zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 26, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • UK Warns of Russia’s Potential Use of AI in Cyberattacks
  • GhostSpider Malware Evades Detection in Salt Typhoon’s Espionage Attacks
  • Ransomware Attack on Blue Yonder Hits Starbucks, Supermarkets

UK Warns of Russia’s Potential Use of AI in Cyberattacks

Source: https://www.reuters.com/technology/cybersecurity/britain-nato-must-stay-ahead-new-ai-arms-race-says-uk-minister-2024-11-25/

What happened: During the NATO Cyber Defence Conference on Monday, a senior UK official warned about Russia using artificial intelligence (AI) in its cyberattacks and noted possible measures to “stay one step ahead in this new AI arms race.” The official also announced the launch of a new UK government-funded Laboratory for AI Security Research at the University of Oxford that will assemble a team of experts to assess the impact of AI on national security.

Why it matters: The United Kingdom’s unwavering support for Ukraine is likely to incite more targeted cyberattacks from Russia with escalating intensity. With rapid developments in the field of AI, several nation-state actors—majorly from North Korea and Iran, and to a lesser extent Russia and China—have begun incorporating generative AI in their cyber operations. By exploiting AI in customized and scalable operations, these actors can enhance cyberattacks, create convincing phishing attempts, automate malware development, and spread disinformation using deepfakes or AI-generated content.

GhostSpider Malware Evades Detection in Salt Typhoon’s Espionage Attacks

Source: https://www.bleepingcomputer.com/news/security/salt-typhoon-hackers-backdoor-telcos-with-new-ghostspider-malware/

What happened: Chinese hacking group Salt Typhoon deployed the GhostSpider backdoor alongside other advanced tools like Masol RAT and Demodex in global espionage campaigns. It successfully breached telecommunications providers, government networks, and critical industries, stealing sensitive data and infiltrating private communications.

Why it matters: GhostSpider is a stealthy, memory-resident backdoor with encrypted communication and modular functionality, making it difficult to detect and counter. Its ability to execute tailored commands and adapt to victim defenses is an escalation in malware sophistication. Combined with other tools in Salt Typhoon’s arsenal, such as rootkits and multi-stage backdoors, this malware enables prolonged and evasive espionage, which can be leveraged in cyberattacks across critical systems worldwide.

Ransomware Attack on Blue Yonder Hits Starbucks, Supermarkets

Source: https://www.darkreading.com/cyberattacks-data-breaches/ransomware-attack-blue-yonder-starbucks-supermarkets

What happened: Blue Yonder, a supply chain management software provider, was hit by a disruptive ransomware attack on November 21. The attack impacted the company’s infrastructure, affecting services for major global retailers, manufacturers, and consumer goods companies.

Why it matters: The attack has disrupted key operations for some of the world’s largest retailers and manufacturers, including delays in scheduling, inventory management, order fulfillment, and time-tracking for companies like Starbucks, Morrisons, and Sainsbury's. With the full extent of the damage still under investigation, the timing of the attack—just before the holiday season—raises concerns about potential supply chain bottlenecks. Given Blue Yonder’s critical role in managing logistics for major companies, any prolonged disruption could lead to inventory shortages, delayed product deliveries, and customer dissatisfaction.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user IntelBroker: Well-regarded and established threat actor IntelBroker, in collaboration with EnergyWeaponUser, claimed to have leaked database associated with PT Pegadaian, an Indonesia-based financial service company, on the predominantly English-language dark web forum, BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-38643: QNAP has issued security bulletins addressing multiple vulnerabilities, including critical flaws. One such flaw, CVE-2024-38643, affects Notes Station 3 due to missing authentication for a critical function. If exploited, this vulnerability could allow remote attackers to gain unauthorized access and execute certain actions. The issue has been patched in Notes Station 3 version 3.9.7 and later.

  • Affected product: Notes Station 3 version 3.9.x

Tags: DIB, tlp:green