zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 24, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 24, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • DOJ Indicts Individuals for Multi-Year Fraudulent Remote Information Technology Worker Scheme
  • Reddit and WeTransfer Impersonation Campaign Targets Users with Malware
  • Now-Fixed Subaru STARLINK Flaws Still a Concern

DOJ Indicts Individuals for Multi-Year Fraudulent Remote Information Technology Worker Scheme

Source: https://www.justice.gov/opa/pr/two-north-korean-nationals-and-three-facilitators-indicted-multi-year-fraudulent-remote

What happened: The U.S. Justice Department announced the indictment of four individuals for a fraudulent scheme to obtain remote information technology (IT) work with U.S. companies that generated revenue for the Democratic People’s Republic of Korea (DPRK or North Korea). An investigation has uncovered a years-long plot to install North Korean IT workers as remote employees to generate revenue for the DPRK regime and evade sanctions.

Why it matters: According to the indictment, over the course of their scheme, the defendants obtained work from at least sixty-four U.S. companies. Payments from ten of those companies generated at least USD 866,255 in revenue, most of which the defendants then laundered through a Chinese bank account. Two of the individuals received laptops from U.S. company employers at their residences, downloading and installing remote access software on them, without authorization, to facilitate IT worker access and to perpetuate the deception of U.S. companies.

Reddit and WeTransfer Impersonation Campaign Targets Users with Malware

Source: https://www.bleepingcomputer.com/news/security/hundreds-of-fake-reddit-sites-push-lumma-stealer-malware/

What happened: Hackers have created nearly 1,000 fake web pages mimicking Reddit and WeTransfer, using a social engineering technique, to distribute the Lumma Stealer malware. Victims are tricked by seemingly legitimate discussions and file-sharing links that ultimately lead to malware downloads.

Why it matters: Hackers are exploiting trusted brands like Reddit and WeTransfer to deceive users into downloading malicious software, bypassing security measures and increasing their chances of success. The widespread distribution of this malware across almost 1,000 fake pages can lead to a large-scale data breach, affecting both individuals and organizations. Victims may suffer financial loss, identity theft, and privacy violations, all of which can likely have long-term consequences.

Now-Fixed Subaru STARLINK Flaws Still a Concern

Source: https://cybersecuritynews.com/subaru-car-vulnerability-lets-hackers-control-the-millions-of-cars-remotely/

What happened: Now-fixed vulnerabilities in Subaru's STARLINK service allowed hackers to remotely unlock and start millions of vehicles, but still poses data security risks. While Subaru patched the issues after being alerted in November, researchers warn that employees still have access to customers' detailed location histories.

Why it matters: These flaws present risks of theft, stalking, and privacy violations, as threat actors can likely track vehicles, control their features, and access personal customer information. The vulnerabilities discovered in Subaru's web tools are likely not isolated incidents. Researchers indicate that similar security flaws are likely to be found in web-based tools of many car manufacturers.

DEEP AND DARK WEB INTELLIGENCE

Telegram user RooTDoS: Pro-Palestine hacktivist group “RooTDoS” revealed its plans to target Iran with future cyberattacks. According to the group, the reason behind this is Iran’s growing influence in the Middle East, where it influences entities in Yemen, Iraq, Syria, and Lebanon.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-0432: EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.

Affected products: Ewon Flexy 202: All versions

Tags: DIB, tlp:green