zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 17, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 17, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Requests Public Comment for Draft National Cyber Incident Response Plan Update
  • Iranian Company Founder Arrested for Supporting IRGC and Procuring U.S. Tech for Military Drones
  • FBI Warns Against HiatusRAT Malware

CISA Requests Public Comment for Draft National Cyber Incident Response Plan Update

Source: https://www.cisa.gov/news-events/alerts/2024/12/16/cisa-requests-public-comment-draft-national-cyber-incident-response-plan-update

What happened: CISA—through the Joint Cyber Defense Collaborative and in coordination with the Office of the National Cyber Director (ONCD)—released the National Cyber Incident Response Plan Update Public Comment Draft.

Why it matters: The draft requests public comment on the National Cyber Incident Response Plan (NCIRP), which began on December 16, 2024 and concludes on January 15, 2025. The draft provides the public an opportunity to provide their knowledge and experiences on the NCIRP. The NCIRP details a national approach to coordinating cyber incident detection and response. CISA is seeking more perspectives to help strengthen the NCIRP and invites stakeholders from across the public and private sectors to share their knowledge and experiences, further informing findings and contributing to this revision.

Iranian Company Founder Arrested for Supporting IRGC and Procuring U.S. Tech for Military Drones

Source: https://www.justice.gov/opa/pr/founder-iranian-company-arrested-providing-material-support-islamic-revolutionary-guard

What happened: A dual U.S.-Iranian national and his co-defendant have been charged with conspiring to export sophisticated electronic components from the United States to Iran in violation of U.S. export control and sanctions laws. The co-defendant is also charged with providing material support to a foreign terrorist organization (FTO), which resulted in the deaths of three U.S. service members killed by a one-way attack Unmanned Aerial Vehicle (UAV), also known as a drone, on a military base in Jordan.

Why it matters: The accused played key roles in supplying advanced navigation technology to the IRGC’s drone program, including components for one-way attack drones. These drones have been used in acts of terror globally, directly threatening U.S. interests and security. This incident shows how violations of export controls go beyond regulatory breaches, as it enables adversaries like Iran to enhance their military capabilities, thereby escalating risks to international stability and U.S. national security.

FBI Warns Against HiatusRAT Malware

Source: https://www.ic3.gov/CSA/2024/241216.pdf

What happened: The FBI has warned of a new wave of HiatusRAT malware attacks targeting vulnerable web cameras and DVRs, particularly Chinese-branded devices. The attackers exploit known vulnerabilities to gain access to devices, steal data, and create a botnet for further malicious activities.

Why it matters: HiatusRAT is a Remote Access Trojan (RAT) whose latest iteration has likely been employed since July 2022. The Hiatus campaign originally targeted outdated network edge devices. It is also observed that these actors use the malware to target a range of Taiwan-based organizations and to carry out reconnaissance against the U.S. government server used for submitting and retrieving defense contract proposals.

DEEP AND DARK WEB INTELLIGENCE

Threat groups claim to target Tunisia, South Africa, and Algeria: Pro-Palestine threat actor groups Moroccan Soldiers and Moroccan Black Cyber Army claimed multiple web defacement attacks against entities in Tunisia, South Africa, and Algeria. The groups also claimed they may target entities in these regions in the future. Moroccan Soldiers claimed that the attack was motivated because the targeted countries supported the Polisario Front. According to the groups, this constitutes a clear violation of Morocco's sovereignty and an unacceptable provocation.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-20767: ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel to be exposed to the internet. CISA has added this vulnerability and CVE-2024-35250 to its Known Exploited Vulnerabilities (KEV) Catalog.

Affected products: ColdFusion versions 2023.6, 2021.12 and earlier

Tags: DIB, tlp:green