ZeroFox Cyber Intelligence Daily Brief - December 13, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 13, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- 14 Indicted in Six-Year Fake IT Worker Scam
- Law Enforcements Takedown Illegal Rydox Marketplace and Admins
- Spanish Police Takes Down Voice Phishing Ring That Defrauded USD 3.1 Million
14 Indicted in Six-Year Fake IT Worker Scam
Source: https://www.theregister.com/2024/12/13/doj_dpkr_fake_tech_worker_indictment/
What happened: The U.S. Department of Justice (DOJ) charged 14 individuals and two firms employing North Korean IT workers who used fake identities to secure remote jobs, earning USD 88 million for the Democratic People’s Republic of North Korea (DPRK or North Korea) over six years. Some of these “workers” extorted employers by threatening to release sensitive data.
Why it matters: The North Korean IT workers gained employment through fraud, exfiltrated sensitive information from U.S. companies, and siphoned money back to the DPRK, allegedly employing tactics to evade sanctions and detection. The stolen financial resources were likely used to fund DPRK’s missile program. Such scams exploit businesses seeking to employ large numbers of contract workers quickly, cause damages beyond financial loss, expose sensitive corporate information, and enable weapons proliferation.
Law Enforcements Takedown Illegal Rydox Marketplace and Admins
What happened: The Justice Department announced the seizure of Rydox and the arrests of three administrators. The United States also obtained judicial authorization to seize the domain www.Rydox[.]cc, which hosted and facilitated access to the Rydox website.
Why it matters: The Rydox site has facilitated the sale of over 321,000 stolen identities, account credentials, and hacking tools to over 18,000 users. Reportedly, for more than eight years, the defendants administered the Rydox marketplace that sold personally identifiable information, credit card information, and login credentials that had been stolen from thousands of U.S. victims. Such cyber criminal activities have global repercussions, where individuals and organizations suffer financial ruin as a result of the theft and misuse of their sensitive personal information.
Spanish Police Takes Down Voice Phishing Ring That Defrauded USD 3.1 Million
Source: https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16409
What happened: Authorities dismantled a criminal organization that defrauded over EUR 3 million (USD 3.1 million) through vishing, arresting 83 individuals in Spain and Peru. Coordinated raids in both countries seized money, phones, computers, and scam-related documentation.
Why it matters: The group operated three call centers with 50 employees, exploited social engineering techniques, and masked phone numbers (spoofing) to deceive over 10,000 victims, making the fraudulent calls appear as if they came from legitimate bank numbers. Victims were tricked into sharing sensitive codes, leading to immediate ATM withdrawals and financial losses.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user SSL_Dragon: Threat actor "SSL_Dragon" claimed to have leaked a database associated with the Thailand division of Oppo, a China-based smartphone manufacturer, on predominantly English-language dark web forum BreachForums. The compromised data includes over 22 million customer records and personal details from the company’s human resources system.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-50623: CVE-2024-50623 is a zero-day flaw in its LexiCom, VLTransfer, and Harmony software where an unrestricted file upload and download could lead to remote code execution. Cleo has patched this zero-day flaw.
Affected product: Cleo Harmony versions before 5.8.0.21, VLTrader versions before 5.8.0.21, and LexiCom versions before 5.8.0.21
Tags: DIB, tlp:green