zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Joint Guidance on PRC Threat Actors Targeting Global Telecommunications Providers
  • Authorities Take Down Illegal Encrypted Messaging Service
  • North Korean Hackers Leverage Russian-Sourced Emails in Phishing Campaigns for Credential Theft

Joint Guidance on PRC Threat Actors Targeting Global Telecommunications Providers

Source: https://www.cisa.gov/news-events/alerts/2024/12/03/cisa-and-partners-release-joint-guidance-prc-affiliated-threat-actor-compromising-networks-global

What happened: CISA—with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners—has released a joint guidance, Enhanced Visibility and Hardening Guidance for Communications Infrastructure.

Why it matters: The guidance is a response to threat actors affiliated with the People’s Republic of China (PRC) compromising networks of major global telecommunications providers to conduct a broad and significant cyber espionage campaign. The compromise of private communications impacted a limited number of individuals primarily involved in government or political activity. Although tailored to network defenders and engineers of communications infrastructure, this guide may also apply to organizations with on-premises enterprise equipment.

Authorities Take Down Illegal Encrypted Messaging Service

Source: https://www.europol.europa.eu/media-press/newsroom/news/international-operation-takes-down-another-encrypted-messaging-service-used-criminals

What happened: A joint investigation team (JIT), involving Eurojust and Europol, has taken down another sophisticated illegal encrypted messaging service, MATRIX, which was first discovered on the phone of a criminal convicted for the murder of a Dutch journalist in 2021. More than 2.3 million messages in 33 languages were intercepted and deciphered during the investigation.

Why it matters: The three-month-long interception and monitoring MATRIX revealed messages that were linked to serious crimes such as international drug trafficking, arms trafficking, and money laundering. The service is reportedly considered superior and more secure than previous applications used by criminals, who were only able to join the service if they received an invitation. The infrastructure to run MATRIX consisted of more than 40 servers in several countries with important servers found in France and Germany.

North Korean Hackers Leverage Russian-Sourced Emails in Phishing Campaigns for Credential Theft

Source: https://thehackernews.com/2024/12/north-korean-kimsuky-hackers-use.html

What happened: Kimsuky, a North Korea-linked hacking group, has been carrying out a series of phishing campaigns using Russian sender addresses and abusing VK’s Mail[.]ru email service. These attacks target users by impersonating trusted entities, like financial institutions and cloud storage services like Naver's MYBOX, tricking victims into clicking malicious links that lead to credential theft.

Why it matters: By leveraging legitimate tools like PHPMailer and trusted email domains like mail[.]ru, internet[.]ru, bk[.]ru, inbox[.]ru, and list[.]ru, Kimsuky increases the chances of bypassing security filters and making phishing emails appear credible. Once credentials are harvested, the threat actors can access personal and business accounts, launching further attacks that likely lead to data theft, espionage, or corporate network infiltration. Furthermore, the use of compromised accounts not only threatens individual and organizational security but also weakens trust in email and cloud-based services.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Fredens Of Security: Threat actor group "Fredens Of Security" has claimed to leak sensitive data allegedly linked to The Royal Thai Armed Forces Headquarters and SEAT, a Spain-based car manufacturer.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-42448: This vulnerability allows attackers to execute arbitrary code on unpatched servers by exploiting the Veeam Service Provider Console (VSPC) management agent machine. VSPC is a remote-managed platform offering Backend as a Service (BaaS) and Disaster Recovery as a Service (DRaaS), used by service providers to monitor the health and security of customer backups.

Affected products: VPSC 8.1.0.21377 and all earlier versions 8 and 7 builds

Tags: DIB, tlp:green