ZeroFox Cyber Intelligence Daily Brief - November 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- People's Republic of China Actors Target Commercial Telecommunications Infrastructure
- Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks
- Leaked Data of More than 100 Million Linked to B2B Data Aggregator Breach
People's Republic of China Actors Target Commercial Telecommunications Infrastructure
What happened: The FBI and CISA have released a joint statement addressing a broad and significant cyber espionage campaign orchestrated by actors affiliated with the People’s Republic of China (PRC), targeting multiple telecommunication companies. Through the campaign, the actors accessed customer call records data, data from law enforcement (LE) requests, and private communications of a few individuals, primarily involved in government or political activity.
Why it matters: The campaign targets, including telecommunication networks, LE databases, and government-associated individuals, likely indicate that the PRC actors were gathering intelligence on the U.S. government and political figures. Such breaches risk exposing classified operations, compromising individual safety, and damaging trust in essential communication infrastructures. Besides, with a new government soon to be formed in the United States, adversarial state-affiliated actors are likely to turn their attention towards government intelligence to give their states a political edge.
Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks
Source: https://thehackernews.com/2024/11/iranian-hackers-use-dream-job-lures-to.html
What happened: The Iranian hacking group TA455, linked to the Islamic Revolutionary Guard Corps (IRGC), has been using fake job offers to target the aerospace sector since September 2023. The group distributes the SnailResin malware, which activates the SlugResin backdoor, allowing for remote access and lateral movement within compromised networks.
Why it matters: This attack marks a shift in TA455's tactics, potentially mimicking North Korean hacking groups to obscure attribution or share tools. By deploying sophisticated malware like SnailResin, the group gains persistent access to sensitive systems, enabling espionage, credential theft, and further exploitation. The aerospace sector, a high-value target, faces long-term risks such as stolen intellectual property, sabotage, and serious cybersecurity threats to national security. Additionally, TA455 employs social engineering techniques to deliver malicious backdoors like MINIBIKE and MINIBUS through fake recruiting websites and LinkedIn profiles.
Leaked Data of More than 100 Million Linked to B2B Data Aggregator Breach
What happened: The business contact details for more than a 100 million people, originally sourced from the B2B data aggregator, have reportedly been leaked. The leaked data, which includes names, emails, job titles, addresses, and social media links, was initially offered for sale on BreachForums in February 2024 for USD 6,000. ZeroFox observed that in August 2024, the data was reportedly exposed on BreachForums, leaving millions of business contacts to potential misuse.
Why it matters: This breach exposes a vast set of sensitive business contact information, putting millions of individuals and companies at risk of targeted cyber threats, such as phishing and spear-phishing attacks. Attackers can use the leaked data to impersonate executives, exploit connections between employees, or conduct sophisticated business email compromise (BEC) scams. The exposure of job titles and social media links also heightens the risk of social engineering, as attackers can tailor their messages to specific individuals or departments.
DEEP AND DARK WEB INTELLIGENCE
Exploit user arkansas: Untested threat actor "arkansas" has advertised shell access to an unnamed UK-based healthcare company on predominantly Russian language Dark Web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-10914: This critical severity vulnerability affects several end-of-life D-Link network-attached storage (NAS) devices. Threat actors can exploit these devices to inject arbitrary shell commands. Threat actors have recently begun to target these devices after the company said that it will no longer support end of life D-Link devices.
Affected products: D-Link DNS-320, DNS-320LW, and DNS-325 and DNS-340L up to 20241028
Tags: DIB, tlp:green