ZeroFox Weekly Intelligence Brief – November 4, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 4, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on November 1; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Russian Espionage Campaign Targets Ukrainian Military Recruits with Malware
What happened: UNC5812, a suspected Russian hybrid espionage group, launched an operation targeting the Ukrainian military through a Telegram channel named Civil Defense and a corresponding website. The campaign, active since September 10, 2024, uses operating system (OS) malware to compromise devices. Android OS users are tricked into disabling specific security software, allowing the installation of a remote access trojan (CraxsRAT) hidden within a decoy mapping app called SUNSPINNER. On another popular OS, malware delivery is facilitated through ZIP files containing the Pronsis loader, which distributes SUNSPINNER and PureStealer malware. Beyond malware distribution, UNC5812 also runs influence operations to disrupt Ukrainian military mobilization by spreading anti-recruitment narratives across messaging platforms.
Law Enforcement Action Across the World
What happened: This week saw several high-profile law enforcement actions targeting threat actors across the world. Six individuals have been charged in the United States for their roles in schemes to rig bids, defraud the government, and pay bribes and kickbacks in connection with the sale of IT products and services to federal government purchasers. These are the first charges in the Justice Department’s ongoing investigation into IT manufacturers, distributors, and resellers who sell products and services to government purchasers, including to the intelligence community. Dutch National Police, in collaboration with the FBI and other international law enforcement bodies, have disrupted the operations of the Redline and Meta infostealers in an operation called Operation Magnus. They seized the source codes, user data, and identifying information of individuals who used the malware. Four members of the REvil ransomware group have been sentenced to several years in prison in Russia for illegal circulation of payment methods. The Russian Federal Security Service (FSB), in collaboration with the Interior Ministry, conducted raids across multiple regions and detained 14 suspects linked to the group, though the investigation is still ongoing to determine each individual’s involvement in the crimes.
LottieFiles Supply Chain Attack Exposes Users to Malicious Crypto Wallet Drainer
What happened: Software-as-a-service platform LottieFiles’ Lottie-Player project recently fell victim to a supply chain attack that resulted in the injection of a crypto-drainer script into various websites. This malicious script is designed to target Lottie-Player users connecting their cryptocurrency wallets, ultimately stealing their assets and NFTs. Reports indicate that at least one individual lost a staggering USD 723,000 in Bitcoin due to this breach. In response, LottieFiles quickly released updated version 2.0.8 and urged users to upgrade immediately. For those unable to do so, it is essential to communicate the potential risks to Lottie-Player end users and caution them against fraudulent wallet connection requests.
Tags: DIB