ZeroFox Cyber Intelligence Daily Brief - October 13, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 13, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and FBI Release Guide on Protecting National Political Organizations from Iranian Cyber Threats
- Russia Arrests U.S.-Sanctioned Cryptex Founder, 95 Other Linked Suspects
- Scammers Target Hurricane Victims with Phishing and Malware
CISA and FBI Release Guide on Protecting National Political Organizations from Iranian Cyber Threats
What happened: CISA and the FBI have released a joint fact sheet titled "How to Protect Against Iranian Targeting of Accounts Associated with National Political Organizations." This fact sheet outlines the threats posed by actors linked to the Iranian Government's Islamic Revolutionary Guard Corps (IRGC), aiming to compromise American accounts to sow discord and undermine confidence in U.S. democratic institutions.
Why it matters: IRGC actors have previously gained and continue to seek access to personal and business accounts using social engineering techniques by targeting victims across email and chat. This fact sheet includes steps that individuals and organizations can take to enhance their security and resilience to protect themselves against the common techniques used by these cyber actors. CISA and FBI strongly recommend all individuals and organizations associated with national political organizations apply the mitigations in this fact sheet.
Russia Arrests U.S.-Sanctioned Cryptex Founder, 95 Other Linked Suspects
What happened: Russian law enforcement apprehended nearly 100 suspects associated with the Cryptex cryptocurrency exchange and a range of online services engaged in illicit payments and the sale of stolen data. In a series of 148 raids, 96 individuals were charged with offenses including participation in a criminal organization, unauthorized access to computer information, and illegal financial activities.
Why it matters: The recent sanctions, dismantling of services, and arrests by Russian law enforcement were crucial in disrupting the financial networks that enable cybercrime. Among those arrested is a key money launderer who was recently sanctioned by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC). The OFAC stated that the adversary’s services—UAPS, PinPays, and PM2BTC—were vital in processing hundreds of millions of dollars for ransomware actors, darknet marketplace vendors, initial access brokers, and other cybercriminals over the past two decades, facilitating activities that threaten security in both digital and financial realms. The seizure of over RUB 1.5 billion (approx. USD 15 million) in assets and luxury items reveals the significant financial resources involved in these illegal activities.
Scammers Target Hurricane Victims with Phishing and Malware
Source: https://hackread.com/scammers-florida-hurricane-victim-fake-fema-malware/
What happened: Cybercriminals are targeting Hurricane Helene victims and relief organizations in Florida, abusing disaster recovery efforts. Researchers have identified three types of scams—fraudulent FEMA claims, phishing attacks using fake hurricane relief websites, and malware disguised as FEMA documents. The schemes aim to steal personal data and funds by posing as legitimate aid providers.
Why it matters: Scammers exploit the urgent need for immediate aid through fake relief websites and malicious files, which could subject individuals to identity theft, financial losses, and even blackmail and extortion. CISA has warned users to be vigilant about fraudulent emails and social media messages—often containing malicious links or attachments—common after major natural disasters. Such scams take advantage of the interests and tensions surrounding natural disasters and complicate disaster recovery, putting already vulnerable individuals at greater risk of financial harm. With another hurricane, Hurricane Milton, threatening the U.S. landscape, such scams will very likely continue to target unsuspecting users for the time being.
Tags: DIB, tlp:green