack
  • New Gorilla Botnet Launches over 300,000 DDoS Attacks Across 100 Countries

ZeroFox Intelligence Brief - October 7 Anniversary Report

Source: https://www.zerofox.com/advisories/26806/

What happened: October 7, 2024, marks the first anniversary of Hamas’ attack on Israel, wherein thousands of Palestinian militants breached the Gaza-Israel border in an unprecedented attack that resulted in the deaths of 1,180 Israelis and foreign nationals. Cyber threat actors are very likely escalating their activity related to the October 7 anniversary, the majority of which has targeted Israeli targets or Israeli-based entities.

Why it matters: At the onset of the Israel-Hamas conflict on October 7, 2023, ZeroFox identified cyber threat actors on Telegram forming alliances with both Israel and Iran in October and November 2023. Throughout the conflict, cyberattacks have accelerated against Israel in tandem with an escalation in the fighting on the ground. Pro-Israel cyber actors are active in the conflict, if to a very likely lesser degree, primarily targeting Iran. On October 7, 2024, ZeroFox observed several cyber campaigns claimed by pro-Palestine threat actors against Israel and pro-Israel nations. The #OpIsrael campaign involved web defacements, distributed denial-of-service (DDoS) attacks, data leaks, and more.

U.S. Utility Company Forced to Take Billing Systems Offline Due to Cyberattack

Source: https://hackread.com/american-water-cyberattack-shuts-down-portal-billing/

What happened: American Water, a major U.S. utility company, experienced a cyberattack on October 3 that disrupted its customer portal and billing systems. The company took offline the MyWater portal and halted billing operations to contain the issue. Water and wastewater services remain operational, and a team of cybersecurity experts is working to manage the situation.

Why it matters: American Water provides water and water and wastewater services, classified as critical infrastructure in the United States. State-sponsored actors, hacktivists, and financially-motivated hackers often target such companies because any service disruption is likely to pose a direct risk to public safety and operational stability, potentially eroding public trust. Moreover, the incident follows a recent report on the Chinese government-backed Salt Typhoon APT group that hacked AT&T, Verizon, and Lumen Technologies, compromising wiretap systems used in criminal investigations. The close timing is a likely indication that these incidents are part of a broader campaign targeting U.S. infrastructure, especially in the run-up to the November Presidential election.

New Gorilla Botnet Launches over 300,000 DDoS Attacks Across 100 Countries

Source: https://thehackernews.com/2024/10/new-gorilla-botnet-launches-over-300000.html

What happened: Cybersecurity researchers have identified a new botnet malware family called Gorilla (or GorillaBot), a variant of the leaked Mirai botnet source code. In less than a month, this botnet executed over 300,000 attack commands, primarily targeting universities, government websites, telecom companies, banks, and the gaming and gambling sectors.

Why it matters: Averaging at least 20,000 commands per day to launch distributed denial-of-service (DDoS) attacks, Gorilla has targeted over 100 countries, with China, the United States, Canada, and Germany being the most affected. Its scale and intensity raise serious concerns about the vulnerability of critical infrastructure and services worldwide. By employing various DDoS techniques, such as UDP flood, ACK BYPASS flood, Valve Source Engine (VSE) flood, SYN flood, and ACK flood, along with the ability to spoof source IP addresses, the botnet can generate substantial traffic and disrupt operations.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user grep: Threat actor "grep" claimed to have leaked a database associated with Cabinet Warehouse, a U.S.-based company that provides kitchen remodeling services on the predominantly English-language dark web forum BreachForums. The leaked database contains user email id, shipping address, orders, billing address, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-43047: Qualcomm has released security patches for this high-severity zero-day vulnerability, which is a use-after-free vulnerability that could result in memory corruption when exploited by local attackers with low privileges.

Affected products: Digital Signal Processor (DSP) service affecting several chipsets

Tags: DIB, tlp:green