zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 6, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 6, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • INTERPOL Cyber Operation Takes Down 22,000 Malicious IP Addresses
  • FBI Investigates Russian-Linked Threats and Disinformation Targeting U.S. Elections
  • China State-Linked Group Accused of Hacking SingTel

INTERPOL Cyber Operation Takes Down 22,000 Malicious IP Addresses

Source: https://www.interpol.int/News-and-Events/News/2024/INTERPOL-cyber-operation-takes-down-22-000-malicious-IP-addresses

What happened: INTERPOL's global Operation Synergia II (conducted from April–August 2024) successfully dismantled over 22,000 malicious IP addresses and seized 59 servers linked to cyber threats like phishing, ransomware, and information theft. The operation also led to the arrest of 41 individuals, with 65 more under investigation.

Why it matters: Operation Synergia II demonstrates the power of global collaboration in combating cybercrime. By taking down over 22,000 malicious IPs and seizing infrastructure critical for the operations, INTERPOL disrupted major cybercriminal campaigns involved in phishing, ransomware, and information theft. This intervention potentially prevented millions of cyberattacks, safeguarding individuals, businesses, and governments worldwide.

FBI Investigates Russian-Linked Threats and Disinformation Targeting U.S. Elections

Source: https://www.fbi.gov/news/press-releases/fbi-statement-on-bomb-threats-to-polling-locations

What happened: The FBI has detected bomb threats targeting polling locations across several states, with many threats seemingly traced back to Russian email domains, though none have been deemed credible. In addition, CISA, the FBI, and the Office of the Director of National Intelligence (ODNI) have reported intensified foreign influence campaigns, especially from Russia, aimed at undermining public confidence in the integrity of U.S. elections.

Why it matters: Even though there have reportedly not been major incidents reflecting direct foreign interference in the ongoing voting process, fake threats and disinformation campaigns are likely to continue. With foreign actors, particularly Russia, amplifying false narratives—such as bogus claims of election fraud in swing states—there is a heightened risk of inciting real-world violence and mistrust, particularly toward election officials. False bomb threats and inauthentic media also risk eroding public trust in election security, potentially affecting voter turnout and creating deeper societal divisions.

China State-Linked Group Accused of Hacking SingTel

Source: https://www.reuters.com/technology/cybersecurity/china-state-linked-group-accused-hacking-singtel-bloomberg-news-reports-2024-11-05/

What happened: Singapore Telecommunications (SingTel) was reportedly breached by Chinese state-sponsored hackers, believed to be the group Volt Typhoon. SingTel confirmed that the malware infection was detected and mitigated and that data has not been compromised nor has any operations been impacted.

Why it matters: Even though, at the time of writing, there has been no negative fallout of this attack, it is likely that the attackers may have been testing their abilities to pull off future successful attacks against telecommunication entities. The breach of SingTel’s systems can likely provide attackers with valuable intelligence on network architecture, security protocols, and potential weaknesses.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Anonymous India: Pro-India hacktivist group "Anonymous India" claimed to have targeted Canada. It will supposedly launch a large number of cyberattacks, with the “reasons” to be disclosed soon.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-45240: The TikTok application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). On Android 12 and later, this is only exploitable by third-party applications.

Affected products: TikTok application versions before 34.5.5 for Android

Tags: DIB, tlp:green