zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 7, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 7, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Federal Court Convicts 10 for Their Participation in Identity Theft and Fraud Ring
  • Scammers Target BASE with Political Meme Coins and Rug Pulls
  • South Korea Fines Meta USD 15.67 Million for Illegally Sharing Sensitive User Data with Advertisers

Federal Court Convicts 10 for Their Participation in Identity Theft and Fraud Ring

Source: https://www.justice.gov/usao-sc/pr/10-convicted-south-carolina-multi-state-identity-theft-and-fraud-ring

What happened: A U.S. federal court has convicted 10 individuals for participating in a COVID-19 relief-themed identity theft and fraud ring in South Carolina, which claimed victims across multiple states. Between 2020 and 2023, the group used stolen identities from the dark web to secure luxury vehicles, loans, and rental properties, leading to over USD 650,000 in fraud and substantial asset seizures.

Why it matters: The group leveraged the dark web to obtain sensitive data that fueled a sophisticated campaign, exposing targeted individuals to substantial financial and physical threats. Victims suffered severe financial repercussions—including unpaid debts and credit damage—while some of the perpetrators fraudulently obtained Paycheck Protection Program (PPP) loans. The campaign is another example of how malicious actors abuse COVID-19 relief programs for financial fraud.

Scammers Target BASE with Political Meme Coins and Rug Pulls

Source: https://hackread.com/scammers-base-ethereum-political-meme-coins-rug-pulls/

What happened: Cybersecurity researchers report a surge in scams targeting blockchain networks, with Coinbase’s BASE chain hit particularly hard by politically themed meme coins and multi-chain vulnerabilities. BASE’s low fees and easy token setup allow frequent, low-cost attacks exploiting critical smart-contract flaws.

Why it matters: BASE’s appeal as a low-cost, scalable blockchain backed by Coinbase has attracted both legit users and cybercriminals, exposing it to scams and compromising investor security and Web3’s reputation. Politically themed tokens like “Trump vs Harris” and “Trump2024” exploit investor emotions, using hidden balance updates and malicious minting functions to trap buyers before abruptly cashing out. Such scams risk BASE’s reputation as a secure decentralized finance (DeFi) platform, deterring new users and reputable developers from joining without stronger security controls.

South Korea Fines Meta USD 15.67 Million for Illegally Sharing Sensitive User Data with Advertisers

Source: https://thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html

What happened: South Korea’s Personal Information Protection Commission (PIPC) has fined Meta USD 15.67 million (21.62 billion Won) for reportedly passing along confidential data about Facebook users to advertisers without consent. Meta is also under the radar for its reported failure to adequately secure inactive accounts allowing threat actors to access and leak 10 users’ personal information.

Why it matters: Meta reportedly gathered sensitive data of 980,000 users and shared them with 4,000 advertisers. The sensitive data included the user's religious stances, sexual orientation, and whether they were a defector from North Korea. Along with the leak of 10 people’s data, the overall lack of watchful privacy measures likely opens up a large user base of such a widely used social media platform to threat actors that can target users in phishing attacks, scams, and can likely harass them. With enough personal information, attackers can convincingly impersonate contacts or use the data for blackmail.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user EvilWeb: Threat actor “EvilWeb” claimed to have breached several business systems in the United States and accessed business registration data of an unspecified number of people.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-20418: A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This vulnerability is due to improper validation of input to the web-based management interface.

  • Affected product:

    • Catalyst IW9165D Heavy Duty Access Points
    • Catalyst IW9165E Rugged Access Points and Wireless Clients
    • Catalyst IW9167E Heavy Duty Access Points
  • CVE-2024-43093: This vulnerability can allow threat actors to escalate privileges in the Android Framework component likely leading to unauthorized access to "Android/data," "Android/obb," and "Android/sandbox" directories and its sub-directories. Google’s Android Security Bulletin addresses several severe vulnerabilities that could lead to local escalation of privilege with no additional execution privileges needed. CVE-2024-43093 and CVE-2024-43047 are two vulnerabilities that may be under limited and targeted exploitation.

  • Affected products: Android Framework

Tags: DIB, tlp:green