ZeroFox Cyber Intelligence Daily Brief - November 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Andrew Tate’s University Breach: User Records and Chats Leaked
- South Korean Police Reveals North Korean Hackers Were Responsible for USD 41.5 Million Crypto Heist
- Bangkok Busts SMS Blaster Sending 1 Million Scam Texts from a Van
Andrew Tate’s University Breach: User Records and Chats Leaked
Source: https://hackread.com/andrew-tate-university-breach-user-records-chats-leak/
What happened: Politically-motivated hackers breached Andrew Tate’s platform, “The Real World,” exposing sensitive data, including usernames, private chats, and email addresses. However, Andrew Tate has seemingly denied that there has been a breach.
Why it matters: Exploiting a critical security flaw, the hackers accessed close to 800,000 usernames and hundreds of chat servers, leaking sensitive user information. The unidentified hackers flooded chatrooms with pro-feminist and LGBTQ+ content, disrupting the platform and banning users. The exposure of sensitive user data, including private messages, email addresses, and usernames, puts members at risk of phishing, harassment, and identity theft.
South Korean Police Reveals North Korean Hackers Were Responsible for USD 41.5 Million Crypto Heist
What happened: The Korean National Police Agency (KNPA), Seoul, has revealed that hackers associated with the North Korean military orchestrated a cryptocurrency heist in 2019, involving 342,000 of a specific type of cryptocurrency coin (equivalent to USD 41.5 million). According to reports, the responsible groups were Lazarus and Andariel, linked to North Korea’s Reconnaissance General Bureau affiliated with its military.
Why it matters: The KNPA identified the tactics, techniques, and procedures (TTPs) performed against the targeted cryptocurrency exchange and shared them with relevant agencies and domestic cryptocurrency exchanges, which will result in the detection of similar crimes and prevent possible damages. North Korean hackers—including Andariel, Lazarus, and Kimsuky—have previously been accused of conducting cyberattacks targeting cryptocurrency-related companies between 2017 and 2023. The motivation behind such cryptocurrency heists is reportedly to gather financial resources to fund North Korea’s missile programs.
Bangkok Busts SMS Blaster Sending 1 Million Scam Texts from a Van
What happened: The Thailand police located a van and arrested an individual for using an SMS blaster device to send over 100,000 phishing messages per hour to people in Bangkok. Over three days, the individual sent nearly one million messages, directing recipients to a fraudulent website asking for credit card details.
Why it matters: The arrest has disrupted a major international phishing operation that targeted millions of people in Bangkok. Scammers sent messages claiming users' reward points were about to expire, sparking a false sense of urgency and prompting recipients to visit a fake AIS (Thailand’s largest mobile operator) website designed to steal sensitive financial information. By clicking the fraudulent link, many individuals risked exposing their credit card details, which likely can lead to unauthorized transactions and financial losses.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Cryptojackers of India: Pro-India hacktivist group "Cryptojackers of India" claimed to target Malaysia under #OpMalaysia. The group alleged that different countries, including Malaysia, have been carrying out cyberattacks targeting Indian cyber space. The actor warns that the upcoming attacks will target a wide range of infrastructure.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-53911: An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a [.]NET Remoting TCP port, is deserialized.
Affected products: Enterprise Vault versions before 15.2
Tags: DIB, tlp:green