ZeroFox Cyber Intelligence Daily Brief - October 24, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 24, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian Trolls Pose as Reputable Media to Sow U.S. Election Chaos
- Threat Actor “Satanic” Claims to have Stolen 350 Million Hot Topic Shoppers Info
- Hacker Leaks 180,000 ESNA User Records on the Eve of Tournament
Russian Trolls Pose as Reputable Media to Sow U.S. Election Chaos
Source: https://www.darkreading.com/vulnerabilities-threats/russians-pose-reputable-media-us-election-chaos
What happened: Russian state-backed actors launched a massive disinformation campaign, flooding the American news ecosystem with fake news disguised as credible sources. This tactic aims to overwhelm journalists, diverting their resources from investigating legitimate stories and debunking falsehoods.
Why it matters: The group reportedly adds branding and logos that make the disinformation look like it's from a trusted U.S. news organization, making it difficult for citizens to know what's real and what isn't. By saturating the information landscape with misleading content, these actors can sway public opinion and potentially influence the outcome of the election, undermining democratic principles. Meanwhile, the Georgia Secretary of State's office recently successfully defended against a cyberattack that targeted the website where voters request absentee ballots, preventing any disruption.
Threat Actor “Satanic” Claims to have Stolen 350 Million Hot Topic Shoppers Info
Source: https://www.theregister.com/2024/10/23/satanic_data_thief/
What happened: A hacker named "Satanic" claims to have stolen the personal data of 350 million Hot Topic customers, including names, emails, addresses, and partial payment information. The breach reportedly stems from a malware infection affecting an employee at a third-party company. The stolen data is being sold for USD 20,000, with the hacker also offering to remove the listing for USD 100,000.
Why it matters: The theft of personal data from 350 million Hot Topic customers poses a risk of targeted phishing attacks, especially given the size of the breach and the detailed customer information involved. While the stolen data lacks full financial details, the exposure of names, emails, and partial payment information could still enable malicious actors to craft other convincing scams. Additionally, the breach shows that third-party vendors can undergo security lapses and that can impact major retailers like Hot Topic. Although the overall impact may reportedly be limited, the leak could lead to reputational damage for Hot Topic, making it essential for stronger cybersecurity practices, especially in third party vendors, to prevent future malware infections.
Hacker Leaks 180,000 ESNA User Records on the Eve of Tournament
Source: https://hackread.com/hackers-leak-esport-north-africa-user-record-before-tournament/
What happened: A threat actor claimed to leak the personal data allegedly belonging to over 180,000 Esport North Africa (ESNA) users just one day before a tournament in Morocco. The 3 GB data package, shared on BreachForums, includes usernames, email addresses, IP addresses, and session details but no passwords or financial information.
Why it matters: Closely following the cyberattack targeting the developer behind the Pokémon game series, the alleged breach of ESNA is likely an indication that threat actors are increasingly targeting gaming platforms. Besides, the critical timing of the breach will likely cause disruptions in the tournament. The leaked personal details will likely expose users to phishing attacks, where malicious attackers might impersonate ESNA representatives and trick the users into a financial scam or identity fraud.
DEEP AND DARK WEB INTELLIGENCE
XSS user Zerodata: On October 23, 2024, the untested threat actor "Zerodata" advertised access to the web panel of the Spanish police on the predominantly Russian language Dark Web forum "XSS." The actor charged USD 5,000 for the access.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-47575: A vulnerability in the FortiManager fgfmd daemon, identified as missing authentication for critical functions [CWE-306], allows a remote unauthenticated attacker to execute arbitrary code or commands through specially crafted requests. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog.
Affected products: The affected products and versions have been listed in this security update.
Tags: DIB, tlp:green