ZeroFox Weekly Intelligence Brief – October 21, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – October 21, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on October 18; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Pro-Palestine Actor RipperSec Explains Motives Behind Attacks on Various Nations
What happened: In a Telegram post, pro-Palestine threat group RipperSec explained the motives behind its cyberattacks on different nations, including Thailand, Israel, Taiwan, the United States, the United Kingdom, France, India, and Australia. Thailand was targeted due to alleged killings of innocent Muslims in Pattani and accusations of land theft. Israel was attacked in response to its actions in Palestine and Lebanon. Taiwan's assault was linked to claims of aiding Israel and insulting Russia. The United States was targeted for allegedly funding actions against innocent people in Palestine and Lebanon, while the United Kingdom and France were attacked for providing support and weaponry to Israel. India faced breaches for its alleged mistreatment of Muslims and backing of Israel, and Australia was attacked due to its perceived support of Israel through financial and military assistance.
Reports Suggest Uptick in Russia, China, and Iran-Linked Attacks Against Adversaries
What happened: A cybersecurity report suggests that the governments of Russia, China, and Iran increasingly rely on hackers to conduct cyber espionage, intelligence gathering, and disinformation campaigns targeting the United States and its allies. The partnerships help each state expand its cyber operations without direct involvement, leveraging hackers motivated by financial gain or political objectives. For instance, an Iran-linked hacking group breached an Israeli dating site to both profit, while Russian-affiliated hackers targeted Ukrainian military devices to aid Russia’s war effort. The report found no evidence of collaboration among these states but noted each country's cyber activities are intensifying. Russia and Iran are focusing on spreading disinformation and launching cyberattacks related to the 2024 U.S. elections. China, while avoiding direct interference in the presidential race, has shifted its focus to regional targets and down-ballot elections in the United States.
DOJ Indicts Two Anonymous Sudan Operators
What happened: The U.S. Department of Justice (DOJ) charged two Sudanese nationals that operated Anonymous Sudan, an online cybercriminal group responsible for tens of thousands of distributed denial-of-service (DDoS) attacks against critical infrastructure, corporate networks, and government agencies in the United States and around the world. Anonymous Sudan’s attacks have caused more than USD 10 million in damages to U.S. victims. These law enforcement actions were taken as part of Operation PowerOFF, an ongoing, coordinated effort among international law enforcement agencies aimed at dismantling criminal DDoS-for-hire infrastructure worldwide.
Tags: tlp:green