zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 27, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 27, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • INTERPOL and AFRIPOL Target Cybercrime in Africa Arresting over 1,000 Suspects
  • Individual Pleads Guilty for Making Vile Threats Against Public Officials
  • Zero-days Exploited by Russian RomCom Hackers

INTERPOL and AFRIPOL Target Cybercrime in Africa Arresting over 1,000 Suspects

Source: https://www.interpol.int/en/News-and-Events/News/2024/Major-cybercrime-operation-nets-1-006-suspects

What happened: A joint operation named “Operation Serengeti” led by INTERPOL and AFRIPOL, resulted in the arrest of 1,006 suspects and the dismantling of 134,089 malicious cyber infrastructures across 19 African countries. The operation targeted major cybercrime threats like ransomware, business email compromise (BEC), digital extortion, and online scams.

Why it matters: By dismantling extensive criminal networks and identifying thousands of victims, the operation will likely reduce the financial and reputational harm caused by the cybercrime campaigns and disrupt dangerous cyber infrastructures that can likely lead to even greater damage. The operation identified more than 35,000 victims of cases linked to nearly USD 193 million in global financial losses reflecting the vast scale and widespread impact of cybercrime both in Africa and worldwide. Operation Serengeti marks a significant advancement in the fight against cybercrime in Africa.

Individual Pleads Guilty for Making Vile Threats Against Public Officials

Source: https://www.justice.gov/usao-az/pr/arizona-man-sentenced-15-months-imprisonment-making-online-threats-against-public

What happened: The U.S. Department of Justice (DOJ) has sentenced an individual to 15 months in prison and 36 months of supervised release for making “vile threats” to execute and sexually assault FBI agents and employees, state and local law enforcement officials, and other public servants. The perpetrator pleaded guilty to one count of Making Threats Against Public Officials.

Why it matters: The actions of the individual are a testament to the fact that as social media platforms become easier to access, with lax censorship, they turn into breeding grounds for online violence, misinformation, and disinformation. Such statements, visible to the public eye, can incite violence, further disinformation campaigns, and pose serious threats to the physical security of those targeted in the statements—as was the case for the violent August riots in the United Kingdom, fuelled by online disinformation. Law enforcement actions, like the DOJ sentencing the individual to prison, can help curb such activities, set a precedent for censorship on social media platforms, and dissuade users from engaging with incendiary posts.

Zero-Days Exploited by Russian RomCom Hackers

Source: https://www.bleepingcomputer.com/news/security/firefox-and-windows-zero-days-exploited-by-russian-romcom-hackers/

What happened: The Russia-based RomCom cybercrime group exploited two zero-day vulnerabilities (CVE-2024-9680 and CVE-2024-49039) to target Firefox and Tor Browser users in Europe and North America. The vulnerabilities allow threat actors to achieve code execution in the content process and the escalation of privilege.

Why it matters: Victims were compromised simply by visiting a malicious website, which redirected them to an exploit server. The shellcode was reportedly executed to download and install the RomCom backdoor, granting attackers remote access to the system. By deploying the RomCom backdoor, attackers likely gain persistent remote access to compromised systems, enabling data exfiltration, espionage, and subsequent financial or operational disruption in critical industries across multiple regions.

DEEP AND DARK WEB INTELLIGENCE

  • Telegram user Mysterious Team Bangladesh: Pro-Palestine hacktivist group Mysterious Team Bangladesh posted that the group will stop conducting cyberattacks for some time due to political tensions in Bangladesh, but plans to resume their activities in the future. This group has carried out numerous actions against Israel and countries that supposedly support Israel, including the United States, India, the United Kingdom, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2023-28461: This Array AG/vxAG remote code execution vulnerability is a web security bug that enables an attacker to browse the filesystem or execute remote code on the SSL VPN gateway using flags attribute in HTTP header without authentication. CISA has added this bug to its Known Exploited Vulnerabilities (KEV) catalog.

  • Affected product: Array Networks Array AG Series and vxAG versions 9.4.0.481 and earlier

Tags: DIB, tlp:green