zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian Espionage Group Targets Ukrainian Military with Malware via Telegram
  • China's “Evasive Panda” APT Debuts High-End Cloud Hijacking
  • North Korean Group Collaborates with Play Ransomware in Cyberattack

Russian Espionage Group Targets Ukrainian Military with Malware via Telegram

Source:https://thehackernews.com/2024/10/russian-espionage-group-targets.html

What happened: A newly uncovered hybrid espionage and influence campaign operated by Russian threat group “UNC5812” targets Ukrainian military recruits using malware for popular operating systems. The campaign uses a deceptive "Civil Defense" persona along with a website and Telegram channel to distribute a malicious app disguised as a recruitment avoidance tool.

Why it matters: By spreading narratives against Ukraine's recruitment efforts, this campaign not only seeks to gather sensitive information but also aims to instill doubt and resistance among potential recruits regarding Ukraine's military initiatives. This poses a significant threat to the country's ability to effectively mobilize its forces during a critical time. The operation enables attackers to engage in data theft and real-time surveillance while masquerading as a legitimate, Ukraine-friendly organization. Overall, it shows Russia's continued involvement and capabilities in the realm of cyber warfare.

China's “Evasive Panda” APT Debuts High-End Cloud Hijacking

Source: https://www.darkreading.com/cloud-security/china-evasive-panda-apt-cloud-hijacking

What happened: China-sponsored hacking group Evasive Panda has launched CloudScout, a sophisticated post-compromise toolset that exploits stolen Web session cookies to access various cloud services. This tool works in conjunction with their proprietary malware framework, MgBot, enabling it to target popular cloud storage and email platforms.

Why it matters: CloudScout allows attackers to bypass security measures through authenticated session hijacking, posing a serious threat to cloud security. CloudScout's ability to infiltrate at least 10 different cloud applications reveals the rising risks associated with these services. As organizations increasingly rely on cloud solutions, this capability can enable attackers to gain unauthorized access to sensitive data, leading to breaches that compromise personal information and corporate secrets. Such widespread access heightens the potential for financial loss and reputational damage, while also facilitating further malicious activities like identity theft and espionage.

North Korean Group Collaborates with Play Ransomware in Cyberattack

Source: https://thehackernews.com/2024/10/north-korean-group-collaborates-with.html

What happened: North Korea-linked Andariel has reportedly been observed working with the Play ransomware group in a recent cyber incident. It is still unclear if this collaboration was a one-time event, that Andariel may be acting as an initial access broker for the Play ransomware group, and if future collaborative efforts are likely.

Why it matters: Collaborations, like this one, likely enables streamlined attacks that may allow the threat groups to evade detection more effectively, while combining resources to allow these groups to target larger or more complex networks. If these groups collaborate in the future, such a partnership can create an ecosystem where the cybercriminal groups can likely share tools, infrastructure, and intelligence, resulting in more persistent threats.

Tags: DIB, tlp:green