zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 1, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 1, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • European Law Enforcement Stops Illegal IPTV Service Providers
  • GhostSpider Malware Evades Detection in Salt Typhoon’s Espionage Attacks
  • South Korean Police Reveals North Korean Hackers Were Responsible for USD 41.5 Million Crypto Heist

European Law Enforcement Stops Illegal IPTV Service Providers

Source: https://www.europol.europa.eu/media-press/newsroom/news/european-law-enforcement-stops-illegal-iptv-service-providers

What happened: Law enforcement authorities across Europe have taken down one of the largest illegal Internet Protocol Television (IPTV) networks operating within and outside the European Union. The investigation targeted 102 suspects, 11 of whom were arrested, for distributing material from streaming services online illegally, including movies and series.

Why it matters: The accused individuals also pirated more than 2,500 television channels such as sports broadcasters, making them available to over 22 million users worldwide without the consent of the copyright holders. In addition to intellectual property crime (copyright infringement), there are, reportedly, indications of further crimes, such as money laundering and cybercrime. Many of these platforms likely operate without safeguards, leaving users vulnerable to exploitation, including data theft, fraud, and more.

GhostSpider Malware Evades Detection in Salt Typhoon’s Espionage Attacks

Source: https://www.bleepingcomputer.com/news/security/salt-typhoon-hackers-backdoor-telcos-with-new-ghostspider-malware/

What happened: Chinese hacking group Salt Typhoon deployed the GhostSpider backdoor alongside other advanced tools like Masol RAT and Demodex in global espionage campaigns. It successfully breached telecommunications providers, government networks, and critical industries, stealing sensitive data and infiltrating private communications.

Why it matters: GhostSpider is a stealthy, memory-resident backdoor with encrypted communication and modular functionality, making it difficult to detect and counter. Its ability to execute tailored commands and adapt to victim defenses is an escalation in malware sophistication. Combined with other tools in Salt Typhoon’s arsenal, such as rootkits and multi-stage backdoors, this malware enables prolonged and evasive espionage, which can be leveraged in cyberattacks across critical systems worldwide.

South Korean Police Reveals North Korean Hackers Were Responsible for USD 41.5 Million Crypto Heist

Source: https://police.go.kr/user/bbs/BD_selectBbs.do?q_bbsCode=1002&q_bbscttSn=20241122133247595&q_tab=&q_searchKeyTy=&q_searchVal=&q_rowPerPage=10&q_currPage=1&q_sortName=&q_sortOrder=&

What happened: The Korean National Police Agency (KNPA), Seoul, has revealed that hackers associated with the North Korean military orchestrated a cryptocurrency heist in 2019, involving 342,000 of a specific type of cryptocurrency coin (equivalent to USD 41.5 million). According to reports, the responsible groups were Lazarus and Andariel, linked to North Korea’s Reconnaissance General Bureau affiliated with its military.

Why it matters: The KNPA identified the tactics, techniques, and procedures (TTPs) performed against the targeted cryptocurrency exchange and shared them with relevant agencies and domestic cryptocurrency exchanges, which will result in the detection of similar crimes and prevent possible damages. North Korean hackers—including Andariel, Lazarus, and Kimsuky—have previously been accused of conducting cyberattacks targeting cryptocurrency-related companies between 2017 and 2023. The motivation behind such cryptocurrency heists is reportedly to gather financial resources to fund North Korea’s missile programs.

Tags: DIB, tlp:green