ZeroFox Cyber Intelligence Daily Brief - December 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian APT Hackers Exploit Pakistani APT Storm-0156 Servers
- Europol Takes Down Fraudulent Shopping Sites
- U.S. Org with Presence in China Targeted by China-Based Actors for Four Months
Russian APT Hackers Exploit Pakistani APT Storm-0156 Servers
Source: https://thehackernews.com/2024/12/russia-linked-turla-exploits-pakistani.html
What happened: Russian APT group Turla has exploited access to the Pakistan-based Storm-0156 hacking group’s command-and-control (C2) servers since 2022 to launch its own cyber operations. The campaign primarily targets Afghan government entities with custom malware.
Why it matters: In this operation, Turla has been operating covertly, using bespoke malware like TwoDash (a downloader) and Statuezy (a clipboard-monitoring trojan) for targeted espionage. The focus on Afghan government networks aligns with Turla's geopolitical interests, likely aimed at intelligence on regional security and politics. This persistent and stealthy campaign can potentially breach sensitive networks, compromising diplomatic and military operations while allowing long-term data exfiltration. The use of compromised C2 servers further complicates detection and attribution, increasing the risk of broader exploitation by other threat actors.
Europol Takes Down Fraudulent Shopping Sites
What happened: Europol and other state authorities coordinated in dismantling a sophisticated criminal network responsible for facilitating large-scale online fraud. In this operation, over 50 servers were seized, significant digital evidence was secured, and two key suspects were placed in pretrial detention.
Why it matters: The investigation began in late 2022, following reports of fraudulent phone calls in which scammers impersonated bank employees to extract sensitive information, such as addresses and security answers, from victims. The stolen data was traced back to a specialised online marketplace that operated as a central hub for the trade of illegally obtained information. The marketplace allowed its thousands of users to buy stolen data sorted by region and account balance. This customisation enabled criminals to carry out targeted fraud with greater efficiency. Investigators also uncovered a network of fake online shops used to trick consumers into entering payment information. The stolen credentials were then sold through the marketplace, generating significant profits for its operators.
U.S. Org with Presence in China Targeted by China-Based Actors for Four Months
What happened: Threat researchers have discovered a four-month operation orchestrated by China-based actors targeting a U.S. organization with a significant presence in China. The operation seemingly aimed to gather intelligence from compromised machines and Exchange servers.
Why it matters: The intelligence gathered in the operation will likely include emails, likely to contain sensitive confidential communication. Both politically and financially motivated actors can leverage such information; the former to give their states a political advantage and the latter to sell the information to any interested party. China-based threat actors, however, are more likely to have political motivations behind targeting U.S. organizations, given the tensions between China and the United States.
DEEP AND DARK WEB INTELLIGENCE
Exploit/XSS user doZKey: Well-regarded threat actor "doZKey" advertised an auction for Global Protect VPN access to an unnamed U.S.-based insurance company on predominantly Russian language dark web forums Exploit and XSS.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-41713: This is a path traversal vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. This vulnerability is exploitable without authentication.
Affected products: MiCollab versions 9.8 SP1 FP2 (9.8.1.201) and earlier
Tags: DIB, tlp:green