ZeroFox Cyber Intelligence Daily Brief - October 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations
- Finland Seizes Servers of “Sipulitie” Dark Web Drugs Market
- Seven Charged in Multi-State Business Email Compromise Scam
CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations
What happened: CISA, along with other agencies, has released a joint cybersecurity advisory. This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors to impact organizations across multiple critical infrastructure sectors.
Why it matters: This advisory aims to warn network defenders of Iranian cyber actors’ use of brute force and other techniques to compromise organizations across multiple critical infrastructure sectors, including the healthcare and public health (HPH), government, information technology, engineering, and energy sectors. The actors likely aim to obtain credentials and information describing the victim’s network that can then be sold to enable access to cybercriminals. Along with the mitigations, the authoring agencies also recommend software manufacturers incorporate secure by design principles and tactics into their software development practices to protect their customers against actors using compromised credentials, thereby strengthening the security posture of their customers.
Finland Seizes Servers of “Sipulitie” Dark Web Drugs Market
What happened: Finnish Customs, in collaboration with Europol and other international authorities, took down the darknet marketplace “Sipulitie,” which was used to anonymously sell illegal narcotics. The operation also seized the site's servers and took offline a related chat-based platform, Tsätti. Authorities have identified the operator, moderators, and users of the marketplaces, with arrests very likely to follow.
Why it matters: This takedown is significant because it disrupts a major network for illegal narcotics sales, which had operated anonymously and amassed over EUR 1.3 million (USD 1.42 million) in revenue. Identifying the operators and users of these platforms also opens the door for further arrests, potentially dismantling broader criminal networks involved in drug trafficking. The operation undermines the infrastructure that criminals rely on, likely making it more difficult for similar marketplaces to emerge or regain traction. This crackdown is likely to disrupt a critical supply chain for drug traffickers, curbing the distribution of narcotics across Europe and stemming the revival of similar marketplaces in the future.
Seven Charged in Multi-State Business Email Compromise Scam
Source: https://www.justice.gov/usao-sdtx/pr/more-indicted-nationwide-business-email-compromise-scheme
What happened: The U.S. Department of Justice (DOJ) has charged seven individuals across multiple states in connection with a large business email compromise (BEC) scheme that defrauded millions of victims. The scheme involved accessing business email accounts, posing as legitimate vendors, and diverting payments to fraudulent bank accounts.
Why it matters: The group targeted businesses across various industries—from finance to healthcare—causing significant financial losses. Victims included companies in Oregon, New Jersey, and Texas, revealing the reach and scale of such BEC campaigns. The suspects attempted to obscure their activities by laundering the stolen funds through multiple accounts. BEC scams exploit trust within business operations, leading to severe financial losses, reputational damage, and operational setbacks.
Tags: DIB, tlp:green