zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI Warns Online Shoppers of Increased Risks from Holiday-Related Scams
  • UK Hospital Network Postpones Procedures After Cyberattack
  • Phishing Scam Exploits Fake Job Terminations to Steal Data and Spread Malware

FBI Warns Online Shoppers of Increased Risks from Holiday-Related Scams

Source: https://www.forbes.com/sites/zakdoffman/2024/11/28/fbi-warns-chrome-safari-and-edge-users-do-not-buy-from-these-sellers/?ss=cybersecurity

What happened: The FBI warns online shoppers against increasing holiday-related scams, where unsuspecting individuals are more likely to fall victim to scams like non-delivery, non-payment, auction fraud, and gift card fraud. With Black Friday being one of the busiest days in retail, the FBI urges shoppers to better guard their personal information and to stay wary of suspicious websites and links.

Why it matters: Threat actors are known to exploit busy shopping days like Black Friday, taking advantage of shoppers drawn to annual discounts. Many websites rely on cookies to enhance user experience by saving session information, but these cookies can be targeted by cybercriminals to execute attacks such as man-in-the-middle attacks, phishing, and cross-site scripting (XSS). The risks increase significantly when users connect to unsecured Wi-Fi networks, as cybercriminals can intercept communication between browsers and websites, stealing session cookies and compromising sensitive information.

UK Hospital Network Postpones Procedures After Cyberattack

Source: https://www.bleepingcomputer.com/news/security/uk-hospital-network-postpones-procedures-after-cyberattack/

What happened: Wirral University Teaching Hospital (WUTH), one of the United Kingdom’s major healthcare providers and part of the NHS Foundation Trust, has suffered a cyberattack that caused a systems outage, leading to the postponement of appointments and procedures, with some IT systems taken offline. Meanwhile, ZeroFox has observed the INC Ransomware leak site targeting the Alder Hey Children's NHS Foundation Trust.

Why it matters: With essential IT infrastructure taken offline, healthcare providers are forced to rely on manual processes, which can significantly slow down operations and compromise the speed of care. While emergency services remain operational, patients are facing long delays and rescheduled appointments, impacting both routine and urgent care. The hospital has urged the public to seek emergency care only for genuine emergencies to avoid further strain on an already overwhelmed system.

Phishing Scam Exploits Fake Job Terminations to Steal Data and Spread Malware

Source: https://www.theregister.com/2024/11/28/fired_phishing_campaign_cloudflare/

What happened: A phishing campaign has been using fake termination notices, mimicking legal tribunal documents, to lure victims into downloading malware like info stealers and banking trojans. The emails exploit the branding of trusted software providers and platform-specific prompts, infecting specific devices and targeting sectors including aerospace, insurance, and education.

Why it matters: By stealing credentials and financial data, this scam enables attackers to access sensitive systems, posing risks like unauthorized transactions, identity theft, and further account compromises. Industries targeted are likely to face further breaches, as attackers are likely to use stolen data to infiltrate networks or sell it on dark markets. Threat actors can mold the attack to likely increase its reach beyond email to social media and networking platforms.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Sylhet Gang: On November 28, 2024, pro-Palestine, religiously motivated Bangladesh-based threat actor group "Sylhet Gang" announced an alliance with threat actor group "Black Widow."

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-49035: This high-severity vulnerability is an improper access control vulnerability that allows an unauthenticated attacker to elevate privileges over a network.

Affected products: Microsoft Power Apps online version (partner[.]microsoft[.]com)

Tags: DIB, tlp:green