ZeroFox Cyber Intelligence Daily Brief - November 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 15, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- EPPO Investigation Uncovers EUR 520 Million VAT Fraud Involving Mafia Networks
- Fraud Network Uses 4,700 Fake Shopping Sites to Steal Credit Cards
- Experts Uncover 70,000 Hijacked Domains in Widespread “Sitting Ducks” Attack Scheme
EPPO Investigation Uncovers EUR 520 Million VAT Fraud Involving Mafia Networks
What happened: A European Public Prosecutor’s Office (EPPO) cross-border operation, dubbed “Moby Dick” has uncovered a sophisticated value added tax (VAT) carousel fraud, primarily involving electronic goods such as wireless earphones and laptops. The investigation, led by the EPPO offices in Milan and Palermo, targeted an organized crime network spanning multiple EU Member States and non-EU countries.
Why it matters: VAT carousel fraud takes advantage of EU rules on cross-border transactions between its Member States, as these are exempt from VAT. The suspects established companies in Italy and other EU Member States, as well as in non-EU countries, enabling them to trade the goods through a fraudulent chain of missing traders–who would then vanish without fulfilling their tax obligations. EPPO’s operation will likely dissuade other such criminal networks from engaging in VAT fraud.
Fraud Network Uses 4,700 Fake Shopping Sites to Steal Credit Cards
What happened: The Chinese threat actor "SilkSpecter" has been creating thousands of fake online stores to steal payment card information from shoppers in the United States and Europe. With 4,695 fraudulent domains, the group uses legitimate payment processors like Stripe to make their sites appear trustworthy. Their domains use less common top level domains (TLDs) like [.]shop, [.]store, [.]vip, and [.]top and often mimic brand names to lure unsuspecting customers.
Why it matters: This campaign likely exposes a significant number of online shoppers to financial fraud and identity theft, potentially leading to direct monetary losses. Furthermore, this highlights the risks associated with unfamiliar domain names, even when combined with trusted payment platforms, increasing the likelihood of similar attacks against other popular e-commerce sites. The high number of fraudulent domains also suggests SilkSpecter’s capability to quickly scale and adapt, posing an ongoing challenge for online consumer safety and brand reputation.
Experts Uncover 70,000 Hijacked Domains in Widespread “Sitting Ducks” Attack Scheme
Source: https://thehackernews.com/2024/11/experts-uncover-70000-hijacked-domains.html
What happened: Malicious actors exploited a technique called "Sitting Ducks" to hijack nearly 70,000 domains out of 800,000 vulnerable ones. They gained control by leveraging misconfigurations in the domain name system (DNS) settings, allowing them to redirect traffic from legitimate domains to malicious sites.
Why it matters: The hijacked domains were trusted and had strong reputations, making them ideal for phishing and fraud schemes. The stealthy nature of the attack makes it difficult to detect, and the wide range of affected industries—ranging from entertainment to legal and retail—highlights the broad impact on both businesses and consumers. This type of attack can expose sensitive information, potentially leading to financial loss, reputational damage, and compromised consumer trust.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user 0mid16B: Threat actor "0mid16B" claimed to have leaked a database associated with Joyalukkas, a UAE-based jewelry retailer on predominantly English-language dark web forum BreachForums. The actor alleged that Joyalukkas experienced a data breach in October 2024, reportedly exposing 414 CSV files.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-43451: This vulnerability discloses a user's NTLMv2 hash to the attacker who could use this to authenticate as the user. Windows has detected exploitation of this vulnerability.
Affected product: Windows has listed the affected products in this advisory.
Palo Alto Networks Critical Bug: Palo Alto Networks has observed threat activity exploiting this unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet.
Affected products: PAN-OS management interface
Tags: DIB, tlp:green