zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Romania Elections Annulled; Integrity Compromised
  • Hungarian Intelligence Accused of Spying on EU Officials
  • Europol and Co. Investigates Phone Phishing Gang

Romania Elections Annulled; Integrity Compromised

Source: https://thehackernews.com/2024/12/romania-cancels-presidential-election.html

What happened: Romania's constitutional court annulled the first round of the presidential election due to allegations of Russian interference, forcing a full restart of the electoral process and leading to the European Commission enforcing measures to safeguard elections under the Digital Services Act. This incident follows allegations that a pro-Russian TikTok influence campaign was actively promoting one of the candidates, who won the first round of the elections.

Why it matters: Romania’s strong alignment with EU policies supporting Ukraine and sanctioning Russia makes it a prime target for interference. Romanian law enforcement and intelligence agencies are carrying out investigations into the alleged Russian interference, including cyberattacks and coordinated social media manipulation. TikTok has identified domestic covert networks influencing voters, while Romanian authorities uncovered state-backed cyberattacks targeting election infrastructure.

Hungarian Intelligence Accused of Spying on EU Officials

Source: https://www.politico.eu/article/hungary-viktor-orban-cia-spy-wiretap-hack-laptop-eu-officials-information-office-budapest-olaf/

What happened: Hungary’s Information Office (IH), Budapest’s equivalent of the CIA, reportedly spied on investigators at the European Anti-Fraud Office (OLAF) by wiretapping their phones, hacking their laptops, and physically following them.

Why it matters: Hungary has dealt with long-standing allegations of using digital surveillance, spyware, and cyber espionage methods to monitor the activities of politically opposed entities and individuals. Such campaigns are likely to disrupt investigative efforts to reduce fraud, corruption, or other illicit activities that can indirectly or directly impact the financial interests of different countries. Besides, the information collected is likely to be used in malicious targeted attacks against officials involved in investigations, subjecting them to threats like blackmail, extortion, and doxxing.

Europol and Co. Investigates Phone Phishing Gang

Source: https://www.europol.europa.eu/media-press/newsroom/news/international-operation-against-phone-phishing-gang-in-belgium-and-netherlands

What happened: An international operation, involving Europol, against a phone phishing gang has led to the arrest of eight suspects. Law enforcement also carried out 17 searches in different locations in Belgium and the Netherlands. Besides committing large-scale phishing campaigns and trying to gain access to financial data by phone or online, the suspects also impersonated the police and banking staff and approached older victims at their doors.

Why it matters: Authorities believe that the victims are based in at least 10 European countries and that the economic damages amount to several millions of euros. The operation, which began in 2022, targeted an organized crime group conducting large-scale phishing campaigns across Europe, impersonating police and bank staff to defraud victims. Authorities issued warnings urging citizens to verify urgent account-related messages, avoid suspicious links, and use up-to-date security measures to counter phishing attempts.

DEEP AND DARK WEB INTELLIGENCE

XSS user doZKey: Untested threat actor "doZKey" has advertised RDWeb access with local administrator rights to an unnamed Spanish real estate company on predominantly Russian language dark web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-12209: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the “filename” parameter of the “umbrella-restore” action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

Affected products: Update Backup Restore & Monitoring plugin for WordPress versions <= 2.17.0

Tags: DIB, tlp:green