zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Five Charged in Nationwide Phishing Scam Targeting Several U.S. Companies
  • Akira Ransomware Racks Up over 30 Victims in a Single Day
  • DOJ Unseals Charges Against Phobos Ransomware Operator

Five Charged in Nationwide Phishing Scam Targeting Several U.S. Companies

Source: https://www.justice.gov/usao-cdca/pr/5-defendants-charged-federally-running-scheme-targeted-victim-companies-phishing-text

What happened: Law enforcement unsealed criminal charges against five defendants for allegedly engaging in a nationwide phishing scam to steal non-public company data and hack into virtual currency accounts to steal millions of dollars in cryptocurrency. The accused targeted employees of companies with phishing text messages and then used the harvested employee credentials to access data and financial accounts.

Why it matters: The defendants reportedly sent mass text messages—with links to phishing pages disguised as legitimate websites—pretending to be from the victim company or a contracted information technology or business services supplier of the victim company. Unsuspecting employees landed on the phishing websites, eventually providing confidential information, including account login credentials. They even authenticated their identities using a two-factor authentication request sent to their mobile phones. The case highlights how threat actors can bypass usually robust security measures, like two-factor authentication, by taking advantage of a user's anxiety for financial gain.

Akira Ransomware Racks Up over 30 Victims in a Single Day

Source: https://www.darkreading.com/cyberattacks-data-breaches/akira-ransomware-30-victims-single-day

What happened: The Akira ransomware group updated its data-leak website on November 13-14, revealing more than 30 new victims. This marks the highest single-day total for the group since it began operating in March 2023. The group uses a ransomware-as-a-service (RaaS) model, stealing sensitive data before encrypting it and demanding a ransom.

Why it matters: This surge in attacks shows a significant escalation in Akira's operations, especially as they surpass their total number of victims for 2023 within just a few months.The latest victims span various industries and countries, with around 25 U.S.-based targets, along with others from Canada, Europe, and more. The growing frequency of these attacks suggests that the group is becoming more effective in its operations, posing an increasing threat to global cybersecurity.

DOJ Unseals Charges Against Phobos Ransomware Operator

Source: https://www.justice.gov/opa/pr/phobos-ransomware-administrator-extradited-south-korea-face-cybercrime-charges

What happened: The U.S. Department of Justice (DOJ) has unsealed charges against an individual for allegedly administering the sale, distribution, and operation of Phobos ransomware. Phobos ransomware, through its affiliates, targeted more than 1,000 public and private entities in the United States and around the world and extorted ransom payments worth more than USD 16 million.

Why it matters: Large-scale and intricate ransomware operations, like Phobos, aim to exfiltrate data for financial gain and evade detection by consistently adapting new strategies. Since May 2019, authorities have regularly recorded Phobos ransomware incidents impacting state, local, tribal, and territorial (SLTT) governments. The operation hacked large corporations, schools, hospitals, nonprofits, and a federally recognized tribe, and they extorted more than USD 16 million in ransom payments. The charges will set a precedent for potential similar threats, discouraging other threat actors from following Phobos’ suit and strengthening response tactics against such ransomware attacks.

Tags: DIB, tlp:green