zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 24, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Law Enforcement Officials Release Final “Don’t Click December” PSA
  • U.S. Rules NSO Group Violated U.S. Hacking Laws to Deploy Spyware
  • Lazarus Group Targets Nuclear Industry with CookiePlus Malware

U.S. Law Enforcement Officials Release Final “Don’t Click December” PSA

Source: https://www.justice.gov/usao-id/pr/us-attorneys-office-fbi-along-tribal-and-local-law-enforcement-officials-release-final

What happened: A U.S. attorney, along with the FBI and local law enforcement agencies has released a fourth and final PSA as part of their joint “Don’t Click December” Consumer Protection Campaign.

Why it matters: The "Tech Support" scam, highlighted in the fourth PSA of the "Don’t Click December" campaign, involves criminals impersonating technology, banking, or government officials to trick victims into sharing personal information. Victims are likely to see a pop-up claiming their accounts have been hacked and urging them to call a number, connecting them to scammers, who steal money. The campaign advises the public to exercise skepticism and caution when receiving unsolicited online, email, pop-up, or text communications from unknown or unverified sources.

U.S. Rules NSO Group Violated U.S. Hacking Laws to Deploy Spyware

Source: https://www.bleepingcomputer.com/news/security/us-court-finds-spyware-maker-nso-liable-for-whatsapp-hacks/

What happened: A U.S. federal judge has ruled that Israeli spyware maker NSO Group using WhatsApp zero-days to deploy Pegasus spyware on at least 1,400 devices infringes U.S. hacking laws. The spyware deployment continued even after NSO was sued by WhatsApp for its illegal surveillance practices.

Why it matters: Spyware—like Pegasus—threatens security and poses a risk to the privacy of targeted users, leaving them vulnerable to invasive surveillance, data exfiltration attacks, unwarranted tracking, and even physical harm. Holding spyware makers responsible for illegal activities will likely encourage other firms to incorporate stricter policies for using spyware models. In this case, where Pegasus attacks targeted one of the most popular communication platforms, the ruling emphasizes the importance of protecting user privacy.

Lazarus Group Targets Nuclear Industry with CookiePlus Malware

Source: https://hackread.com/lazarus-group-nuclear-industry-cookieplus-malware/

What happened: The North Korea-linked Lazarus Group has shifted its focus to the nuclear industry. The attack involved delivering malicious archive files to at least two employees of a nuclear organization over the course of a month, using fake job postings as a delivery method—part of a tactic known as the “DeathNote campaign” or “Operation DreamJob.”

Why it matters: This signals a new phase in the Lazarus Group’s activities, previously focused on defense, aerospace, and cryptocurrency, and now extending into the sensitive nuclear sector. The use of fake job postings as a social engineering tactic lures victims with false career opportunities to gain access to their systems, potentially compromising sensitive data and allowing persistent network intrusions. Additionally, the introduction of "CookiePlus," a novel memory-resident malware, enhances the group's ability to evade detection.

DEEP AND DARK WEB INTELLIGENCE

  • Doxbin Leadership Transition: On December 23, 2024, admin of pastebin site Doxbin, Demeter and Pierce, announced that they have decided to step away from their roles. This development comes about 6 months after the site was taken temporarily offline allegedly for security reasons.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2021-44207: A threat actor with knowledge of the validationKey and decryptionKey for a web application can construct a malicious ViewState that passes the MAC check and will be deserialized by the server. This deserialization can result in the remote execution of code on the server.

  • Affected product: Acclaim USAHERDS web application versions 7.4.0.1 and Earlier

Tags: DIB, tlp:green