zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 13, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 13, 2025

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian SORM Technology Expands in Central Asia and Latin America
  • Muddling Meerkat Linked to Domain Spoofing in Global Spam Campaign
  • U.S. Department of Justice Charges Three Operators of Cryptocurrency Mixers with Money Laundering

Russian SORM Technology Expands in Central Asia and Latin America

Source: https://www.darkreading.com/threat-intelligence/russia-commercial-surveillance-success-globally

What happened: Several governments in Central Asia and Latin America have acquired the System for Operative Investigative Activities (SORM) wiretapping technology from Russian suppliers, potentially enabling Russian intelligence agencies to access wiretapped systems as well. The technology involves the installation of surveillance equipment within telecommunications facilities, enabling the client government’s intelligence agency to access sensitive data from citizens' communications.

Why it matters: SORM wiretapping technology allows local intelligence agencies to monitor communications without consent, enabling them to track dissidents, activists, and opposition, while Russian authorities can potentially exploit this data for espionage or influence. Adversarial nations are also likely to gain access to critical government data, threatening national security by compromising sensitive military, intelligence, and diplomatic operations, while suppressing free speech in regions where dissent is already repressed. For travelers and business people, the increased risk of surveillance, identity theft, and espionage is likely to expose them as targets during trips to countries with SORM technology.

Muddling Meerkat Linked to Domain Spoofing in Global Spam Campaign

Source: https://hackread.com/muddling-meerkat-domain-spoofing-spam-scams/

What happened: Researchers uncovered an extensive malspam campaign conducted by the threat group Muddling Meerkat, which impersonated global organizations to distribute malicious content via spam emails. Several organizations reported receiving notifications that their domains were getting abused, especially domains that faced limited public exposure—typically reflecting Chinese IP addresses.

Why it matters: Domain spoofing is proliferating despite existing cybersecurity measures to contain attacks where threat actors deployed sophisticated domain spoofing tactics to extort phished victims. Over 4,000 backdoors have been found in abandoned infrastructure (likely, expired domains) freely available to threat actors of all capabilities to commandeer and abuse them, after gaining remote access to infected servers. The growing instances of spoofed domains likely indicate a growing global attack sphere along with threat actors proliferating, because of their activities made considerably efficient through unattended backdoors and likely lax operational security at organizational and user level.

U.S. Department of Justice Charges Three Operators of Cryptocurrency Mixers with Money Laundering

Source: https://www.justice.gov/opa/pr/operators-cryptocurrency-mixers-charged-money-laundering

What happened: The U.S. Department of Justice (DOJ) charged three Russian nationals for operating cryptocurrency “mixers,” Blender[.]io and Sinbad[.]io, that enabled the laundering of criminally derived funds, including the proceeds of ransomware and wire fraud.

Why it matters: The operators of Blender[.]io and Sinbad[.]io seemingly made it easier for state-sponsored hacking groups and other cybercriminals to profit from offenses jeopardizing public safety and national security. The mixers were allegedly used by criminals globally to launder funds stolen from the victims of cybercrimes like ransomware and virtual currency thefts. The Department of Treasury’s Office of Foreign Assets Control (OFAC) has previously sanctioned Blender[.]io and Sinbad[.]io, citing their use by North Korea to launder stolen cryptocurrency and obfuscate transactions related to illegal activities.

DEEP AND DARK WEB INTELLIGENCE

  • Hacking forum promotes private crypter: A new advertisement on a hacking forum promotes a private crypter tool, claiming it can bypass SmartScreen protections and a popular web browser, and evade detection by security software.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-12834: Delta Electronics DRASimuCAD expects a specific data type when it opens files, but the program will accept data of the wrong type from specially crafted files. Successful exploitation of this bug could crash the device or potentially allow remote code execution.

  • Affected product: DRASimuCAD version 1.02

Tags: DIB, tlp:green