zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian Espionage Group Targets Ukrainian Military with Malware via Telegram
  • French ISP Free Confirms Data Breach After Leak
  • Dutch Police Disrupt Operations of RedLine and Meta Password Stealers

Russian Espionage Group Targets Ukrainian Military with Malware via Telegram

Source: https://thehackernews.com/2024/10/russian-espionage-group-targets.html

What happened: A newly uncovered hybrid espionage and influence campaign operated by Russian threat group “UNC5812” targets Ukrainian military recruits using malware for popular operating systems. The campaign uses a deceptive "Civil Defense" persona along with a website and Telegram channel to distribute a malicious app disguised as a recruitment avoidance tool.

Why it matters: By spreading narratives against Ukraine's recruitment efforts, this campaign not only seeks to gather sensitive information but also aims to instill doubt and resistance among potential recruits regarding Ukraine's military initiatives. This poses a significant threat to the country's ability to effectively mobilize its forces during a critical time. The operation enables attackers to engage in data theft and real-time surveillance while masquerading as a legitimate, Ukraine-friendly organization. Overall, it shows Russia's continued involvement and capabilities in the realm of cyber warfare.

French ISP Free Confirms Data Breach After Leak

Source: https://www.bleepingcomputer.com/news/security/free-frances-second-largest-isp-confirms-data-breach-after-leak/

What happened: Hackers breached the systems of French internet service provider (ISP) Free, stealing some customer personal information, including international bank account numbers (IBANs) for certain subscribers, though passwords, payment data, and communications content remained secure.

Why it matters: This breach exposed a large ISP’s vulnerability, endangering customers' financial and personal data security. Although Free secured sensitive information like passwords and payment details, stolen IBANs could still be misused in phishing attacks or for fraud. Scammers can likely combine these partial data points with social engineering to deceive victims, especially when customers are unaware their data has been compromised. At the time of writing, the breach has not reportedly impacted Free’s services, while the company swiftly implemented measures to secure its systems.

Dutch Police Disrupt Operations of RedLine and Meta Password Stealers

Source: https://www.theregister.com/2024/10/28/dutch_cops_pwn_the_redline/

What happened: Dutch National Police, in collaboration with the FBI and other international law enforcement bodies, have disrupted the operations of the Redline and Meta infostealers in an operation called Operation Magnus. They seized the source codes, user data, and identities of individuals who used the malware.

Why it matters: Several threat actors, including Scattered Spider, have been known to favor RedLine and Meta for their infostealing capabilities. Even though it is very likely that new infostealers will emerge to take their place, the revelation of RedLine and Meta user identities will likely expose frequent buyers and disrupt criminal collaborations. Besides, authorities can use the user data from the seized information to study patterns of threat actor activity or identify imminent threats.

DEEP AND DARK WEB INTELLIGENCE

New cybercrime group emerges | A newly emerged cybercrime group, initially called "ICA Group," was formed by members of BreachForums. It later changed its name to "HELLCAT." Reports suggest that the group has taken servers offline for a few days in preparation for their next target.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-32640: New automated exploit Muraider has been observed abusing this SQL injection vulnerability to infect websites that use affected CMS versions.

Affected products: Mura/Masa CMS

Tags: DIB, tlp:green