ZeroFox Cyber Intelligence Daily Brief - October 31, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 31, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- JCDC’s Industry-Government Collaboration Speeds Mitigation of CrowdStrike IT Outage
- North Korean Group Collaborates with Play Ransomware in Cyberattack
- Malware "FakeCall" Now Reroutes Bank Calls to Attackers
JCDC’s Industry-Government Collaboration Speeds Mitigation of CrowdStrike IT Outage
What happened: CISA, through the Joint Cyber Defense Collaborative (JCDC), enabled swift, coordinated response and information sharing in the wake of a significant IT outage caused by a CrowdStrike software update. This outage, which impacted government, critical infrastructure, and industry across the globe, led to disruptions in essential services, including air travel, healthcare, and financial operations.
Why it matters: Leveraging its unique ability to bring together public and private sector partners, JCDC facilitated virtual engagements with over 1,000 federal agency representatives. In close collaboration with CrowdStrike, a JCDC partner, CISA provided critical updates, mitigation guidance, and analysis on the potential for malicious exploitation of the outage.
North Korean Group Collaborates with Play Ransomware in Cyberattack
Source: https://thehackernews.com/2024/10/north-korean-group-collaborates-with.html
What happened: North Korea-linked threat group Andariel has reportedly been observed working with the Play ransomware group in a recent cyber incident. It is still unclear if this collaboration was a one-time event, that Andariel may be acting as an initial access broker for the Play ransomware group, and if future collaborative efforts are likely.
Why it matters: Collaborations, like this one, likely enables streamlined attacks that may allow the threat groups to evade detection more effectively, while combining resources to allow these groups to target larger or more complex networks. If these groups collaborate in the future, such a partnership can create an ecosystem where the cybercriminal groups can likely share tools, infrastructure, and intelligence, resulting in more persistent threats.
Malware "FakeCall" Now Reroutes Bank Calls to Attackers
What happened: A new version of FakeCall malware for a popular mobile operating system can hijack outgoing calls to banks, redirecting them to an attacker’s phone. This banking trojan not only impersonates banks to extract sensitive information through voice phishing (vishing) but can also capture audio and video streams from infected devices.
Why it matters: This malware poses a significant threat to users' personal and financial security by enabling attackers to manipulate communication with banks, making it difficult for victims to discern legitimate interactions. By masquerading as trusted contacts and setting itself as the default call handler, the malware gains control over all calls, intercepting and redirecting them without the user’s knowledge. Its ability to capture live audio and video escalates the risk to privacy and security, allowing attackers to listen to sensitive conversations and access personal information, such as passwords, which can potentially lead to further attacks. Additionally, real-time monitoring of the victim’s environment enables attackers to gather further insights, facilitating more sophisticated phishing schemes tailored to what they observe.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user DarkRaaS: Threat actor "DarkRaaS" allegedly advertised a database for sale associated with Zanko, a Malaysia-based IT solutions service provider, on predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-10456: Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary [.]NET objects prior to authentication.
Affected products: InfraSuite Device Master Versions 1.0.12 and prior
Tags: DIB, tlp:green