ZeroFox Cyber Intelligence Daily Brief - December 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 5, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Sanctions Against Individuals and Entities in Russian Money Laundering Network
- Romanian Elections Integrity Under Threat from Russia
- INTERPOL Campaign Warns Against Cyber and Financial Crimes
Sanctions Against Individuals and Entities in Russian Money Laundering Network
What happened: An international NCA-led investigation—Operation Destabilise—has exposed and disrupted Russian money laundering networks supporting organised crime spread acroos the United Kingdom, the Middle East, Russia, and South America. Investigators have identified two Russian-speaking networks collaborating at the heart of the criminal enterprise, Smart and TGR.
Why it matters: Operation Destabilise uncovered a complex scheme, whereby the networks collect funds in one country and make the equivalent value available in another, often by swapping cryptocurrency for cash. After being paid in crypto in exchange for their cash, criminal gangs would use the virtual currency to reinvest in their illicit business, buying more drugs or firearms without the need to move any physical money across borders. The financial service provided to such groups perpetuated their violent activity, enabling them to cause serious harm to communities across the United Kingdom.
Romanian Elections Integrity Under Threat from Russia
What happened: Declassified Romanian documents "aggressive hybrid Russian attacks" and campaigns targeted consecutive elections, including leaking access data for election websites on Russian cybercrime platforms. Romania's intelligence agency also identified over 85,000 cyberattacks aiming to target system vulnerabilities.
Why it matters: Romania’s strong alignment with EU policies supporting Ukraine and sanctioning Russia makes it a prime target for interference. A particular campaign also promoted a reportedly pro-Russian candidate, who has openly advocated for withdrawing Romanian support for Ukraine, a stance that could isolate the country within the European Union. By promoting such a candidate, Russia may aim to secure policies favorable to its interests or disrupt Romania’s alignment with Western powers.
INTERPOL Campaign Warns Against Cyber and Financial Crimes
What happened: INTERPOL has launched the "Think Twice" campaign to raise awareness about the rising threat of cyber and financial crimes targeting vulnerable individuals and organizations. The campaign highlights five growing online threats: ransomware, malware, phishing, generative artificial intelligence (AI) scams, and romance baiting.
Why it matters: The Think Twice campaign aims to reduce online scam risks by educating users on being more cautious about unsolicited digital interactions, verifying identities, and pausing before engaging with suspicious content. Meanwhile, the FBI is also warning that cybercriminals are leveraging generative AI to amplify fraud, making their schemes more realistic and harder to detect. As online scams become more sophisticated, they pose increasing threats to individuals and businesses, leading to possibilities of financial losses and diminished trust in digital spaces.
DEEP AND DARK WEB INTELLIGENCE
- XSS user 4Rr0w: Untested threat actor "4Rr0w" advertised VPN access with domain administrator rights to an unnamed oil company based in Latin America on predominantly Russian language dark web forum XSS. According to 4Rr0w, there were more than 8,000 hosts on the network.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Multiple vulnerabilities in I-O DATA routers: Japan’s computer emergency response team (CERT) has issued an alert about zero-day vulnerabilities in I-O Data router devices that threat actors are exploiting to modify device settings, execute commands, or even turn off the firewall.
Affected product: I-O DATA routers UD-LT1 and UD-LT1/EX
CVE-2024-51378: This bug allows remote attackers to bypass authentication and execute arbitrary commands. CISA has this bug in its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Affected products: CyberPanel (aka Cyber Panel) versions before 1c0c6cb
Tags: DIB, tlp:green