zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief –December 9, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief –December 9, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on December 6, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

FTC Takes Action Against Illegal Sale of Sensitive Location Data

What happened: The Federal Trade Commission (FTC) has accused data brokers Mobilewalla, Inc. and Gravy Analytics of unlawfully tracking and selling sensitive location data. Mobilewalla allegedly collected private addresses and sold the information without taking reasonable steps to verify consumers’ consent. Under the FTC’s proposed settlement order, Mobilewalla will also be banned from collecting consumer data from online advertising auctions for purposes other than participating in those auctions. Meanwhile, Gravy Analytics and its subsidiary, Venntel, illegally tracked and sold sensitive location data from users—including sensitive private data about consumers. As per the FTC, Gravy Analytics and Venntel will be prohibited from selling, disclosing, or using sensitive location data in any product or service and must establish a sensitive data location program.

Poland Probes Illegal Spyware Deployment by Former Leaders

What happened: Poland’s current government, led by Donald Tusk, is investigating alleged abuses of Pegasus spyware by the previous Law and Justice (PiS) administration. The former internal security chief was arrested after ignoring three summons to testify before a parliamentary committee. Reports indicate that Pegasus was used against three government critics, including a senator targeted multiple times before the 2019 elections. Amnesty International and other institutions confirmed these findings, and a 2023 Polish Senate report deemed the spyware’s use unlawful.

North Korean Hackers Leverage Russian-Sourced Emails for Credential Theft

What happened: North Korea’s advanced persistent threat (APT) group Kimsuky has been orchestrating a series of sophisticated phishing campaigns to steal user credentials in Japan and South Korea. These attacks typically involve emails that appear to come from Russian sender addresses, using domains associated with VK’s Mail[.]ru service—including trusted email domains like mail[.]ru, internet[.]ru, bk[.]ru, inbox[.]ru, and list[.]ru. Kimsuky exploits these domains to impersonate trusted entities, such as financial institutions and popular internet services like Naver (South Korea’s search engine and online platform). One of the group’s common tactics involves phishing emails masquerading as notifications from Naver's MYBOX cloud storage, falsely alerting users to the presence of malicious files in their accounts and urging them to click on links to delete these supposed threats. Often crafted to invoke a sense of urgency, these emails aim to deceive recipients into disclosing sensitive information or downloading malware.

Tags: tlp:green