ZeroFox Cyber Intelligence Daily Brief - December 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 12, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Law Enforcement Operation Shuts DDoS Booters Ahead of Christmas
- Cyberattack Disrupts Krispy Kreme Operations; Online Ordering Hampered
- Chinese Law Enforcement Connected to EagleMsgSpy Spyware Misuse
Law Enforcement Operation Shuts DDoS Booters Ahead of Christmas
What happened: A global law enforcement (LE) operation, PowerOFF, has seized 27 of the most popular platforms worldwide, disrupting a holiday tradition for cybercriminals of launching Distributed Denial-of-Service (DDoS) attacks to take websites offline.
Why it matters: The operation targeted two websites “booter” and “stresser” websites, which enabled cybercriminals and hacktivists to flood targets with illegal traffic, rendering websites and other web-based services inaccessible. The festive season has long been a peak period for hackers to carry out some of their most disruptive DDoS attacks, causing severe financial loss, reputational damage and operational chaos for their victims. The motivations for launching such attacks vary, from economic sabotage and financial gain to ideological reasons, as demonstrated by notorious hacktivist collectives such as Killnet or Anonymous Sudan.
Cyberattack Disrupts Krispy Kreme Operations; Online Ordering Hampered
Source: https://hackread.com/krispy-kreme-cyber-attack-disrupted-online-order-us/
What happened: Popular donut chain Krispy Kreme has stated that unauthorized access to some of its information technology systems has impacted certain operations, including online ordering in the United States. The investigation is ongoing and the company is actively trying to restore its systems.
Why it matters: Even though the cyberattack did not affect in-store sales and deliveries, the company saw a share drop of about 2 percent in premarket trading. The costs the company will bear due to the incident are “reasonably likely to have a material impact on the company’s results of operations and financial condition.” The cyberattack, conducted during the holiday season, when Krispy Kreme outlets are unusually busy, is a likely indication that it was a targeted attack aimed at harming the company’s reputation, finances, and customer trust in the institution.
Chinese Law Enforcement Connected to EagleMsgSpy Spyware Misuse
What happened: EagleMsgSpy, a newly discovered Android spyware, is reported to be used by Chinese law enforcement to monitor mobile devices. This sophisticated malware, linked to specific Chinese developers and operators, is capable of stealing sensitive data including messages, recordings, call logs, location, and more.
Why it matters: Researchers have found evidence of continuous development of the malware indicating that the developers are refining their techniques, likely to target high profile targets, a wider range of victims, including individuals, organizations, and governments. Additionally, EagleMsgSpy poses a significant threat due to its extensive data collection capabilities and stealthy operation. Its association with law-enforcement agencies raises concerns about potential misuse and surveillance by the government on its people.
DEEP AND DARK WEB INTELLIGENCE
- Exploit user ProfessorKliq: Well-regarded threat actor "ProfessorKliq" advertised an auction for Fortinet VPN access bundle with domain user rights to three unnamed U.S. and Canadian companies on predominantly Russian language Dark Web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Apple addresses multiple vulnerabilities: Apple has recently released critical security updates for iOS 18.2 and macOS Sequoia 15.2 to address a wide range of vulnerabilities. These vulnerabilities, including kernel exploits, WebKit flaws, and a severe bug in libexpat, could potentially lead to data leaks, unauthorized code execution, and system compromises. Users are strongly urged to install these updates promptly to protect their devices.
Affected product: The affected products have been listed in this advisory.
CVE-2024-53247: A low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE). This vulnerability is among the 10 high-severity vulnerabilities addressed in Atlassian’s December security bulletin.
Affected products: Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.461 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform.
Tags: DIB, tlp:green