zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 3, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 3, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hydra Market Leader Sentenced to Life in Prison, over a Dozen Convicted
  • Poland Probes Illegal Spyware Deployment by Former Leaders
  • SmokeLoader Malware Targets IT, Healthcare, and Manufacturing in Taiwan

Hydra Market Leader Sentenced to Life in Prison, over a Dozen Convicted

Source: https://epp.genproc.gov.ru/web/proc_50/mass-media/news?item=99442998

What happened: The leader of the criminal group behind the now-defunct dark web platform Hydra Market was sentenced to life imprisonment, alongside more than a dozen accomplices convicted for trafficking nearly a ton of drugs.

Why it matters: Hydra Market, one of the largest illicit online marketplaces, facilitated the global distribution of illegal drugs and other criminal activities from 2015 to 2018 across Russia and Belarus. The leader of the criminal group was sentenced to life imprisonment and fined RUB 4 million (approx. USD 37.56 thousand), while the co-conspirators received prison sentences ranging from 8 to 23 years and fines totaling RUB 16 million (approx. USD 0.15 million).

Poland Probes Illegal Spyware Deployment by Former Leaders

Source: https://techcrunch.com/2024/12/02/poland-arrests-former-spy-chief-in-pegasus-spyware-probe/

What happened: The former head of Poland's internal security service was arrested and is detained to testify about the prior government’s use of Pegasus spyware to surveil hundreds of opposition politicians and others. The current government is currently investigating these unlawful surveillance practices.

Why it matters: Advocacy groups, including Amnesty International, have, in the past, emphasized the urgent need to regulate spyware like Pegasus to prevent its misuse. Authorities allegedly used Pegasus against opposition figures, including a member of the Polish Senate, potentially undermining the integrity of Poland’s 2019 parliamentary elections and democratic processes. Poland’s ruling party reportedly misused public funds—meant to be set aside to aid crime victims and rehabilitate offenders—to purchase Pegasus and deployed it against political critics, indicating abuse of power.

SmokeLoader Malware Targets IT, Healthcare, and Manufacturing in Taiwan

Source: https://thehackernews.com/2024/12/smokeloader-malware-resurfaces.html

What happened: SmokeLoader malware, which has resurfaced after being disrupted in May 2024 in law enforcement-run Operation Endgame, is targeting healthcare, information technology, and manufacturing entities in Taiwan. Threat actors continue to deploy SmokeLoader to distribute payloads through new command-and-control (C2) infrastructure.

Why it matters: SmokeLoader’s versatile features, including advanced evasion techniques and modular design, allow it to adapt to a variety of attack scenarios, while complicating analysis and detection efforts. Moreover, the malware can also deliver plugins directly instead of relying on standalone payloads, which allows threat actors to maintain persistent access to compromised systems, exfiltrate data, perform distributed denial-of-service (DDoS) attacks, and mine cryptocurrency.

DEEP AND DARK WEB INTELLIGENCE

XSS user KrakenBite: Untested threat actor "KrakenBite" advertised a 5-in-1 phishing kit with Telegram Bot on predominantly Russian language dark web forum XSS. According to KrakenBite, the phishing kit contains five phishing pages source code (html, css, js).

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-39392: InDesign Desktop versions ID18.5.2, ID19.3, and earlier are vulnerable to a Heap-based Buffer Overflow that could allow arbitrary code execution within the context of the current user. Exploiting this vulnerability requires user interaction, as the victim is required to open a malicious file.

Affected products: InDesign Desktop versions ID18.5.2, ID19.3, and earlier

Tags: DIB, tlp:green