zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 17, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 17, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations
  • DOJ Indicts Two Operatives of the DDoS Hacktivist Group Anonymous Sudan
  • Russia Using Generative AI to Ramp Up Disinformation, Says Ukraine Minister

CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations

Source: https://www.cisa.gov/news-events/alerts/2024/10/16/cisa-fbi-nsa-and-international-partners-release-advisory-iranian-cyber-actors-targeting-critical

What happened: CISA, along with other agencies, has released a joint cybersecurity advisory. This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors to impact organizations across multiple critical infrastructure sectors.

Why it matters: This advisory aims to warn network defenders of Iranian cyber actors’ use of brute force and other techniques to compromise organizations across multiple critical infrastructure sectors, including the healthcare and public health (HPH), government, information technology, engineering, and energy sectors. The actors likely aim to obtain credentials and information describing the victim’s network that can then be sold to enable access to cybercriminals. Along with the mitigations, the authoring agencies also recommend software manufacturers incorporate secure by design principles and tactics into their software development practices to protect their customers against actors using compromised credentials, thereby strengthening the security posture of their customers.

DOJ Indicts Two Operatives of the DDoS Hacktivist Group Anonymous Sudan

Source: https://www.justice.gov/usao-cdca/pr/two-sudanese-nationals-indicted-alleged-role-anonymous-sudan-cyberattacks-hospitals

What happened: The U.S. Department of Justice (DOJ) has charged two individuals with running Anonymous Sudan, a cybercriminal group responsible for numerous distributed denial-of-service (DDoS) attacks targeting critical infrastructure, government agencies, and businesses globally. In March 2024, U.S. authorities seized and disabled the DDoS tool the group used to attack hospitals, government networks, and private companies.

Why it matters: Anonymous Sudan is known for conducting politically motivated DDoS attacks, which—despite being relatively less complicated to mitigate—are likely to cause disruptions in crucial emergency operations, causing widespread damage, especially for entities like hospitals. Since its launch in 2023, the group has orchestrated over 35,000 DDoS attacks. The attacks targeted high-profile entities—including U.S. law enforcement authorities, hospitals, and tech giants—causing over USD 10 million in damages.

Russia Using Generative AI to Ramp Up Disinformation, Says Ukraine Minister

Source: https://www.reuters.com/technology/artificial-intelligence/russia-using-generative-ai-ramp-up-disinformation-says-ukraine-minister-2024-10-16/

What happened: A senior Ukrainian official reported that Russia is using generative artificial intelligence (AI) to intensify its disinformation campaigns against Ukraine. He noted that these campaigns are increasingly difficult to detect, with extensive false information being spread on social media to bolster their credibility.

Why it matters: These disinformation campaigns not only target Ukrainians but also seek to sway public opinion in other countries during crucial electoral periods. Ukrainian officials have reported that in August many citizens were facing online disinformation campaigns linked to Russia's security and intelligence agencies. Early this week, U.S. intelligence reported that Russia is using AI tools to influence American voters ahead of the upcoming presidential election. In response, Moscow has accused Ukraine and Western nations of conducting a sophisticated information war against it.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user CyberVolk: Pro-Russia threat actor group CyberVolk has allegedly threatened to conduct various cyberattacks, including ransomware, DDoS, data breaches, and web defacements, against Japan under the ongoing operations #OpJP and #31D.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-38814: VMware has released security patches for an authenticated SQL injection vulnerability in VMware HCX. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager.

  • Affected product: VMware HCX platform versions 4.8.x, 4.9.x, 4.10.x, and more

Tags: DIB, tlp:green