zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 9, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait
  • FBI Issues Warning About Racist Text Messages
  • South Korea Says Pro-Russia Groups Responsible for Cyberattacks After North's Troop Dispatch

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

Source: https://thehackernews.com/2024/11/china-aligned-mirrorface-hackers-target.html

What happened: The China-aligned hacking group MirrorFace (also known as Earth Kasha), part of the APT10 umbrella, was observed targeting a diplomatic organization in the European Union (EU) using spear-phishing. The group lured the victim with an email about the 2025 World Expo in Osaka, Japan, containing a link to a malicious ZIP archive (The EXPO Exhibition in Japan in 2025[.]zip) hosted on a cloud storage service to gain access.

Why it matters: This marks the first time MirrorFace has targeted an EU entity, expanding its operational reach beyond Japan, Taiwan, and India. The use of the 2025 World Expo as a social engineering tool suggests that MirrorFace is likely leveraging high-profile global events to craft convincing phishing campaigns, exploiting widespread public and professional interest to gain access to sensitive networks. The attack could signal broader geopolitical espionage, with potential implications for sensitive diplomatic and international security information.

FBI Issues Warning About Racist Text Messages

Source: https://www.fbi.gov/news/press-releases/fbi-statement-on-offensive-and-racist-text-messages

What happened: Thousands of individuals across the United States received offensive and racist text messages, reportedly from a government phone number, raising concerns about a possible data breach or misuse of official communication channels. The FBI acknowledged the situation and confirmed it is coordinating with the Justice Department and other federal agencies to investigate and address the incident.

Why it matters: Offensive and racist messages targeting specific communities are likely to incite fear, anger, or division likely leading to public unrest and even physical altercations. Malicious actors will likely leverage social tensions built after the U.S. election results to disrupt public order or test government responses. Besides, such impersonations of official channels will likely erode public trust in legitimate emergency alerts and public safety communications, making people more susceptible to misinformation and hindering effective crisis response.

South Korea Says Pro-Russia Groups Responsible for Cyberattacks After North's Troop Dispatch

Source: https://www.reuters.com/world/south-korea-says-pro-russia-groups-responsible-cyberattacks-after-norths-troop-2024-11-08/

What happened: Pro-Russia hacking groups launched cyberattacks against South Korea after North Korea sent troops to Russia to support its war in Ukraine. The attacks targeted government and private websites, causing temporary outages but no major damage.

Why it matters: The cyberattacks by pro-Russia hacking groups on South Korea, following North Korea’s troop support to Russia, can likely indicate a potential increase in cyber threats, especially hacktivism, stemming from geopolitical alliances. This attack likely escalates cybersecurity concerns for South Korea, and that allied states might launch attacks to further mutual political and military goals. The attacks can also likely indicate that critical South Korean infrastructure could face heightened vulnerability to state-aligned groups.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user Fighter Blackhat Cyber Crime: Threat actor "Fighter Blackhat Cyber Crime" announced to collaborate with pro-Palestine, pro-Muslim hacktivist group RipperSec (allegedly operating from Malaysia). The collaboration aimed to target Australia and Ukraine under operations #OpsAustralia and #OpsUkraine for supporting Israel.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-51358: An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application. This flaw has a CVSS score of 9.8.

  • Affected product: Linux Server Heimdall v.2.6.1

Tags: DIB, tlp:green