zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 28, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Chinese Hackers Suspected of Targeting Phones Used by Trump and Vance
  • Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions
  • Fog and Akira Ransomware Target VPN Flaw to Attack Corporate Network

Chinese Hackers Suspected of Targeting Phones Used by Trump and Vance

Source: https://www.nytimes.com/2024/10/25/us/politics/trump-vance-hack.html#

What happened: The phones of former President Donald Trump and his running mate, Senator JD Vance, were targeted in a broader intelligence-gathering operation by Chinese hackers, which also affected several prominent Democrats. Investigators are now assessing the breach's extent and potential implications. Meanwhile, Iranian actors successfully shared the hacked emails reported by Trump's campaign over a month ago with a Democratic operative, who then released a substantial amount of material through a political action committee and independent journalists.

Why it matters: With elections just a week away, threat actors are ramping up cyberattacks to manipulate public opinion and disrupt the electoral process, employing tactics like hacking and disinformation to influence voter behavior. The targeting of phones belonging to key political figures from both parties, along with the release of hacked emails from Trump’s campaign by Iranian actors, exposes sensitive information that potentially can be used to manipulate political narratives and disrupt campaigns. Recently, ZeroFox has observed that the pro-Russian hacktivist group Deanon Club claimed to have exposed 280 million Social Security Numbers (SSNs) associated with U.S. citizens. These leaked data can facilitate further cyberattacks, affecting voter perceptions and strategies, and ultimately impacting election outcomes by enabling foreign entities to launch disinformation campaigns that manipulate public opinion.

Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions

Source: https://thehackernews.com/2024/10/four-revil-ransomware-members-sentenced.html

What happened: Four members of the REvil ransomware group have been sentenced to several years in prison in Russia for illegal circulation of payment methods. The Russian Federal Security Service (FSB), in collaboration with the Interior Ministry, conducted raids across multiple regions to detain 14 suspects linked to the group, though the investigation is still ongoing to determine each individual’s involvement in the crimes.

Why it matters: As one of the most prominent cybercriminal groups globally, it was responsible for major breaches, including attacks on Apple, JBS, and the Texas government. With key members arrested and their financial assets seized, the group's ability to operate has been severely disrupted. This could not only decrease the frequency of large-scale ransomware attacks but also serve as a deterrent to other cybercriminals. The arrest of its members may reveal additional information about the group’s dealings and other tactics and techniques, which can likely aid further law enforcement agencies in tracking other potentially active threat groups.

Fog and Akira Ransomware Target VPN Flaw to Attack Corporate Network

Source: https://www.bleepingcomputer.com/news/security/fog-ransomware-targets-sonicwall-vpns-to-breach-corporate-networks/

What happened: Fog and Akira ransomware groups breached corporate networks through VPN accounts by exploiting a critical vulnerability. Although the flaw was patched in August 2024, attackers quickly leveraged it, executing at least 30 remote access intrusions, with 75 percent of these attacks tied to Akira.

Why it matters: Many breached organizations ran outdated software, lacked multi-factor authentication, and used default VPN settings, making them easy targets. The speed of the attacks—sometimes encrypting data in under two hours—did not allow a sufficient response time, especially as the attackers focused on critical systems like virtual machines and backups. The campaigns' selective data theft strategy, targeting only recent and sensitive files, likely indicates that Fog and Akira are evolving their precision tactics.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user ShadowDefenders: Threat group "ShadowDefenders" reportedly targeted the official website of the United States Environmental Protection Agency (EPA). It claims that it has compromised the EPA's database.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-6981: This critical severity bug (CVSS score: 9.8) could allow an attacker to perform administrative actions without proper authentication.

  • Affected product: OMNTEC Proteus Tank Monitoring OEL8000III K/X ATG Generation 3.0

  • CVE-2024-41992: It is a command injection flaw in the Wi-Fi Test Suite, enabling unauthenticated attackers to execute arbitrary commands with root privileges on Arcadyan routers.

  • Affected products: Wi-Fi Test Suite

Tags: DIB, tlp:green