zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – October 28, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – October 28, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 9:00 AM (EDT) on October 25, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Disinformation and Cyber Threats Ahead of the 2024 Elections

What happened: In the wake of escalating disinformation efforts ahead of the elections, the Department of Justice (DOJ) has taken proactive measures by issuing a Notice of Proposed Rulemaking (NPRM) to implement President Biden’s Executive Order 14117, which is aimed at safeguarding Americans' sensitive personal data from foreign adversaries. This initiative comes in response to the growing threat posed by state-sponsored disinformation campaigns. Among these threats, China's Spamouflage disinformation crew (also known as Dragonbridge) has specifically targeted a prominent U.S. lawmaker. Utilizing fake news campaigns, Spamouflage has trolled his official X account and spread negative narratives on platforms like Reddit and Medium. In a concerning escalation, the group has begun using deepfake technology to craft misleading videos designed to influence the upcoming presidential election. Meanwhile, Russian state-backed actors have launched a sweeping disinformation campaign that is inundating the American news landscape with fake news masquerading as credible reporting. This strategy aims to overwhelm journalists, diverting their attention from legitimate investigations and making it more challenging to debunk false claims. Amid this chaotic backdrop, Iran's Cotton Sandstorm—a hacking group linked to the Islamic Revolutionary Guard Corps (IRGC)—is reportedly conducting its own influence operations as the elections draw near. Another Iranian group, Storm-2035, is actively spreading divisive and conspiratorial articles by impersonating various local U.S. news outlets, posting around eight articles weekly and targeting both Democrats and Republicans. Reports suggest that Iran's election activities seem to favor the Harris campaign, while Russia has intensified its attacks against the Harris-Walz campaign. Adding to the tumult, Russian-language accounts on X and Telegram have been observed circulating an artificial intelligence (AI)-enhanced deepfake video of Vice President Kamala Harris. The video depicts her making inappropriate jokes about assassination attempts against Trump and has already garnered tens of thousands of views.

Exposed United Nations Database Left Sensitive Information Accessible Online

What happened: A database belonging to the United Nations (UN) Trust Fund to End Violence Against Women was found exposed online, revealing over 115,000 sensitive files related to organizations working with vulnerable communities globally—including under oppressive regimes. The data included staffing information, contracts, and detailed financial audits. A researcher discovered the misconfigured database and notified the UN, which promptly secured it.

Pro-India Hacktivists Plan to Target Canada amid Escalating Diplomatic Tensions

What happened: On October 22, 2024, pro-India hacktivist groups Indian Cyber Force and Indian Cyber Army announced preparations for a cyberattack on Canada, intending to disrupt its cyber infrastructure. This escalation occurs amid heightened geopolitical tensions between India and Canada. The hacktivists framed their planned actions as retaliation against Canadian Prime Minister Justin Trudeau, accusing him of aligning with Khalistani extremists and having an anti-India stance. This is not the first time Indian hacktivists have targeted Canadian cyber assets. In September 2023, Indian Cyber Force launched cyberattacks on websites connected to the Canadian military following the controversial killing of Canadian Sikh leader Hardeep Singh Nijjar, which strained relations between the two nations.

Tags: tlp:green