zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief –October 14, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief –October 14, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 9:00 AM (EDT) on October 11, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

U.S. Utility Company Forced to Take Systems Offline After Cyber Incident

What happened: American Water faced a cyberattack that disrupted its customer portal and billing operations, though water and wastewater services remain unaffected. The company is working with cybersecurity experts to manage the incident and ensure a swift recovery. While the full impact of the attack is still being assessed, American Water does not anticipate any material adverse effect on its financial condition or operations. Customers may experience disruptions in account management, but critical services continue to operate without issue.

Salt Typhoon’s Targeted Campaigns Against U.S. Entities

What happened: Chinese state-backed advanced persistent threat (APT) group Salt Typhoon has breached multiple critical U.S. infrastructure networks, specifically targeting major telecommunications providers—including Verizon, AT&T, and Lumen. Notably, the hackers infiltrated networks used by the U.S. government for court-authorized wiretaps, which facilitate criminal and national security investigations. The group focused on gaining long-term, deep, and stealthy access, remaining undetected for months or potentially longer by targeting a small number of broadband and cable networks. Additionally, researchers have stated that this campaign aimed to steal sensitive data and potentially prepare the group for future disruptive attacks. The nature and extent of the breach have alarmed government officials, with experts describing the incident as one of the most severe cyber espionage events in recent years.

Pro-Palestine Hackers Target Israel and Pro-Israel Nations on October 7 Anniversary

What happened: October 7, 2024, marks the first anniversary of Hamas’ attack on Israel, during which thousands of Palestinian militants breached the Gaza-Israel border in an unprecedented assault that resulted in the deaths of 1,180 Israelis and foreign nationals. In the lead-up to this anniversary, ZeroFox observed pro-Palestine threat actors launching multiple cyber campaigns against Israel and its allies under the #OpIsrael banner. Key actions include attacks by the Anonymous Collective and KromSec; these groups targeted an Israeli electricity company and leaked data from the Israeli Association for Ecology and Environmental Sciences, while also spreading misinformation, disinformation, and malinformation against nations and companies connected to Israel. The Sylhet Gang attacked the marketing site Perniagaan Viral, and Actor Nusantara leaked information from Indian companies in response to India’s support for Israel. Hunt3r Kill3rs claimed a data leak involving 130 Israeli defense firms, and LulzSec Black (in collaboration with Moroccan Soldiers) accessed a database containing over 20,000 sensitive records. Additionally, Blackhun73r, Cyber Toufan, and Ghosts of Palestine have expressed gratitude for their collaborations on cyberattacks and vowed to continue targeting pro-Israel entities. Nearly 200 hacktivist groups are now engaged in cyberwarfare related to the conflict, with distributed denial-of-service (DDoS) attacks being the most prevalent method. Many pro-Russian hacktivists are also joining these efforts to disrupt daily life and influence the information landscape. ZeroFox has also identified cyber threat actors on Telegram forming alliances with both Israel and Iran in October and November 2023. Throughout the conflict, cyberattacks against Israel have intensified in tandem with escalations in ground fighting. While pro-Israel cyber actors are also active, they are likely operating to a lesser degree, primarily targeting Iran.

Tags: tlp:green