ZeroFox Cyber Intelligence Daily Brief - December 7, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 7, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- DroidBot Trojan Targets Financial Institutions After Evolving into Malware-as-a-Service
- Actor’s Telegram Account Removed After Mass Reporting
- CISA’s Guidance on Choosing Secure and Verifiable Technologies
DroidBot Trojan Targets Financial Institutions After Evolving into Malware-as-a-Service
Source: https://www.darkreading.com/threat-intelligence/trojan-service-hits-euro-banks-crypto-exchanges
What happened: "DroidBot," an aggressive Android remote access Trojan (RAT) Trojan, is being used to steal data from banks, cryptocurrency exchanges, and other national organizations via spyware-like features, including keylogging and remote device control. It is reportedly also evolving into a malware-as-a-service (MaaS) operation.
Why it matters: DroidBot has been active since mid-2024, with involvement in 77 attacks across Europe, and is now allegedly on the verge of targeting Latin America. The MaaS tool comes with an embargo of advanced surveillance tools that gives it adaptability to build scalable and targeted operations. It can pose a significant risk to financial sectors in emerging markets exposing them to theft, fraud, and operational disruption.
Actor’s Telegram Account Removed After Mass Reporting
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/76940
What happened: Pro-Russia threat actor group "NoName057(16)" reported that its official Telegram channel got banned, which was subscribed to by nearly 85,000 users. Another pro-Russia threat actor group, "Cyber Army of Russia Reborn," an ally of NoName057(16), also faced the same issue, claiming: "our main channel was demolished by enemies."
Why it matters: The Telegram policy changes (announced in mid-2024) caused a lot of buzz among cybercriminals. Initially, threat actor groups discussed getting rid of their Telegram channels and starting their activities on X (Twitter) and Discord channels. However, despite the policy change on Telegram, threat actors continue to view it as crucial for their communication and public-facing announcements. The two prominent threat actors are well known in the underground world for their pro-Russia stance. In its post, NoName057(16) has promised to up their criminal activities, seemingly deeming this closure as Telegram’s bias toward Russian actors. As a result of which, these actors can likely target communication companies like Telegram to reinforce their geopolitical stance and show their indignation at having taken away its massive following that it had gathered.
CISA’s Guidance on Choosing Secure and Verifiable Technologies
What happened: CISA—in partnership with several international partners—has released updates to a Secure by Design Alert, Choosing Secure and Verifiable Technologies.
Why it matters: The procurement of any digital product or service increases the attack surface of an organisation’s information environment. Proactive integration of security mitigations into the procurement process can assist in managing risks present within the technology supply chain and reduce costs for organizations. This guidance aids procuring organizations and manufacturers of digital products and services in choosing and developing technology that is secure by design.
DEEP AND DARK WEB INTELLIGENCE
- ZeroFox Observes Uptick in Attacks Targeting Healthcare: On December 4 and 5, ZeroFox observed a rise in posts targeting hospitals in the United States. Threat actors octagon, Br34cHM45t3r, and mapateam claimed a database leak associated with several healthcare service providers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-10905: This bug allows HTTP access to static content in the IdentityIQ application directory that should be protected. Hackers are likely to exploit this vulnerability to access restricted files.
Affected product: All IdentityIQ versions up to patch levels 8.4p2, 8.3p5, and 8.2p8
Tags: DIB, tlp:green