ZeroFox Weekly Intelligence Brief – December 2, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – December 2, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on November 29, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
INTERPOL and AFRIPOL Target Cybercrime in Africa, Arresting over 1,000 Suspects
What happened: Operation Serengeti, coordinated by INTERPOL and AFRIPOL, was a major law enforcement initiative across 19 African countries, targeting a wide range of cybercrimes. Between September 2 and October 31, authorities arrested over 1,000 individuals suspected of involvement in cybercriminal activities, including ransomware attacks, business email compromise (BEC), digital extortion, and online scams. These crimes led to an estimated global financial loss of nearly USD 193 million, and approximately USD 44 million of the stolen funds were reportedly recovered. This operation resulted in the takedown of over 134,000 malicious infrastructures. The operation focused on dismantling various types of fraud schemes, from Ponzi scams and credit card fraud to online investment and multi-level marketing frauds.
UK Warns of Russia’s Potential Use of AI in Cyberattacks
What happened: During the recent NATO Cyber Defence Conference, a senior UK official warned about Russia using artificial intelligence (AI) in its cyberattacks and noted possible measures to “stay one step ahead in this new AI arms race.” The measures include the launch of a new UK government-funded Laboratory for AI Security Research at the University of Oxford that will assemble a team of experts to assess the impact of AI on national security. The official also stated that besides Russia’s military effort, the state is involved in orchestrating a “hidden” cyberwar that can be both destabilizing and debilitating. Russia has targeted media, telecoms, political and democratic institutions, and energy infrastructure in the United Kingdom and continues to target other such states that lend support to or are seemingly politically aligned with Ukraine in the Russia-Ukraine war.
Zero-Days Exploited by Russian RomCom Hackers
What happened: The Russia-based threat actors dubbed as RomCom exploited two zero-day vulnerabilities—CVE-2024-9680 and CVE-2024-49039—targeting Firefox and Tor Browser users in Europe and North America. According to the National Institute of Standards and Technology’s (NIST’s) National Vulnerability Database (NVD), an attacker was able to achieve code execution in the content process by exploiting a use-after-free in animation timelines. The second vulnerability is a task scheduler elevation of privilege vulnerability.
Tags: DIB, tlp:green