ZeroFox Cyber Intelligence Daily Brief - November 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
- Chinese Hackers Target Linux with New Backdoors
- USDA Releases Report Detailing the Implementation of Phishing-Resistant Multi-Factor Authentication
North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
Source: https://thehackernews.com/2024/11/north-korean-front-companies.html
What happened: Threat actors linked to North Korea have been impersonating U.S.-based software and technology consulting businesses to infiltrate global job markets, including the United States, as part of a broader scheme to generate illicit revenue. This operation, dubbed “Wagemole,” involves North Korean IT workers using fake identities to secure employment and funnel a significant portion of their wages back to the regime.
Why it matters: This activity is a strategy by North Korea to bypass international sanctions and fund its weapons programs, including nuclear and ballistic missile development. By exploiting the global demand for IT workers, North Korea is able to obtain foreign currency and launder it through legitimate employment channels. The Wagemole scheme likely finances activities that contribute to security threats and deepening global political divides.
Chinese Hackers Target Linux with New Backdoors
What happened: Chinese APT group "Gelsemium" has adapted its malware toolkit to target Linux systems, introducing backdoors named Wolfsbane and Firewood. These tools execute commands from command-and-control (C2) servers, enabling data exfiltration, file operations, and system manipulation.
Why does it matter: It is likely that threat actors are targeting Linux devices more since organizations have accelerated their adoption, while defenses improve in other popular operating systems (OS). The adaptation of Gelsemium's toolkit to Linux systems likely indicates an expansion of China's cyber espionage capabilities. By introducing Linux backdoors like Wolfsbane and Firewood, the group aims to infiltrate and maintain control over critical systems used by governments, businesses, and research organizations.
USDA Releases Report Detailing the Implementation of Phishing-Resistant Multi-Factor Authentication
What happened: CISA and the U.S. Department of Agriculture (USDA) jointly released a report detailing how USDA successfully implemented phishing-resistant authentication for its personnel in situations where USDA could not exclusively rely on personal identity verification (PIV) cards.
Why it matters: USDA turned to Fast IDentity Online (FIDO) capabilities, which its centralized technology architecture already supported, to address the challenge of finding an authentication solution to counter credential phishing threats. FIDO is a set of authentication protocols that uses cryptographic keys on user devices to offer a secure, phishing-resistant way to authenticate user identities—all without passwords. To date, this technology has allowed approximately 40,000 registered users, some of whom historically required PIV exemptions, to access USDA’s network without introducing the risks associated with usernames and passwords.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Hunt3r Kill3rs and more: On November 21, 2024, pro-Palestine (and an ally of many pro-Russia groups) threat actor group Hunt3r Kill3r announced a cyber campaign on the American cyberspace called #RED_EYE_OP, including other threat actor groups.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-21287: Vulnerability in the Oracle Agile Product Lifecycle Management (PLM) Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data.
Affected products: Oracle Agile PLM Framework, version 9.3.6
Tags: DIB, tlp:green