ZeroFox Cyber Intelligence Daily Brief - November 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 18, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- NSO Group Used Another WhatsApp Zero-Day After Being Sued
- Darkweb Cryptocurrency Mixer Developer Gets Three Years in Prison
- Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia
NSO Group Used Another WhatsApp Zero-Day After Being Sued
What happened: NSO Group exploited multiple zero-day vulnerabilities in WhatsApp, including a previously unknown exploit called "Erised," to deploy its Pegasus spyware on targets' devices using zero-click attacks. These attacks occurred even after NSO was sued by WhatsApp for its illegal surveillance practices.
Why it matters: Pegasus, a spyware platform developed by the NSO Group, allows its customers to secretly monitor, track, and extract sensitive data from victims' devices, posing serious risks to personal privacy and security. This invasive surveillance exposes individuals to exploitation, manipulation, and even physical harm. Despite being sued by WhatsApp for its illegal surveillance practices, NSO continued deploying zero-click attacks, revealing a blatant disregard for legal boundaries.
Darkweb Cryptocurrency Mixer Developer Gets Three Years in Prison
What happened: The U.S. Department of Justice (DoJ) sentenced the operator of darknet cryptocurrency “mixer” Helix to three years in prison. Helix processed transactions involving over USD 300 million worth of cryptocurrency from 2014 to 2017. The individual also operated Grams, a darknet search engine connected to Helix.
Why it matters: Cryptocurrency mixers (or tumblers) like Helix charge fees to aggregate funds from multiple owners and distribute them to destination addresses, thereby obscuring the direct connection between the digital coins and their owner. Because of the added layer of privacy, Helix was one of the most popular mixing services on the darknet and was highly sought after by online drug dealers who needed to launder their illicit proceeds. Helix’s operator also developed an Application Program Interface (API) to allow darknet markets to integrate Helix directly into their bitcoin withdrawal systems, directly contributing to the laundering of tens of millions of dollars.
Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia
Source: https://thehackernews.com/2024/11/vietnamese-hacker-group-deploys-new-pxa.html
What happened: A Vietnam-linked threat actor is targeting government and educational entities in Europe and Asia with a new malware strain called PXA Stealer. This malware strain can reportedly decrypt stored passwords, steal browser cookies, and exploit Facebook Ads Manager for ad-related account details.
Why it matters: The PXA Stealer poses significant risks like intellectual property theft, espionage, and the disruption of critical services. By decrypting stored passwords and exploiting widely used platforms like Facebook Ads Manager, the strain can likely enable financial fraud, unauthorized transactions, and the diversion of funds from compromised accounts. Researchers have also identified connections to other threat actors, such as CoralRaider, which could mean a potential collaboration or an ongoing sharing of resources, given that the threat actors have been observed to use platforms like Telegram to market hacking tools.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user 0mid16B: Threat actor "0mid16B" claimed to have leaked a database associated with GoldMaster, a Thailand-based jewelry retailer on predominantly English-language dark web forum BreachForums. The actor alleged that GoldMaster experienced a data breach in November 2024, reportedly leaking 21,481 records of its VIP customers' personal information.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-11120: Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Taiwan’s Computer Emergency Response Team has warned this vulnerability has already been exploited by attackers.
Affected product: GeoVision device model GV-VS12, GV-VS11, GV-DSP LPR V3, and GV-LX4C V2 / GV-LX4C V3
Tags: DIB, tlp:green