zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 19, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Releases Best Practice Guidance for Mobile Communications
  • Phishers Cast Wide Net with Spoofed Calendar Invites
  • Raccoon Stealer Malware Operator Nabbed by United States

CISA Releases Best Practice Guidance for Mobile Communications

Source: https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications

What happened: CISA released Mobile Communications Best Practice Guidance in response to cyber espionage activities by People’s Republic of China (PRC) government-affiliated threat actors targeting commercial telecommunications infrastructure, senior government, and political figures with sensitive information.

Why it matters: These actors target both commercial telecommunications infrastructure and highly valuable individuals, amplifying the risk of critical information theft or manipulation. Such breaches can lead to serious geopolitical consequences, from diplomatic tensions to national security risks. To mitigate these threats, CISA strongly urges highly targeted individuals to immediately review and apply the best practices provided in the guidance, including the consistent use of end-to-end encryption, to protect mobile communications.

Phishers Cast Wide Net with Spoofed Calendar Invites

Source: https://www.theregister.com/2024/12/18/google_calendar_spoofed_in_phishing_campaign/

What happened: Cyber criminals are spoofing popular calendar invite emails in a phishing scheme targeting over 300 organizations, sending more than 4,000 emails over four weeks.

Why it matters: By mimicking legitimate calendar invites or support links, the attackers prey on victims' trust, often resulting in the unknowing disclosure of sensitive data. The scheme is designed to trick users into completing a fake authentication process, entering sensitive details, and providing payment information, all of which can lead to identity theft, financial scams, or unauthorized charges. This sophisticated method of deception exploits common online tools, making it harder for users to identify fraudulent attempts.

Raccoon Stealer Malware Operator Nabbed by United States

Source: https://www.bleepingcomputer.com/news/security/raccoon-stealer-malware-operator-gets-5-years-in-prison-after-guilty-plea/

What happened: Ukrainian cybercriminal reportedly behind the Raccoon Stealer malware-as-a-service (MaaS) operation has been sentenced to five years in prison, while the criminal operation was shut down by international law enforcement efforts. Millions of computers around the world have been infected with the Raccoon malware and more than two million victims have had their personal information, financial information, and passwords stolen by Raccoon.

Why it matters: Raccoon Stealer could reportedly steal sensitive data like passwords, credit card information, and personal details. It was likely easily accessible to cybercriminals since the operators rented their MaaS model for USD 75 per week or USD 200 monthly, allowing even amateur actors to cause significant financial loss and identity theft for millions of victims. What exacerbated the threat this service posed was that it evolved over time to provide buyers additional data theft capabilities and other features.

DEEP AND DARK WEB INTELLIGENCE

Exploit user Faramir: Untested threat actor "Faramir" advertised an auction for RDWeb access with domain user rights to an unnamed Dutch commercial and residential construction company on predominantly Russian-language dark-web forum Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-25623: This vulnerability allows a threat actor to impersonate an account on a remote server that satisfies all of the following properties: allows the attacker to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as the ActivityPub actors; and serves user-uploaded document in response to requests with an “Accept” header value of the Activity Streams media type. Versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19 contain a fix for this issue.

Affected products: Versions before 4.2.7, 4.1.15, 4.0.15, and 3.5.19

Tags: DIB, tlp:green