zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 14, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 14, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Seven Charged in Multi-State Business Email Compromise Scam
  • India's Star Health Says It Received USD 68,000 Ransom Demand After Data Leak
  • GitHub and More Abused in New Wave of Phishing Attacks

Seven Charged in Multi-State Business Email Compromise Scam

Source: https://www.justice.gov/usao-sdtx/pr/more-indicted-nationwide-business-email-compromise-scheme

What happened: The U.S. Department of Justice (DOJ) has charged seven individuals across multiple states in connection with a large business email compromise (BEC) scheme that defrauded millions of victims. The scheme involved accessing business email accounts, posing as legitimate vendors, and diverting payments to fraudulent bank accounts.

Why it matters: The group targeted businesses across various industries—from finance to healthcare—causing significant financial losses. Victims included companies in Oregon, New Jersey, and Texas, revealing the reach and scale of such BEC campaigns. The suspects attempted to obscure their activities by laundering the stolen funds through multiple accounts. BEC scams exploit trust within business operations, leading to severe financial losses, reputational damage, and operational setbacks.

India's Star Health Says It Received USD 68,000 Ransom Demand After Data Leak

Source: https://www.reuters.com/world/india/indias-star-health-says-it-received-68k-ransom-demand-after-data-leak-2024-10-12/

What happened: Star Health, one of India's largest health insurers, received a ransom demand of USD 68,000 from hackers who leaked sensitive data of over 31 million policyholders. The attackers reportedly utilized Telegram chatbots to disseminate personal information.

Why it matters: The hackers' use of Telegram chatbots and a dedicated website to leak sensitive customer data amplifies the scale of the breach—impacting millions of policyholders—and facilitates the rapid sharing of personal information, making it easily accessible to malicious actors. Customers will be significantly affected, as their sensitive information—such as full names, phone numbers, addresses, medical records, and tax details—has been compromised, raising concerns about identity theft and targeted phishing attacks. Adding to the crisis, the hackers have demanded a ransom of USD 68,000 from the company. Meanwhile, Star Health has initiated internal investigations to assess the extent of the breach and is pursuing legal action against Telegram and the hacker.

GitHub and More Abused in New Wave of Phishing Attacks

Source: https://thehackernews.com/2024/10/github-telegram-bots-and-qr-codes.html

What happened: A new malware campaign targeting the insurance and finance sectors uses GitHub links in phishing emails to deliver the Remcos remote access trojan (RAT). Attackers exploit compromised accounts from legitimate hotels, tricking victims into clicking on fake booking-related links. Researchers observed that the threat actors behind these phishing attempts used elements like ASCII and Unicode-based QR codes and blob URLs to evade detection and bypass security measures.

Why it matters: Threat actors are observed abusing GitHub to stage malicious payloads without reportedly leaving visible traces, making detection more difficult. By exploiting GitHub issues, attackers can upload malware that persists even after the issue is closed, enabling them to deliver malware like Remcos RAT or Lua-based loaders. This technique not only evades traditional security measures but also leverages trusted platforms, increasing the risk of successful infections in sectors like insurance and finance. Additionally, the theft of sensitive financial information can likely have severe consequences to companies and patrons alike.

DEEP AND DARK WEB INTELLIGENCE

  • Exploit user Mr28: Untested threat actor "Mr28" has advertised a SIM swap service for U.S.-based telecommunications companies on predominantly Russian language Dark Web forum Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-30088: This elevation of privilege vulnerability can let an attacker gain SYSTEM privileges. Iranian advanced persistent threat group OilRig, or APT34, has been exploiting this bug to target government and critical infrastructure entities in the United Arab Emirates and the Gulf region. The patch for this bug was released in June, 2024.

  • Affected product: The list of affected products have been included in this advisory.

Tags: DIB, tlp:green