zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Federal Court Convicts 10 for Their Participation in Identity Theft and Fraud Ring
  • INTERPOL Cyber Operation Takes Down 22,000 Malicious IP Addresses
  • APT36 Refines Tools in Attacks on Indian Targets

Federal Court Convicts 10 for Their Participation in Identity Theft and Fraud Ring

Source: https://www.justice.gov/usao-sc/pr/10-convicted-south-carolina-multi-state-identity-theft-and-fraud-ring

What happened: A U.S. federal court has convicted 10 individuals for participating in a COVID-19 relief-themed identity theft and fraud ring in South Carolina, which claimed victims across multiple states. Between 2020 and 2023, the group used stolen identities from the dark web to secure luxury vehicles, loans, and rental properties, leading to over USD 650,000 in fraud and substantial asset seizures.

Why it matters: The group leveraged the dark web to obtain sensitive data that fueled a sophisticated campaign, exposing targeted individuals to substantial financial and physical threats. Victims suffered severe financial repercussions—including unpaid debts and credit damage—while some of the perpetrators fraudulently obtained Paycheck Protection Program (PPP) loans. The campaign is another example of how malicious actors abuse COVID-19 relief programs for financial fraud.

INTERPOL Cyber Operation Takes Down 22,000 Malicious IP Addresses

Source: https://www.interpol.int/News-and-Events/News/2024/INTERPOL-cyber-operation-takes-down-22-000-malicious-IP-addresses

What happened: INTERPOL's global Operation Synergia II (conducted from April–August 2024) successfully dismantled over 22,000 malicious IP addresses and seized 59 servers linked to cyber threats like phishing, ransomware, and information theft. The operation also led to the arrest of 41 individuals, with 65 more under investigation.

Why it matters: Operation Synergia II demonstrates the power of global collaboration in combating cybercrime. By taking down over 22,000 malicious IPs and seizing infrastructure critical for the operations, INTERPOL disrupted major cybercriminal campaigns involved in phishing, ransomware, and information theft. This intervention potentially prevented millions of cyberattacks, safeguarding individuals, businesses, and governments worldwide.

APT36 Refines Tools in Attacks on Indian Targets

Source: https://www.darkreading.com/cyberattacks-data-breaches/apt36-refines-tools-attacks-indian-targets

What happened: Pakistan's APT36 group has upgraded its ElizaRAT malware targeting Indian government, military, and diplomatic sectors. The updated ElizaRAT reportedly includes several features including advanced command-and-control capabilities, a new payload that exfiltrates sensitive file metadata from compromised systems, and new evasion techniques.

Why it matters: The new capabilities APT36 has adopted likely increases the threat posed to India's government, military, and diplomatic infrastructure, potentially further compromising sensitive information essential to national security. The advanced evasion techniques in the new ElizaRAT variant is likely intended to make it more difficult for defenders to detect and weed out the malware, prolonging attackers' access to compromised systems. Additionally, the new payload reportedly enables APT36 to collect targeted data, which could provide valuable intelligence or be leveraged for further attacks, thereby amplifying the group’s intended impact on critical sectors.

Tags: DIB, tlp:green