ZeroFox Cyber Intelligence Daily Brief - December 29, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 29, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Rules NSO Group Violated U.S. Hacking Laws to Deploy Spyware
- Mozi Botnet’s Successor Androxgh0st Poses Major Threat to Critical Infrastructure
- Dark Web Facial ID Farm Warning—Hackers Build Identity Fraud Database
U.S. Rules NSO Group Violated U.S. Hacking Laws to Deploy Spyware
What happened: A U.S. federal judge has ruled that Israeli spyware maker NSO Group using WhatsApp zero-days to deploy Pegasus spyware on at least 1,400 devices infringes U.S. hacking laws. The spyware deployment continued even after NSO was sued by WhatsApp for its illegal surveillance practices.
Why it matters: Spyware—like Pegasus—threatens security and poses a risk to the privacy of targeted users, leaving them vulnerable to invasive surveillance, data exfiltration attacks, unwarranted tracking, and even physical harm. Holding spyware makers responsible for illegal activities will likely encourage other firms to incorporate stricter policies for using spyware models. In this case, where Pegasus attacks targeted one of the most popular communication platforms, the ruling emphasizes the importance of protecting user privacy.
Mozi Botnet’s Successor Androxgh0st Poses Major Threat to Critical Infrastructure
Source: https://www.theregister.com/2024/12/24/androxgh0st_botnet_mozi/
What happened: Cybersecurity researchers are warning that the Androxgh0st botnet, which has adopted some capabilities of the now-defunct Mozi botnet, is a major threat to critical infrastructure and is likely a cyber weapon of the Chinese government.
Why it matters: Androxgh0st has infected hundreds of thousands of systems and expanded its arsenal of exploits by 100 percent in almost a year by exploiting vulnerabilities in routers, VPNs, firewalls, web servers, and several popular operating systems. In January 2024, U.S. federal agencies released a joint advisory highlighting how Androxgh0st establishes a botnet for victim identification and exploitation in vulnerable networks and targets files that contain confidential information, such as credentials, for various high-profile applications. The likely association with the Chinese government and its sophisticated capabilities showcases how Androxgh0st is likely to be a threat to critical infrastructure—a hub of sensitive information that impacts national security.
Dark Web Facial ID Farm Warning—Hackers Build Identity Fraud Database
What happened: A dark web criminal group has been uncovered collecting genuine identity documents along with matching facial ID images. This operation was designed to bypass Know Your Customer (KYC) verification processes, which are used to prevent identity fraud in banking and financial institutions.
Why it matters: The criminal group used authentic identity documents paired with corresponding facial biometric data, making it more difficult to identify the perpetrators through conventional security checks. Unlike previous incidents where stolen biometric data was scraped from breached databases, the group appears to have acquired the information directly from users. This poses a significant risk to banks, financial institutions, and any organization that relies on KYC and biometric authentication systems, potentially leading to a rise in identity fraud and other related crimes.
Tags: DIB, tlp:green