ZeroFox Cyber Intelligence Daily Brief - December 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hydra Market Leader Sentenced to Life in Prison, over a Dozen Convicted
- Poland Probes Illegal Spyware Deployment by Former Leaders
- SmokeLoader Malware Targets IT, Healthcare, and Manufacturing in Taiwan
Sanctions Against Individuals and Entities in Russian Money Laundering Network
What happened: An international NCA-led investigation—Operation Destabilise—has exposed and disrupted Russian money laundering networks supporting organised crime spread across the United Kingdom, the Middle East, Russia, and South America. Investigators have identified two Russian-speaking networks collaborating at the heart of the criminal enterprise, Smart and TGR.
Why it matters: Operation Destabilise uncovered a complex scheme, whereby the networks collect funds in one country and make the equivalent value available in another, often by swapping cryptocurrency for cash. After being paid in crypto in exchange for their cash, criminal gangs would use the virtual currency to reinvest in their illicit business, buying more drugs or firearms without the need to move any physical money across borders. The financial service provided to such groups perpetuated their violent activity, enabling them to cause serious harm to communities across the United Kingdom.
Joint Guidance on PRC Threat Actors Targeting Global Telecommunications Providers
What happened: CISA—with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners—has released a joint guidance, Enhanced Visibility and Hardening Guidance for Communications Infrastructure.
Why it matters: The guidance is a response to threat actors affiliated with the People’s Republic of China (PRC) compromising networks of major global telecommunications providers to conduct a broad and significant cyber espionage campaign. The compromise of private communications impacted a limited number of individuals primarily involved in government or political activity. Although tailored to network defenders and engineers of communications infrastructure, this guide may also apply to organizations with on-premises enterprise equipment.
Wanted Russian Hacker Linked to Hive and LockBit Ransomware Operations Arrested
What happened: A Russian cybercriminal linked to the LockBit and the Hive ransomware groups has reportedly been arrested. They have allegedly conducted significant attacks against entities in the United States and global businesses and critical infrastructure. The United States had offered a USD 10 million reward for information leading to their arrest or conviction.
Why it matters: The individual’s operations targeted thousands of victims globally, including critical infrastructure and businesses in the United States and other countries. By targeting their extensive network and exposing the scale of the damage caused, this arrest could help prevent further financial losses and reputational harm from their ransomware campaigns. Additionally, disrupting the individual’s extensive operations can likely lead to fewer attacks, potentially safeguarding critical systems and industries from even more severe disruptions.
Tags: DIB, tlp:green